Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2017-16651 KEVEPSS 37%

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, i…

Fix: after 1.1.9
Fix from $1,950 2017-11-09
Chrome HIGH 8.8
CVE-2017-5070 KEVEPSS 31%

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to e…

Fix: 59.0.3071.86 / 59.0.3071.92+
Fix from $1,950 2017-10-27
Enterprise Linux Desktop HIGH 8.8
CVE-2017-11292 KEVEPSS 12%

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the…

Fix: after 27.0.0.159
Fix from $1,950 2017-10-22
Weblogic Server HIGH 7.5
CVE-2017-10271 KEVEPSS 100%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected …

Patch available
Fix from $1,950 2017-10-19
Office Compatibility Pack HIGH 7.8
CVE-2017-11826 KEVEPSS 81%

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer…

Patch available
Fix from $1,950 2017-10-13
Outlook HIGH 7.8
CVE-2017-11774 KEVEPSS 60%

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Offic…

Patch available
Fix from $1,950 2017-10-13
Enterprise Linux HIGH 7.8
CVE-2017-1000253 KEVEPSS 11%

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ…

Fix: 3.2.70 / 3.4.109+
Fix from $1,950 2017-10-05
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…

Mitigation only
Fix from $2,300 2017-10-04
Tomcat HIGH 8.1
CVE-2017-12617 KEVEPSS 100%

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…

Fix: 7.0.82 / 8.0.47+
Fix from $1,950 2017-10-04
iOS CRITICAL 9.8
CVE-2017-12240 KEVEPSS 14%

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remot…

Fix: after 15.6
Fix from $2,300 2017-09-29
iOS MEDIUM 6.5
CVE-2017-12238 KEV

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an …

Fix: after 15.4
Fix from $1,600 2017-09-29
iOS HIGH 7.5
CVE-2017-12237 KEVEPSS 7%

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an…

Fix: after 16.5
Fix from $1,950 2017-09-29
iOS HIGH 7.5
CVE-2017-12235 KEVEPSS 7%

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an un…

Fix: after 15.6
Fix from $1,950 2017-09-29
iOS HIGH 7.5
CVE-2017-12234 KEVEPSS 7%

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthen…

Fix: after 15.6
Fix from $1,950 2017-09-29
iOS HIGH 7.5
CVE-2017-12233 KEVEPSS 7%

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthen…

Fix: after 15.6
Fix from $1,950 2017-09-29
iOS MEDIUM 6.5
CVE-2017-12232 KEV

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through…

Fix: after 15.6
Fix from $1,600 2017-09-29
iOS HIGH 7.5
CVE-2017-12231 KEVEPSS 7%

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticate…

Fix: after 15.6
Fix from $1,950 2017-09-29
Dir 626l Firmware CRITICAL 9.8
CVE-2015-1187 KEVEPSS 83%

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

Mitigation only
Fix from $2,300 2017-09-21
Tomcat HIGH 8.1
CVE-2017-12615 KEVEPSS 100%

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t…

Fix: after 7.0.79
Fix from $1,950 2017-09-19
Struts HIGH 8.1
CVE-2017-9805 KEVEPSS 99%

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for des…

Fix: 2.3.34 / 2.5.13+
Fix from $1,950 2017-09-15
.net Framework HIGH 7.8
CVE-2017-8759 KEVEPSS 87%

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or app…

Patch available
Fix from $1,950 2017-09-13
iOS HIGH 7.5
CVE-2017-6627 KEVEPSS 6%

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,950 2017-09-07
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2017-11357 KEVEPSS 76%

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to per…

Fix: 2020.1.114+
Fix from $2,300 2017-08-23
Ui For Asp.net Ajax CRITICAL 9.8
CVE-2017-11317 KEVEPSS 83%

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows rem…

Fix: after 2016.3.1027
Fix from $2,300 2017-08-23
Message Gateway HIGH 8.8
CVE-2017-6327 KEVEPSS 35%

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual m…

Fix: 10.6.3-267+
Fix from $1,950 2017-08-11
Ethernet Diagnostics Driver Iqvw32.sys HIGH 7.8
CVE-2015-2291 KEVEPSS 9%

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a de…

Patch available
Fix from $1,950 2017-08-09
Netweaver Application Server Java HIGH 7.5
CVE-2017-12637 KEVEPSS 95%

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a…

Mitigation only
Fix from $1,950 2017-08-07
iOS MEDIUM 6.5
CVE-2017-6663 KEV

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker…

Mitigation only
Fix from $1,600 2017-08-07
Dotnetnuke HIGH 8.8
CVE-2017-9822 KEVEPSS 95%

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

Fix: 9.1.1+
Fix from $1,950 2017-07-20
Netscaler Sd Wan CRITICAL 9.8
CVE-2017-6316 KEVEPSS 73%

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. O…

Fix: after 9.1.2.26.561201
Fix from $2,300 2017-07-20