Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Internet Explorer HIGH 8.8
CVE-2017-0210 KEVEPSS 20%

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker …

Patch available
Fix from $1,950 2017-04-12
Office HIGH 7.8
CVE-2017-0199 KEVEPSS 100%

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2…

Patch available
Fix from $1,950 2017-04-12
Tomcat CRITICAL 9.8
CVE-2016-8735 KEVEPSS 90%

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M1…

Fix: 6.0.48 / 7.0.73+
Fix from $2,300 2017-04-06
Emg2926 Firmware HIGH 8.8
CVE-2017-6884 KEVEPSS 38%

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the …

Mitigation only
Fix from $1,950 2017-04-06
Multi Router Looking Glass CRITICAL 9.8
CVE-2014-3931 KEVEPSS 29%

fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.

Fix: after 5.4.1
Fix from $2,300 2017-03-31
Internet Information Services CRITICAL 9.8
CVE-2017-7269 KEVEPSS 100%

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 200…

Patch available
Fix from $2,300 2017-03-27
iOS CRITICAL 9.8
CVE-2017-3881 KEVEPSS 99%

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated,…

Fix: after 15.1
Fix from $2,300 2017-03-17
Internet Explorer HIGH 8.8
CVE-2017-0149 KEVEPSS 29%

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf…

Patch available
Fix from $1,950 2017-03-17
Server Message Block HIGH 8.1
CVE-2017-0148 KEVEPSS 99%

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Win…

Fix: 4.0e+
Fix from $1,950 2017-03-17
Windows 10 1507 HIGH 7.5
CVE-2017-0147 KEVEPSS 100%

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Win…

Patch available
Fix from $1,950 2017-03-17
Server Message Block HIGH 8.8
CVE-2017-0146 KEVEPSS 90%

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Win…

Fix: after 4.0e
Fix from $1,950 2017-03-17
Server Message Block HIGH 8.8
CVE-2017-0145 KEVEPSS 90%

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Win…

Fix: 4.0e+
Fix from $1,950 2017-03-17
Server Message Block HIGH 8.8
CVE-2017-0144 KEVEPSS 99%

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Win…

Fix: 4.0e+
Fix from $1,950 2017-03-17
Server Message Block HIGH 8.8
CVE-2017-0143 KEVEPSS 93%

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Win…

Fix: 4.0e+
Fix from $1,950 2017-03-17
Windows 7 HIGH 7.8
CVE-2017-0101 KEVEPSS 57%

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Se…

Patch available
Fix from $1,950 2017-03-17
Xml Core Services MEDIUM 6.5
CVE-2017-0022 KEVEPSS 18%

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP…

Patch available
Fix from $1,600 2017-03-17
Windows 10 1507 HIGH 7.8
CVE-2017-0005 KEVEPSS 11%

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 20…

Patch available
Fix from $1,950 2017-03-17
Windows 10 1507 HIGH 7.8
CVE-2017-0001 KEV

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 20…

Patch available
Fix from $1,950 2017-03-17
Struts CRITICAL 9.8
CVE-2017-5638 KEVEPSS 100%

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message gene…

Fix: 2.3.32 / 2.5.10.1+
Fix from $2,300 2017-03-11
Dgn2200 Series Firmware HIGH 8.8
CVE-2017-6334 KEVEPSS 72%

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell…

Fix: after 10.0.0.50
Fix from $1,950 2017-03-06
Edge HIGH 8.1
CVE-2017-0037 KEVEPSS 80%

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnS…

Patch available
Fix from $1,950 2017-02-26
Dgn2200 Firmware CRITICAL 9.8
CVE-2017-6077 KEVEPSS 68%

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell meta…

Fix: after 10.0.0.50
Fix from $2,300 2017-02-22
D6100 Firmware CRITICAL 9.8
CVE-2016-10174 KEVEPSS 83%

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buff…

Mitigation only
Fix from $2,300 2017-01-30
Chrome HIGH 8.8
CVE-2016-5198 KEVEPSS 35%

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisati…

Fix: 54.0.2840.85 / 54.0.2840.87+
Fix from $1,950 2017-01-19
R6200 Firmware HIGH 8.1
CVE-2017-5521 KEVEPSS 89%

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 device…

Mitigation only
Fix from $1,950 2017-01-17
WordPress CRITICAL 9.8
CVE-2016-10033 KEVEPSS 100%

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command an…

Fix: 5.2.18+
Fix from $2,300 2016-12-30
Excel HIGH 7.8
CVE-2016-7262 KEVEPSS 58%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-a…

Patch available
Fix from $1,950 2016-12-20
Flash Player Desktop Runtime HIGH 8.8
CVE-2016-7892 KEVEPSS 19%

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class.…

Fix: after 23.0.0.207
Fix from $1,950 2016-12-15
D6220 Firmware HIGH 8.8
CVE-2016-6277 KEVEPSS 100%

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.…

Fix: after 1.0.7.2_1.1.93
Fix from $1,950 2016-12-14
Netweaver Application Server Java MEDIUM 6.5
CVE-2016-9563 KEVEPSS 24%

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi…

Mitigation only
Fix from $1,600 2016-11-23