Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Espeak Ruby CRITICAL 9.8
CVE-2016-10193

The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the speak, sa…

Fix: after 1.0.2
Fix from $2,300 2017-03-03
Xen MEDIUM 6.5
CVE-2016-9815

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous abort.

Patch available
Fix from $1,600 2017-02-27
Xen MEDIUM 6.5
CVE-2016-9816

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2.

Patch available
Fix from $1,600 2017-02-27
Xen MEDIUM 6.5
CVE-2016-9817

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort wi…

Patch available
Fix from $1,600 2017-02-27
Xen MEDIUM 6.5
CVE-2016-9818

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP.

Patch available
Fix from $1,600 2017-02-27
Websphere Mq MEDIUM 6.5
CVE-2016-8915

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under th…

Patch available
Fix from $1,600 2017-02-22
Websphere Mq MEDIUM 6.5
CVE-2016-8986

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP reques…

Patch available
Fix from $1,600 2017-02-22
Xen MEDIUM 5.5
CVE-2016-9378

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM gues…

Patch available
Fix from $1,600 2017-02-22
Debian Linux HIGH 7.5
CVE-2016-9956

The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.

Fix: after 2016.4.3
Fix from $1,950 2017-02-22
Cognos Disclosure Management MEDIUM 5.3
CVE-2016-6077

IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document…

Patch available
Fix from $1,600 2017-02-15
Bigtree Cms MEDIUM 5.4
CVE-2016-10223

An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP …

Fix: after 4.2.14
Fix from $1,600 2017-02-14
Dacenter HIGH 7.8
CVE-2016-9356

An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path issue.

Fix: after 1.4
Fix from $1,950 2017-02-13
Omniview HIGH 7.5
CVE-2016-5801

An issue was discovered in OmniMetrix OmniView, Version 1.2. Insufficient password requirements for the OmniView web application may allow an attacke…

Mitigation only
Fix from $1,950 2017-02-13
Ion5000 CRITICAL 9.8
CVE-2016-5815

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 ser…

Mitigation only
Fix from $2,300 2017-02-13
Ikiwiki HIGH 7.5
CVE-2016-10026

ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins an…

Mitigation only
Fix from $1,950 2017-02-13
Puppet Enterprise MEDIUM 5.3
CVE-2016-2787

The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which a…

Mitigation only
Fix from $1,600 2017-02-13
Marionette Collective CRITICAL 9.8
CVE-2016-2788

MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the …

Fix: 3.8.6 / 2016.2.1+
Fix from $2,300 2017-02-13
Exponent Cms CRITICAL 9.8
CVE-2016-7565

install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array parameter.

Patch available
Fix from $2,300 2017-02-13
Hspa 3g10wve Firmware HIGH 7.3
CVE-2015-6023EPSS 11%

ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intende…

No fix yet
Fix from $1,950 2017-02-09
Dotclear HIGH 8.8
CVE-2015-8832

Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage th…

Fix: after 2.8.1
Fix from $1,950 2017-02-09
Security Directory Server MEDIUM 5.5
CVE-2015-1976

IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to cra…

Fix: after 6.4.0.6
Fix from $1,600 2017-02-08
Bigfix Platform HIGH 7.8
CVE-2016-0214

IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a m…

Patch available
Fix from $1,950 2017-02-08
System Storage Ts3100 Ts3200 Tape Library CRITICAL 9.8
CVE-2016-9005

IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and…

Mitigation only
Fix from $2,300 2017-02-08
Android CRITICAL 9.8
CVE-2016-8418

A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of th…

Fix: after 6.0.1
Fix from $2,300 2017-02-08
Oncommand Workflow Automation HIGH 8.1
CVE-2016-1894

NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.

Fix: after 3.1
Fix from $1,950 2017-02-07
Salt CRITICAL 9.1
CVE-2016-9639

Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.

Fix: after 2015.8.10
Fix from $2,300 2017-02-07
Security Access Manager For Web 7.0 Firmware MEDIUM 5.5
CVE-2016-3020

IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content…

Patch available
Fix from $1,600 2017-02-07
Security Key Lifecycle Manager CRITICAL 9.8
CVE-2016-6095

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cre…

Patch available
Fix from $2,300 2017-02-02
Urbancode Deploy HIGH 7.5
CVE-2016-9008

IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.

Patch available
Fix from $1,950 2017-02-01
Urbancode Deploy HIGH 7.5
CVE-2016-2942

IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processe…

Patch available
Fix from $1,950 2017-02-01