91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,351–1,400 of 1,734 in KEV · page 28 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2018-14933 | NUUO NVRmini Devices OS Command Injection Vulnerability KEVNUUO | NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddi… |
| CVE-2018-14847 | MikroTik Router OS Directory Traversal Vulnerability KEVMikroTik | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due … |
| CVE-2018-14839 | LG N1A1 NAS Remote Command Execution Vulnerability KEVLG | LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability. |
| CVE-2018-14667 | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability KEVRed Hat | Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker cou… |
| CVE-2018-14634 | Linux Kernel Integer Overflow Vulnerability KEVLinux | Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (o… |
| CVE-2018-14558 | Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability KEVTenda | Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrust… |
| CVE-2018-13383 | Fortinet FortiOS and FortiProxy Out-of-bounds Write KEVFortinet | A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. |
| CVE-2018-13382 | Fortinet FortiOS and FortiProxy Improper Authorization KEVFortinet | An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. |
| CVE-2018-13379 | Fortinet FortiOS SSL VPN Path Traversal Vulnerability KEVFortinet | Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through… |
| CVE-2018-13374 | Fortinet FortiOS and FortiADC Improper Access Control Vulnerability KEVCVSS 4.3Fortinet | Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in … |
| CVE-2018-1273 | VMware Tanzu Spring Data Commons Property Binder Vulnerability KEVCVSS 9.8VMware Tanzu | Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution. |
| CVE-2018-11776 | Apache Struts Remote Code Execution Vulnerability KEVApache | Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true a… |
| CVE-2018-11138 | Quest KACE System Management Appliance Remote Command Execution Vulnerability KEVCVSS 9.8Quest | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform r… |
| CVE-2018-10562 | Dasan GPON Routers Command Injection Vulnerability KEVDasan | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code… |
| CVE-2018-10561 | Dasan GPON Routers Authentication Bypass Vulnerability KEVDasan | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code… |
| CVE-2018-1000861 | Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability KEVJenkins | A code execution vulnerability exists in the Stapler web framework used by Jenkins |
| CVE-2018-0824 | Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability KEVMicrosoft | Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a speci… |
| CVE-2018-0802 | Microsoft Office Memory Corruption Vulnerability KEVMicrosoft | Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execut… |
| CVE-2018-0798 | Microsoft Office Memory Corruption Vulnerability KEVMicrosoft | Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execut… |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability KEVCVSS 7.5Cisco | Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a den… |
| CVE-2018-0180 | Cisco IOS Software Denial-of-Service Vulnerability KEVCisco | A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an… |
| CVE-2018-0179 | Cisco IOS Software Denial-of-Service Vulnerability KEVCisco | A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an… |
| CVE-2018-0175 | Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability KEVCisco | Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could… |
| CVE-2018-0174 | Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability KEVCisco | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). |
| CVE-2018-0173 | Cisco IOS and IOS XE Software Improper Input Validation Vulnerability KEVCisco | A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packet… |
| CVE-2018-0172 | Cisco IOS and IOS XE Software Improper Input Validation Vulnerability KEVCisco | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). |
| CVE-2018-0171 | Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability KEVCisco | Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a… |
| CVE-2018-0167 | Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability KEVCisco | There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR S… |
| CVE-2018-0161 | Cisco IOS Software Resource Management Errors Vulnerability KEVCisco | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could all… |
| CVE-2018-0159 | Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability KEVCisco | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an u… |
| CVE-2018-0158 | Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability KEVCisco | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an u… |
| CVE-2018-0156 | Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability KEVCisco | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reloa… |
| CVE-2018-0155 | Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability KEVCisco | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series … |
| CVE-2018-0154 | Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability KEVCisco | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remot… |
| CVE-2018-0151 | Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability KEVCisco | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to ca… |
| CVE-2018-0147 | Cisco Secure Access Control System Java Deserialization Vulnerability KEVCisco | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary c… |
| CVE-2018-0125 | Cisco VPN Routers Remote Code Execution Vulnerability KEVCisco | A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full c… |
| CVE-2017-9841 | PHPUnit Command Injection Vulnerability KEVPHPUnit | PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site wi… |
| CVE-2017-9822 | DotNetNuke (DNN) Remote Code Execution Vulnerability KEVDotNetNuke (DNN) | DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. |
| CVE-2017-9805 | Apache Struts Deserialization of Untrusted Data Vulnerability KEVApache | Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code exec… |
| CVE-2017-9791 | Apache Struts 1 Improper Input Validation Vulnerability KEVApache | The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. |
| CVE-2017-9248 | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability KEVProgress | Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Tele… |
| CVE-2017-8759 | Microsoft .NET Framework Remote Code Execution Vulnerability KEVMicrosoft | Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affe… |
| CVE-2017-8570 | Microsoft Office Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. |
| CVE-2017-8543 | Microsoft Windows Search Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory. |
| CVE-2017-8540 | Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability KEVMicrosoft | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W… |
| CVE-2017-8464 | Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability KEVMicrosoft | Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file |
| CVE-2017-8291 | Artifex Ghostscript Type Confusion Vulnerability KEVArtifex | Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile. |
| CVE-2017-7921 | Hikvision Multiple Products Improper Authentication Vulnerability KEVHikvision | Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain ac… |
| CVE-2017-7494 | Samba Remote Code Execution Vulnerability KEVSamba | Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to l… |