91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,301–1,350 of 1,734 in KEV · page 27 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2018-8639 | Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability KEVMicrosoft | Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker… |
| CVE-2018-8611 | Microsoft Windows Kernel Privilege Escalation Vulnerability KEVMicrosoft | A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. |
| CVE-2018-8589 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability coul… |
| CVE-2018-8581 | Microsoft Exchange Server Privilege Escalation Vulnerability KEVMicrosoft | A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonat… |
| CVE-2018-8453 | Microsoft Win32k Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. |
| CVE-2018-8440 | Microsoft Windows Privilege Escalation Vulnerability KEVMicrosoft | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). |
| CVE-2018-8414 | Microsoft Windows Shell Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths. |
| CVE-2018-8406 | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability KEVMicrosoft | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. |
| CVE-2018-8405 | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability KEVMicrosoft | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. |
| CVE-2018-8373 | Microsoft Scripting Engine Memory Corruption Vulnerability KEVMicrosoft | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. |
| CVE-2018-8298 | ChakraCore Scripting Engine Type Confusion Vulnerability KEVChakraCore | The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. |
| CVE-2018-8174 | Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability KEVCVSS 7.5Microsoft | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" |
| CVE-2018-8120 | Microsoft Win32k Privilege Escalation Vulnerability KEVCVSS 7.0Microsoft | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. |
| CVE-2018-7841 | Schneider Electric U.motion Builder SQL Injection Vulnerability KEVSchneider Electric | A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. |
| CVE-2018-7602 | Drupal Core Remote Code Execution Vulnerability KEVCVSS 9.8Drupal | A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. |
| CVE-2018-7600 | Drupal Core Remote Code Execution Vulnerability KEVDrupal | Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in compl… |
| CVE-2018-7445 | MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability KEVMikroTik | In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can ex… |
| CVE-2018-6961 | VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability KEVVMware | VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in… |
| CVE-2018-6882 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability KEVCVSS 6.1Synacor | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. |
| CVE-2018-6789 | Exim Buffer Overflow Vulnerability KEVExim | Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. |
| CVE-2018-6530 | D-Link Multiple Routers OS Command Injection Vulnerability KEVD-Link | Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. |
| CVE-2018-6065 | Google Chromium V8 Integer Overflow Vulnerability KEVGoogle | Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
| CVE-2018-5430 | TIBCO JasperReports Server Information Disclosure Vulnerability KEVTIBCO | TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including ke… |
| CVE-2018-5002 | Adobe Flash Player Stack-based Buffer Overflow Vulnerability KEVAdobe | Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. |
| CVE-2018-4990 | Adobe Acrobat and Reader Double Free Vulnerability KEVAdobe | Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution. |
| CVE-2018-4939 | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability KEVAdobe | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. |
| CVE-2018-4878 | Adobe Flash Player Use-After-Free Vulnerability KEVAdobe | Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. |
| CVE-2018-4344 | Apple Multiple Products Memory Corruption Vulnerability KEVApple | Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. |
| CVE-2018-4063 | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability KEVSierra Wireless | Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, re… |
| CVE-2018-2628 | Oracle WebLogic Server Unspecified Vulnerability KEVOracle | Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. |
| CVE-2018-2380 | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability KEVSAP | SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path informati… |
| CVE-2018-20753 | Kaseya VSA Remote Code Execution Vulnerability KEVCVSS 9.8Kaseya | Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. |
| CVE-2018-20250 | WinRAR Absolute Path Traversal Vulnerability KEVCVSS 7.8RARLAB | WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution |
| CVE-2018-20062 | ThinkPHP "noneCms" Remote Code Execution Vulnerability KEVThinkPHP | ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. |
| CVE-2018-19953 | QNAP NAS File Station Cross-Site Scripting Vulnerability KEVCVSS 6.1QNAP | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. |
| CVE-2018-19949 | QNAP NAS File Station Command Injection Vulnerability KEVCVSS 9.8QNAP | A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. |
| CVE-2018-19943 | QNAP NAS File Station Cross-Site Scripting Vulnerability KEVCVSS 8.0QNAP | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. |
| CVE-2018-19410 | Paessler PRTG Network Monitor Local File Inclusion Vulnerability KEVPaessler | Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write priv… |
| CVE-2018-19323 | GIGABYTE Multiple Products Privilege Escalation Vulnerability KEVCVSS 9.8GIGABYTE | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write … |
| CVE-2018-19322 | GIGABYTE Multiple Products Code Execution Vulnerability KEVCVSS 7.8GIGABYTE | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write d… |
| CVE-2018-19321 | GIGABYTE Multiple Products Privilege Escalation Vulnerability KEVCVSS 7.8GIGABYTE | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and wri… |
| CVE-2018-19320 | GIGABYTE Multiple Products Unspecified Vulnerability KEVCVSS 7.8GIGABYTE | The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that coul… |
| CVE-2018-18809 | TIBCO JasperReports Library Directory Traversal Vulnerability KEVTIBCO | TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. |
| CVE-2018-18325 | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability KEVDotNetNuke (DNN) | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. Th… |
| CVE-2018-17480 | Google Chromium V8 Out-of-Bounds Write Vulnerability KEVGoogle | Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. Th… |
| CVE-2018-17463 | Google Chromium V8 Remote Code Execution Vulnerability KEVGoogle | Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vu… |
| CVE-2018-15982 | Adobe Flash Player Use-After-Free Vulnerability KEVCVSS 7.8Adobe | Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability |
| CVE-2018-15961 | Adobe ColdFusion Unrestricted File Upload Vulnerability KEVAdobe | Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. |
| CVE-2018-15811 | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability KEVDotNetNuke (DNN) | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. |
| CVE-2018-15133 | Laravel Deserialization of Untrusted Data Vulnerability KEVLaravel | Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited i… |