91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,401–1,450 of 1,734 in KEV · page 29 of 35

IDTitleSummary
CVE-2017-7269Microsoft Windows Server Buffer Overflow Vulnerability
KEVMicrosoft
Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute c…
CVE-2017-6884Zyxel EMG2926 Routers Command Injection Vulnerability
KEVCVSS 8.8Zyxel
Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may explo…
CVE-2017-6862NETGEAR Multiple Devices Buffer Overflow Vulnerability
KEVNETGEAR
Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.
CVE-2017-6744Cisco IOS Software SNMP Remote Code Execution Vulnerability
KEVCisco
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely …
CVE-2017-6743Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
KEVCisco
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to …
CVE-2017-6742Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
KEVCisco
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to …
CVE-2017-6740Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
KEVCisco
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to …
CVE-2017-6739Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
KEVCisco
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to …
CVE-2017-6738Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
KEVCisco
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to …
CVE-2017-6737Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
KEVCisco
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to …
CVE-2017-6736Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
KEVCisco
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to …
CVE-2017-6663Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause …
CVE-2017-6627Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected syst…
CVE-2017-6334NETGEAR DGN2200 Devices OS Command Injection Vulnerability
KEVNETGEAR
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands
CVE-2017-6327Symantec Messaging Gateway Remote Code Execution Vulnerability
KEVSymantec
Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, …
CVE-2017-6316Citrix Multiple Products Remote Code Execution Vulnerability
KEVCitrix
A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN E…
CVE-2017-6077NETGEAR DGN2200 Remote Code Execution Vulnerability
KEVNETGEAR
NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.
CVE-2017-5689Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
KEVIntel
Intel products contain a vulnerability which can allow attackers to perform privilege escalation.
CVE-2017-5638Apache Struts Remote Code Execution Vulnerability
KEVApache
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
CVE-2017-5521NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability
KEVNETGEAR
Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server.
CVE-2017-5070Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This …
CVE-2017-5030Google Chromium V8 Memory Corruption Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability …
CVE-2017-3881Cisco IOS and IOS XE Remote Code Execution Vulnerability
KEVCisco
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote at…
CVE-2017-3506Oracle WebLogic Server OS Command Injection Vulnerability
KEVOracle
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitra…
CVE-2017-3066Adobe ColdFusion Deserialization Vulnerability
KEVAdobe
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
CVE-2017-18368Zyxel P660HN-T1A Routers Command Injection Vulnerability
KEVZyxel
Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user…
CVE-2017-18362Kaseya VSA SQL Injection Vulnerability
KEVCVSS 9.8Kaseya
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
CVE-2017-17562Embedthis GoAhead Remote Code Execution Vulnerability
KEVEmbedthis
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
CVE-2017-16651Roundcube Webmail File Disclosure Vulnerability
KEVRoundcube
Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are…
CVE-2017-15944Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
KEVPalo Alto Networks
Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.
CVE-2017-12637SAP NetWeaver Directory Traversal Vulnerability
KEVSAP
SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a re…
CVE-2017-12617Apache Tomcat Remote Code Execution Vulnerability
KEVCVSS 8.1Apache
When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it…
CVE-2017-12615Apache Tomcat on Windows Remote Code Execution Vulnerability
KEVCVSS 8.1Apache
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could…
CVE-2017-12319Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, …
CVE-2017-12240Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
KEVCisco
The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthentica…
CVE-2017-12238Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent at…
CVE-2017-12237Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause hi…
CVE-2017-12235Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attack…
CVE-2017-12234Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
KEVCisco
There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to …
CVE-2017-12233Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
KEVCisco
There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to …
CVE-2017-12232Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthe…
CVE-2017-12231Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
KEVCisco
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause …
CVE-2017-12149CVE-2017-12149
KEVCVSS 9.8redhat
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of t…
CVE-2017-11882Microsoft Office Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
CVE-2017-11826Microsoft Office Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who success…
CVE-2017-11774Microsoft Office Outlook Security Feature Bypass Vulnerability
KEVMicrosoft
Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attac…
CVE-2017-11357Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
KEVCVSS 9.8Telerik
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location …
CVE-2017-11317Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
KEVTelerik
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVE-2017-11292Adobe Flash Player Type Confusion Vulnerability
KEVAdobe
Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
CVE-2017-10271Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
KEVCVSS 7.5Oracle
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.