Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1507 HIGH 7.8
CVE-2019-1405 KEVEPSS 30%

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Wi…

Patch available
Fix from $1,950 2019-11-12
Windows 10 1507 HIGH 7.8
CVE-2019-1388 KEVEPSS 9%

An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Cert…

Patch available
Fix from $1,950 2019-11-12
Windows 10 1709 HIGH 7.8
CVE-2019-1385 KEV

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acc…

Patch available
Fix from $1,950 2019-11-12
Officescan HIGH 7.5
CVE-2019-18187 KEVEPSS 25%

Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files f…

Mitigation only
Fix from $1,950 2019-10-28
PHP CRITICAL 9.8
CVE-2019-11043 KEVEPSS 99%

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM modu…

Fix: 7.1.33 / 7.2.24+
Fix from $2,300 2019-10-28
Solaris HIGH 8.8
CVE-2019-3010 KEVEPSS 13%

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploit…

Patch available
Fix from $1,950 2019-10-16
Nostromo Nhttpd CRITICAL 9.8
CVE-2019-16278 KEVEPSS 99%

Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HT…

Fix: 1.9.7+
Fix from $2,300 2019-10-14
Debian Linux HIGH 7.8
CVE-2019-2215 KEVEPSS 44%

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit thi…

Patch available
Fix from $1,950 2019-10-11
Windows 10 1803 HIGH 7.8
CVE-2019-1322 KEVEPSS 19%

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege…

Patch available
Fix from $1,950 2019-10-10
Windows 10 1607 HIGH 7.8
CVE-2019-1315 KEV

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manag…

Patch available
Fix from $1,950 2019-10-10
Ubuntu Linux CRITICAL 9.8
CVE-2019-16928 KEVEPSS 42%

Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string…

Fix: after 4.92.2
Fix from $2,300 2019-09-27
Dir 655 Firmware CRITICAL 9.8
CVE-2019-16920 KEVEPSS 100%

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker…

Fix: after 3.02b05
Fix from $2,300 2019-09-27
Vbulletin CRITICAL 9.8
CVE-2019-16759 KEVEPSS 100%

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

Fix: after 5.5.4
Fix from $2,300 2019-09-24
Internet Explorer HIGH 7.5
CVE-2019-1367 KEVEPSS 45%

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engi…

Patch available
Fix from $1,950 2019-09-23
Dns 320 Firmware CRITICAL 9.8
CVE-2019-16057 KEVEPSS 87%

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

Fix: after 2.05.b10
Fix from $2,300 2019-09-16
S\@t Browser CRITICAL 9.8
CVE-2019-16256 KEV

Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location a…

Mitigation only
Fix from $2,300 2019-09-12
Excel HIGH 8.8
CVE-2019-1297 KEVEPSS 22%

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft…

Patch available
Fix from $1,950 2019-09-11
Windows 10 1703 HIGH 7.8
CVE-2019-1253 KEVEPSS 12%

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an…

Patch available
Fix from $1,950 2019-09-11
Windows 10 1507 HIGH 7.8
CVE-2019-1215 KEVEPSS 19%

An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege V…

Patch available
Fix from $1,950 2019-09-11
Windows 10 1507 HIGH 7.8
CVE-2019-1214 KEV

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windo…

Patch available
Fix from $1,950 2019-09-11
Nagios Xi HIGH 8.8
CVE-2019-15949 KEVEPSS 77%

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin …

Fix: 5.6.6+
Fix from $1,950 2019-09-05
Storefront Server HIGH 7.5
CVE-2019-13608 KEVEPSS 30%

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

Fix: 3.0.8000 / 3.12.4000+
Fix from $1,950 2019-08-29
Docker HIGH 7.8
CVE-2019-15752 KEVEPSS 32%

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in…

Fix: 2.1.0.1+
Fix from $1,950 2019-08-28
Webmin CRITICAL 9.8
CVE-2019-15107 KEVEPSS 100%

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

Fix: after 1.920
Fix from $2,300 2019-08-16
Commerce Cloud CRITICAL 9.8
CVE-2019-0344 KEVEPSS 7%

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex…

Mitigation only
Fix from $2,300 2019-08-14
Jira Server CRITICAL 9.8
CVE-2019-11581 KEVEPSS 85%

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. A…

Fix: 7.6.14 / 7.13.5+
Fix from $2,300 2019-08-09
Solr HIGH 7.2
CVE-2019-0193 KEVEPSS 84%

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh…

Fix: 7.7.3 / 8.1.2+
Fix from $1,950 2019-08-01
Firefox CRITICAL 10.0
CVE-2019-11708 KEVEPSS 56%

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent …

Fix: 60.7.2 / 67.0.4+
Fix from $2,300 2019-07-23
Firefox HIGH 8.8
CVE-2019-11707 KEVEPSS 38%

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We…

Fix: 60.7.1 / 60.7.2+
Fix from $1,950 2019-07-23
Pan Os HIGH 8.1
CVE-2019-1579 KEVEPSS 46%

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalPro…

Fix: 7.1.19 / 8.0.12+
Fix from $1,950 2019-07-19