Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Openshift Ai HIGH 8.8
CVE-2026-42271 KEVEPSS 83%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…

Fix: 1.83.7 / 2.25.8+
Fix from $1,950 2026-05-08
Codeready Linux Builder HIGH 8.8
CVE-2019-8720 KEV

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution.…

Mitigation only
Fix from $1,950 2023-03-06
Enterprise Linux Server Update Services For Sap Solutions HIGH 7.8
CVE-2021-4034 KEVEPSS 95%

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

Patch available
Fix from $1,950 2022-01-28
Enterprise Linux CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …

Patch available
Fix from $2,300 2021-09-16
Enterprise Linux Desktop HIGH 7.8
CVE-2018-15982 KEVEPSS 82%

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to a…

Fix: after 31.0.0.153
Fix from $1,950 2019-01-18
Richfaces CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…

Fix: after 3.3.4
Fix from $2,300 2018-11-06
Enterprise Linux Desktop HIGH 7.8
CVE-2018-5002 KEVEPSS 25%

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary …

Fix: after 29.0.0.171
Fix from $1,950 2018-07-09
Enterprise Linux Desktop HIGH 7.8
CVE-2018-4878 KEVEPSS 90%

A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Pri…

Fix: 28.0.0.161+
Fix from $1,950 2018-02-06
Enterprise Linux Desktop HIGH 8.8
CVE-2017-11292 KEVEPSS 12%

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the…

Fix: after 27.0.0.159
Fix from $1,950 2017-10-22
Enterprise Linux HIGH 7.8
CVE-2017-1000253 KEVEPSS 11%

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ…

Fix: 3.2.70 / 3.4.109+
Fix from $1,950 2017-10-05
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-12149 KEVEPSS 91%

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessF…

Mitigation only
Fix from $2,300 2017-10-04
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7855 KEVEPSS 25%

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to …

Fix: after 23.0.0.185
Fix from $1,950 2016-11-01
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4171 KEVEPSS 20%

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as expl…

Fix: after 21.0.0.242
Fix from $2,300 2016-06-16
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4117 KEVEPSS 94%

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May …

Fix: after 21.0.0.226
Fix from $2,300 2016-05-11
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-3718 KEVEPSS 77%

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (…

Patch available
Fix from $1,600 2016-05-05
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-3715 KEVEPSS 75%

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

Patch available
Fix from $1,600 2016-05-05
Enterprise Linux Desktop HIGH 8.8
CVE-2015-8651 KEVEPSS 68%

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Ad…

Fix: 11.2.202.559 / 18.0.0.324+
Fix from $1,950 2015-12-28
Satellite MEDIUM 5.3
CVE-2015-4902 KEVEPSS 13%

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployme…

Patch available
Fix from $1,600 2015-10-22
Enterprise Linux Desktop HIGH 7.8
CVE-2015-7645 KEVEPSS 68%

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attac…

Fix: after 18.0.0.252
Fix from $1,950 2015-10-15
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5123 KEVEPSS 18%

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Wind…

Fix: after 18.0.0.203
Fix from $2,300 2015-07-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5122 KEVEPSS 94%

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on W…

Fix: after 18.0.0.204
Fix from $2,300 2015-07-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5119 KEVEPSS 99%

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x…

Fix: after 18.0.0.194
Fix from $2,300 2015-07-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3113 KEVEPSS 100%

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46…

Fix: 11.2.202.468 / 13.0.0.296+
Fix from $2,300 2015-06-23
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3043 KEVEPSS 74%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: 11.2.202.457 / 13.0.0.281+
Fix from $2,300 2015-04-14
Subscription Asset Manager HIGH 7.5
CVE-2014-0130 KEVEPSS 54%

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18,…

Fix: 3.2.18 / 4.0.5+
Fix from $1,950 2014-05-07
Enterprise Linux Desktop HIGH 8.8
CVE-2014-0502 KEVEPSS 24%

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.…

Fix: 4.0.0.1628 / 11.2.202.341+
Fix from $1,950 2014-02-21
Enterprise Linux Desktop CRITICAL 9.8
CVE-2013-2729 KEVEPSS 67%

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code…

Fix: 9.5.5 / 10.1.7+
Fix from $2,300 2013-05-16
Enterprise Linux Desktop HIGH 8.8
CVE-2013-0643 KEVEPSS 11%

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x be…

Fix: 10.3.183.67 / 11.2.202.273+
Fix from $1,950 2013-02-27
Enterprise Linux Desktop HIGH 8.8
CVE-2013-0648 KEVEPSS 11%

Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 o…

Fix: 10.3.183.67 / 11.2.202.273+
Fix from $1,950 2013-02-27
Enterprise Linux Desktop HIGH 7.8
CVE-2013-0640 KEVEPSS 87%

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a de…

Fix: 9.5.4 / 10.1.6+
Fix from $1,950 2013-02-14