Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aleos HIGH 8.8
CVE-2018-4063 KEVEPSS 28%

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially craf…

Fix: 4.4.9 / 4.9.4+
Fix from $1,950 2019-05-06
5200w T Firmware CRITICAL 9.8
CVE-2017-18368 KEVEPSS 95%

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remo…

Mitigation only
Fix from $2,300 2019-05-02
Am 100 Firmware CRITICAL 9.8
CVE-2019-3929 KEVEPSS 99%

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befo…

Fix: 2.4.1.19+
Fix from $2,300 2019-04-30
Zimbra Collaboration Suite HIGH 7.5
CVE-2019-9621 KEVEPSS 81%

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows S…

Fix: 8.6.0 / 8.7.11+
Fix from $1,950 2019-04-30
Agile Plm CRITICAL 9.8
CVE-2019-2725 KEVEPSS 100%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected …

Fix: 5.2.36 / 6.0.16+
Fix from $2,300 2019-04-26
Connect Secure HIGH 7.2
CVE-2019-11539 KEVEPSS 99%

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse P…

Mitigation only
Fix from $1,950 2019-04-26
Business Intelligence Publisher HIGH 7.2
CVE-2019-2616 KEVEPSS 92%

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported ver…

Patch available
Fix from $1,950 2019-04-23
Confluence Server HIGH 8.8
CVE-2019-3398 KEVEPSS 97%

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to …

Fix: 6.6.13 / 6.12.4+
Fix from $1,950 2019-04-18
Windows 10 1507 HIGH 7.8
CVE-2019-0859 KEV

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation…

Patch available
Fix from $1,950 2019-04-09
Windows 10 1703 HIGH 7.8
CVE-2019-0841 KEVEPSS 41%

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation o…

Patch available
Fix from $1,950 2019-04-09
Windows 10 1507 HIGH 7.8
CVE-2019-0803 KEVEPSS 45%

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation…

Patch available
Fix from $1,950 2019-04-09
Internet Explorer HIGH 7.5
CVE-2019-0752 KEVEPSS 82%

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engi…

Patch available
Fix from $1,950 2019-04-09
Windows 7 HIGH 7.8
CVE-2019-0808 KEVEPSS 53%

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation…

Patch available
Fix from $1,950 2019-04-09
Windows 10 1507 HIGH 7.8
CVE-2019-0797 KEV

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation…

Patch available
Fix from $1,950 2019-04-09
Windows 10 1507 MEDIUM 6.5
CVE-2019-0703 KEVEPSS 10%

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosu…

Patch available
Fix from $1,600 2019-04-09
HTTP Server HIGH 7.8
CVE-2019-0211 KEVEPSS 65%

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads …

Fix: after 2.4.38
Fix from $1,950 2019-04-08
Rlc 410w Firmware HIGH 7.2
CVE-2019-11001 KEVEPSS 38%

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to …

Fix: after 1.0.227
Fix from $1,950 2019-04-08
Iphone Os HIGH 7.8
CVE-2018-4344 KEV

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, wat…

Fix: 5.0 / 10.14+
Fix from $1,950 2019-04-03
Rails HIGH 7.5
CVE-2019-5418 KEVEPSS 99%

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers…

Fix: 4.2.11.1 / 5.0.7.2+
Fix from $1,950 2019-03-27
Xperience CRITICAL 9.8
CVE-2019-10068 KEVEPSS 96%

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validat…

Fix: 10.0.52 / 11.0.48+
Fix from $2,300 2019-03-26
Kibana CRITICAL 10.0
CVE-2019-7609 KEVEPSS 95%

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion …

Fix: 5.6.15 / 6.6.1+
Fix from $2,300 2019-03-25
Confluence Server CRITICAL 9.8
CVE-2019-3396 KEVEPSS 100%

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the …

Fix: 6.6.12 / 6.12.3+
Fix from $2,300 2019-03-25
Social Warfare MEDIUM 6.1
CVE-2019-9978 KEVEPSS 73%

The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as expl…

Fix: 3.5.3+
Fix from $1,600 2019-03-24
Nexus Repository Manager CRITICAL 9.8
CVE-2019-7238 KEVEPSS 77%

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Fix: 3.15.0+
Fix from $2,300 2019-03-21
Pipeline\ CRITICAL 9.9
CVE-2019-1003030 KEVEPSS 97%

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cp…

Fix: after 2.63
Fix from $2,300 2019-03-08
Script Security CRITICAL 9.9
CVE-2019-1003029 KEVEPSS 74%

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbo…

Fix: after 1.53
Fix from $2,300 2019-03-08
Jasperreports Library MEDIUM 6.5
CVE-2018-18809 KEVEPSS 79%

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperRe…

Fix: after 7.1.0
Fix from $1,600 2019-03-07
Internet Explorer MEDIUM 6.5
CVE-2019-0676 KEVEPSS 8%

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited thi…

Patch available
Fix from $1,600 2019-03-05
Sharepoint Enterprise Server CRITICAL 9.8
CVE-2019-0604 KEVEPSS 100%

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, ak…

Patch available
Fix from $2,300 2019-03-05
Iphone Os HIGH 7.5
CVE-2019-6223 KEV

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.…

Fix: 10.14.3 / 12.1.4+
Fix from $1,950 2019-03-05