91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,301–1,350 of 1,734 in KEV · page 27 of 35

IDTitleSummary
CVE-2018-8639Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
KEVMicrosoft
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker…
CVE-2018-8611Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
CVE-2018-8589Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability coul…
CVE-2018-8581Microsoft Exchange Server Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonat…
CVE-2018-8453Microsoft Win32k Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
CVE-2018-8440Microsoft Windows Privilege Escalation Vulnerability
KEVMicrosoft
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
CVE-2018-8414Microsoft Windows Shell Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
CVE-2018-8406Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
KEVMicrosoft
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
CVE-2018-8405Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
KEVMicrosoft
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
CVE-2018-8373Microsoft Scripting Engine Memory Corruption Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
CVE-2018-8298ChakraCore Scripting Engine Type Confusion Vulnerability
KEVChakraCore
The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
CVE-2018-8174Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
KEVCVSS 7.5Microsoft
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
CVE-2018-8120Microsoft Win32k Privilege Escalation Vulnerability
KEVCVSS 7.0Microsoft
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
CVE-2018-7841Schneider Electric U.motion Builder SQL Injection Vulnerability
KEVSchneider Electric
A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
CVE-2018-7602Drupal Core Remote Code Execution Vulnerability
KEVCVSS 9.8Drupal
A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-7600Drupal Core Remote Code Execution Vulnerability
KEVDrupal
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in compl…
CVE-2018-7445MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability
KEVMikroTik
In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session request messages. Remote attackers with access to the service can ex…
CVE-2018-6961VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability
KEVVMware
VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in…
CVE-2018-6882Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
KEVCVSS 6.1Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
CVE-2018-6789Exim Buffer Overflow Vulnerability
KEVExim
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
CVE-2018-6530D-Link Multiple Routers OS Command Injection Vulnerability
KEVD-Link
Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.
CVE-2018-6065Google Chromium V8 Integer Overflow Vulnerability
KEVGoogle
Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML pa…
CVE-2018-5430TIBCO JasperReports Server Information Disclosure Vulnerability
KEVTIBCO
TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including ke…
CVE-2018-5002Adobe Flash Player Stack-based Buffer Overflow Vulnerability
KEVAdobe
Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
CVE-2018-4990Adobe Acrobat and Reader Double Free Vulnerability
KEVAdobe
Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
CVE-2018-4939Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
KEVAdobe
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
CVE-2018-4878Adobe Flash Player Use-After-Free Vulnerability
KEVAdobe
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
CVE-2018-4344Apple Multiple Products Memory Corruption Vulnerability
KEVApple
Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.
CVE-2018-4063Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
KEVSierra Wireless
Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, re…
CVE-2018-2628Oracle WebLogic Server Unspecified Vulnerability
KEVOracle
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
CVE-2018-2380SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
KEVSAP
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path informati…
CVE-2018-20753Kaseya VSA Remote Code Execution Vulnerability
KEVCVSS 9.8Kaseya
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
CVE-2018-20250WinRAR Absolute Path Traversal Vulnerability
KEVCVSS 7.8RARLAB
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
CVE-2018-20062ThinkPHP "noneCms" Remote Code Execution Vulnerability
KEVThinkPHP
ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
CVE-2018-19953QNAP NAS File Station Cross-Site Scripting Vulnerability
KEVCVSS 6.1QNAP
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2018-19949QNAP NAS File Station Command Injection Vulnerability
KEVCVSS 9.8QNAP
A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
CVE-2018-19943QNAP NAS File Station Cross-Site Scripting Vulnerability
KEVCVSS 8.0QNAP
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2018-19410Paessler PRTG Network Monitor Local File Inclusion Vulnerability
KEVPaessler
Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write priv…
CVE-2018-19323GIGABYTE Multiple Products Privilege Escalation Vulnerability
KEVCVSS 9.8GIGABYTE
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write …
CVE-2018-19322GIGABYTE Multiple Products Code Execution Vulnerability
KEVCVSS 7.8GIGABYTE
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write d…
CVE-2018-19321GIGABYTE Multiple Products Privilege Escalation Vulnerability
KEVCVSS 7.8GIGABYTE
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and wri…
CVE-2018-19320GIGABYTE Multiple Products Unspecified Vulnerability
KEVCVSS 7.8GIGABYTE
The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that coul…
CVE-2018-18809TIBCO JasperReports Library Directory Traversal Vulnerability
KEVTIBCO
TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.
CVE-2018-18325DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
KEVDotNetNuke (DNN)
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. Th…
CVE-2018-17480Google Chromium V8 Out-of-Bounds Write Vulnerability
KEVGoogle
Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. Th…
CVE-2018-17463Google Chromium V8 Remote Code Execution Vulnerability
KEVGoogle
Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vu…
CVE-2018-15982Adobe Flash Player Use-After-Free Vulnerability
KEVCVSS 7.8Adobe
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
CVE-2018-15961Adobe ColdFusion Unrestricted File Upload Vulnerability
KEVAdobe
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.
CVE-2018-15811DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
KEVDotNetNuke (DNN)
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
CVE-2018-15133Laravel Deserialization of Untrusted Data Vulnerability
KEVLaravel
Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited i…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.