91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,351–1,400 of 1,734 in KEV · page 28 of 35

IDTitleSummary
CVE-2018-14933NUUO NVRmini Devices OS Command Injection Vulnerability
KEVNUUO
NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddi…
CVE-2018-14847MikroTik Router OS Directory Traversal Vulnerability
KEVMikroTik
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due …
CVE-2018-14839LG N1A1 NAS Remote Command Execution Vulnerability
KEVLG
LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.
CVE-2018-14667Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
KEVRed Hat
Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker cou…
CVE-2018-14634Linux Kernel Integer Overflow Vulnerability
KEVLinux
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (o…
CVE-2018-14558Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
KEVTenda
Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrust…
CVE-2018-13383Fortinet FortiOS and FortiProxy Out-of-bounds Write
KEVFortinet
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
CVE-2018-13382Fortinet FortiOS and FortiProxy Improper Authorization
KEVFortinet
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
CVE-2018-13379Fortinet FortiOS SSL VPN Path Traversal Vulnerability
KEVFortinet
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through…
CVE-2018-13374Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
KEVCVSS 4.3Fortinet
Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in …
CVE-2018-1273VMware Tanzu Spring Data Commons Property Binder Vulnerability
KEVCVSS 9.8VMware Tanzu
Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.
CVE-2018-11776Apache Struts Remote Code Execution Vulnerability
KEVApache
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true a…
CVE-2018-11138Quest KACE System Management Appliance Remote Command Execution Vulnerability
KEVCVSS 9.8Quest
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform r…
CVE-2018-10562Dasan GPON Routers Command Injection Vulnerability
KEVDasan
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code…
CVE-2018-10561Dasan GPON Routers Authentication Bypass Vulnerability
KEVDasan
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code…
CVE-2018-1000861Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability
KEVJenkins
A code execution vulnerability exists in the Stapler web framework used by Jenkins
CVE-2018-0824Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
KEVMicrosoft
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a speci…
CVE-2018-0802Microsoft Office Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execut…
CVE-2018-0798Microsoft Office Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execut…
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
KEVCVSS 7.5Cisco
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a den…
CVE-2018-0180Cisco IOS Software Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an…
CVE-2018-0179Cisco IOS Software Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an…
CVE-2018-0175Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
KEVCisco
Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could…
CVE-2018-0174Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability
KEVCisco
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
CVE-2018-0173Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
KEVCisco
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packet…
CVE-2018-0172Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
KEVCisco
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
CVE-2018-0171Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
KEVCisco
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a…
CVE-2018-0167Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
KEVCisco
There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR S…
CVE-2018-0161Cisco IOS Software Resource Management Errors Vulnerability
KEVCisco
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could all…
CVE-2018-0159Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an u…
CVE-2018-0158Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
KEVCisco
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an u…
CVE-2018-0156Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reloa…
CVE-2018-0155Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series …
CVE-2018-0154Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remot…
CVE-2018-0151Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability
KEVCisco
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to ca…
CVE-2018-0147Cisco Secure Access Control System Java Deserialization Vulnerability
KEVCisco
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary c…
CVE-2018-0125Cisco VPN Routers Remote Code Execution Vulnerability
KEVCisco
A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full c…
CVE-2017-9841PHPUnit Command Injection Vulnerability
KEVPHPUnit
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site wi…
CVE-2017-9822DotNetNuke (DNN) Remote Code Execution Vulnerability
KEVDotNetNuke (DNN)
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
CVE-2017-9805Apache Struts Deserialization of Untrusted Data Vulnerability
KEVApache
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code exec…
CVE-2017-9791Apache Struts 1 Improper Input Validation Vulnerability
KEVApache
The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVE-2017-9248Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
KEVProgress
Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Tele…
CVE-2017-8759Microsoft .NET Framework Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affe…
CVE-2017-8570Microsoft Office Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
CVE-2017-8543Microsoft Windows Search Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.
CVE-2017-8540Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
KEVMicrosoft
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W…
CVE-2017-8464Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability
KEVMicrosoft
Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file
CVE-2017-8291Artifex Ghostscript Type Confusion Vulnerability
KEVArtifex
Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.
CVE-2017-7921Hikvision Multiple Products Improper Authentication Vulnerability
KEVHikvision
Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain ac…
CVE-2017-7494Samba Remote Code Execution Vulnerability
KEVSamba
Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to l…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.