Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Coldfusion CRITICAL 9.8
CVE-2018-15961 KEVEPSS 100%

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnera…

Mitigation only
Fix from $2,300 2018-09-25
Windows 10 1607 HIGH 7.8
CVE-2018-8440 KEVEPSS 18%

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Eleva…

Patch available
Fix from $1,950 2018-09-13
Struts HIGH 8.1
CVE-2018-11776 KEVEPSS 100%

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by u…

Fix: 2.3.35 / 2.5.17+
Fix from $1,950 2018-08-22
Windows 10 1703 HIGH 8.8
CVE-2018-8414 KEVEPSS 74%

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution V…

Patch available
Fix from $1,950 2018-08-15
Windows 10 1507 HIGH 7.8
CVE-2018-8406 KEV

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX G…

Patch available
Fix from $1,950 2018-08-15
Windows 10 1507 HIGH 7.8
CVE-2018-8405 KEV

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX G…

Patch available
Fix from $1,950 2018-08-15
Internet Explorer HIGH 7.5
CVE-2018-8373 KEVEPSS 54%

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engi…

Patch available
Fix from $1,950 2018-08-15
Laravel HIGH 8.1
CVE-2018-15133 KEVEPSS 77%

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially u…

Fix: after 5.6.29
Fix from $1,950 2018-08-09
Nvrmini Firmware CRITICAL 9.8
CVE-2018-14933 KEVEPSS 95%

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir c…

Mitigation only
Fix from $2,300 2018-08-04
Routeros CRITICAL 9.1
CVE-2018-14847 KEVEPSS 96%

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary …

Fix: after 6.42
Fix from $2,300 2018-08-02
Drupal CRITICAL 9.8
CVE-2018-7602 KEVEPSS 99%

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple …

Fix: 7.59 / 8.4.8+
Fix from $2,300 2018-07-19
Chakracore HIGH 7.5
CVE-2018-8298 KEVEPSS 75%

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory …

Fix: 1.10.1+
Fix from $1,950 2018-07-11
Enterprise Linux Desktop HIGH 7.8
CVE-2018-5002 KEVEPSS 25%

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary …

Fix: after 29.0.0.171
Fix from $1,950 2018-07-09
Acrobat Dc HIGH 8.8
CVE-2018-4990 KEVEPSS 37%

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerabi…

Fix: after 18.011.20038
Fix from $1,950 2018-07-09
Prtg Network Monitor HIGH 7.2
CVE-2018-9276 KEVEPSS 87%

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administ…

Fix: 18.2.39 / 21.2.68+
Fix from $1,950 2018-07-02
Nsx Sd Wan By Velocloud HIGH 8.1
CVE-2018-6961 KEVEPSS 86%

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component i…

Fix: 3.1.0+
Fix from $1,950 2018-06-11
Debian Linux HIGH 7.5
CVE-2016-9079 KEVEPSS 87%

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting…

Fix: 45.5.1 / 50.0.2+
Fix from $1,950 2018-06-11
Adaptive Security Appliance Software HIGH 7.5
CVE-2018-0296 KEVEPSS 100%

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affec…

Fix: 6.1.0 / 6.2.2.3+
Fix from $1,950 2018-06-07
Kace System Management Appliance CRITICAL 9.8
CVE-2018-11138 KEVEPSS 92%

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be a…

Mitigation only
Fix from $2,300 2018-05-31
Coldfusion CRITICAL 9.8
CVE-2018-4939 KEVEPSS 63%

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vu…

Mitigation only
Fix from $2,300 2018-05-19
Windows 10 1607 HIGH 7.5
CVE-2018-8174 KEVEPSS 89%

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code …

Patch available
Fix from $1,950 2018-05-09
Windows 7 HIGH 7.0
CVE-2018-8120 KEVEPSS 74%

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation…

Patch available
Fix from $1,950 2018-05-09
Windows 10 1507 HIGH 8.8
CVE-2018-0824 KEVEPSS 72%

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM f…

Patch available
Fix from $1,950 2018-05-09
Gpon Router Firmware CRITICAL 9.8
CVE-2018-10562 KEVEPSS 100%

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponFo…

Mitigation only
Fix from $2,300 2018-05-04
Gpon Router Firmware CRITICAL 9.8
CVE-2018-10561 KEVEPSS 93%

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device th…

Mitigation only
Fix from $2,300 2018-05-04
Weblogic Server CRITICAL 9.8
CVE-2018-2628 KEVEPSS 99%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are af…

Patch available
Fix from $2,300 2018-04-19
Jasperreports Server HIGH 8.8
CVE-2018-5430 KEVEPSS 50%

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server fo…

Fix: after 6.4.2
Fix from $1,950 2018-04-17
Spring Data Rest CRITICAL 9.8
CVE-2018-1273 KEVEPSS 96%

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused …

Fix: after 3.0.5
Fix from $2,300 2018-04-11
Drupal CRITICAL 9.8
CVE-2018-7600 KEVEPSS 100%

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issu…

Fix: 8.3.9 / 8.4.6+
Fix from $2,300 2018-03-29
iOS MEDIUM 5.9
CVE-2018-0180 KEV

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to tri…

Mitigation only
Fix from $1,600 2018-03-28