Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thinkphp HIGH 8.8
CVE-2019-9082 KEVEPSS 97%

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefu…

Fix: 3.2.4+
Fix from $1,950 2019-02-24
Drupal HIGH 8.1
CVE-2019-6340 KEVEPSS 92%

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to a…

Fix: 8.5.11 / 8.6.10+
Fix from $1,950 2019-02-21
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2019-8394 KEVEPSS 63%

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

Fix: 10.0.0+
Fix from $1,600 2019-02-17
Winrar HIGH 7.8
CVE-2018-20250 KEVEPSS 96%

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.…

Fix: after 5.61
Fix from $1,950 2019-02-05
Virtual System Administrator CRITICAL 9.8
CVE-2018-20753 KEVEPSS 29%

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payload…

Fix: 9.3.0.35 / 9.4.0.36+
Fix from $2,300 2019-02-05
Manageditsync CRITICAL 9.8
CVE-2017-18362 KEVEPSS 87%

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to t…

Fix: after 2017
Fix from $2,300 2019-02-05
Rv320 Firmware HIGH 7.5
CVE-2019-1653 KEVEPSS 100%

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentic…

Mitigation only
Fix from $1,950 2019-01-24
Rv320 Firmware HIGH 7.2
CVE-2019-1652 KEVEPSS 96%

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticat…

Fix: 1.4.2.22+
Fix from $1,950 2019-01-24
Enterprise Linux Desktop HIGH 7.8
CVE-2018-15982 KEVEPSS 82%

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to a…

Fix: after 31.0.0.153
Fix from $1,950 2019-01-18
Windows 10 1507 HIGH 7.8
CVE-2019-0543 KEV

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege…

Patch available
Fix from $1,950 2019-01-08
Internet Explorer HIGH 8.8
CVE-2019-0541 KEVEPSS 53%

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution V…

Patch available
Fix from $1,950 2019-01-08
Aorus Graphics Engine CRITICAL 9.8
CVE-2018-19323 KEVEPSS 9%

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GU…

Fix: 1.26 / 1.57+
Fix from $2,300 2018-12-21
Aorus Graphics Engine HIGH 7.8
CVE-2018-19322 KEV

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.…

Fix: 1.26 / 1.57+
Fix from $1,950 2018-12-21
Aorus Graphics Engine HIGH 7.8
CVE-2018-19321 KEV

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.…

Fix: 1.26 / 1.57+
Fix from $1,950 2018-12-21
Aorus Graphics Engine HIGH 7.8
CVE-2018-19320 KEV

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GU…

Fix: 1.26 / 1.57+
Fix from $1,950 2018-12-21
Internet Explorer HIGH 7.5
CVE-2018-8653 KEVEPSS 24%

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engi…

Patch available
Fix from $1,950 2018-12-20
Windows 10 1507 HIGH 7.8
CVE-2018-8639 KEVEPSS 22%

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation…

Patch available
Fix from $1,950 2018-12-12
Windows 10 1607 HIGH 7.8
CVE-2018-8611 KEV

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of P…

Patch available
Fix from $1,950 2018-12-12
Nonecms CRITICAL 9.8
CVE-2018-20062 KEVEPSS 100%

An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the …

Mitigation only
Fix from $2,300 2018-12-11
Chrome HIGH 8.8
CVE-2018-17480 KEVEPSS 36%

Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 all…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Jenkins CRITICAL 9.8
CVE-2018-1000861 KEVEPSS 98%

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/mai…

Fix: after 2.153
Fix from $2,300 2018-12-10
Prtg Network Monitor CRITICAL 9.8
CVE-2018-19410 KEVEPSS 87%

PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator)…

Fix: 18.2.40.1683+
Fix from $2,300 2018-11-21
Chrome HIGH 8.8
CVE-2018-6065 KEVEPSS 60%

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 a…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-17463 KEVEPSS 85%

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox vi…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Windows 7 HIGH 7.8
CVE-2018-8589 KEV

An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulner…

Patch available
Fix from $1,950 2018-11-14
Exchange Server HIGH 7.4
CVE-2018-8581 KEVEPSS 27%

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." Th…

Patch available
Fix from $1,950 2018-11-14
Richfaces CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…

Fix: after 3.3.4
Fix from $2,300 2018-11-06
Ac7 Firmware CRITICAL 9.8
CVE-2018-14558 KEVEPSS 9%

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9)…

Fix: after 15.03.06.44_cn
Fix from $2,300 2018-10-30
Windows 10 1507 HIGH 7.8
CVE-2018-8453 KEVEPSS 70%

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation…

Patch available
Fix from $1,950 2018-10-10
Pan Os HIGH 7.8
CVE-2018-14634 KEVEPSS 15%

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise p…

Fix: 7.1.23 / 8.0.16+
Fix from $1,950 2018-09-25