91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,401–1,450 of 1,734 in KEV · page 29 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2017-7269 | Microsoft Windows Server Buffer Overflow Vulnerability KEVMicrosoft | Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute c… |
| CVE-2017-6884 | Zyxel EMG2926 Routers Command Injection Vulnerability KEVCVSS 8.8Zyxel | Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may explo… |
| CVE-2017-6862 | NETGEAR Multiple Devices Buffer Overflow Vulnerability KEVNETGEAR | Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution. |
| CVE-2017-6744 | Cisco IOS Software SNMP Remote Code Execution Vulnerability KEVCisco | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely … |
| CVE-2017-6743 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability KEVCisco | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to … |
| CVE-2017-6742 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability KEVCisco | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to … |
| CVE-2017-6740 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability KEVCisco | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to … |
| CVE-2017-6739 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability KEVCisco | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to … |
| CVE-2017-6738 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability KEVCisco | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to … |
| CVE-2017-6737 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability KEVCisco | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to … |
| CVE-2017-6736 | Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability KEVCisco | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to … |
| CVE-2017-6663 | Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability KEVCisco | A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause … |
| CVE-2017-6627 | Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability KEVCisco | A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected syst… |
| CVE-2017-6334 | NETGEAR DGN2200 Devices OS Command Injection Vulnerability KEVNETGEAR | dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands |
| CVE-2017-6327 | Symantec Messaging Gateway Remote Code Execution Vulnerability KEVSymantec | Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, … |
| CVE-2017-6316 | Citrix Multiple Products Remote Code Execution Vulnerability KEVCitrix | A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN E… |
| CVE-2017-6077 | NETGEAR DGN2200 Remote Code Execution Vulnerability KEVNETGEAR | NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution. |
| CVE-2017-5689 | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability KEVIntel | Intel products contain a vulnerability which can allow attackers to perform privilege escalation. |
| CVE-2017-5638 | Apache Struts Remote Code Execution Vulnerability KEVApache | Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. |
| CVE-2017-5521 | NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability KEVNETGEAR | Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server. |
| CVE-2017-5070 | Google Chromium V8 Type Confusion Vulnerability KEVGoogle | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This … |
| CVE-2017-5030 | Google Chromium V8 Memory Corruption Vulnerability KEVGoogle | Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability … |
| CVE-2017-3881 | Cisco IOS and IOS XE Remote Code Execution Vulnerability KEVCisco | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote at… |
| CVE-2017-3506 | Oracle WebLogic Server OS Command Injection Vulnerability KEVOracle | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitra… |
| CVE-2017-3066 | Adobe ColdFusion Deserialization Vulnerability KEVAdobe | Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. |
| CVE-2017-18368 | Zyxel P660HN-T1A Routers Command Injection Vulnerability KEVZyxel | Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user… |
| CVE-2017-18362 | Kaseya VSA SQL Injection Vulnerability KEVCVSS 9.8Kaseya | ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. |
| CVE-2017-17562 | Embedthis GoAhead Remote Code Execution Vulnerability KEVEmbedthis | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. |
| CVE-2017-16651 | Roundcube Webmail File Disclosure Vulnerability KEVRoundcube | Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are… |
| CVE-2017-15944 | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability KEVPalo Alto Networks | Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained. |
| CVE-2017-12637 | SAP NetWeaver Directory Traversal Vulnerability KEVSAP | SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a re… |
| CVE-2017-12617 | Apache Tomcat Remote Code Execution Vulnerability KEVCVSS 8.1Apache | When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it… |
| CVE-2017-12615 | Apache Tomcat on Windows Remote Code Execution Vulnerability KEVCVSS 8.1Apache | When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could… |
| CVE-2017-12319 | Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability KEVCisco | A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, … |
| CVE-2017-12240 | Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability KEVCisco | The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthentica… |
| CVE-2017-12238 | Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability KEVCisco | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent at… |
| CVE-2017-12237 | Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability KEVCisco | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause hi… |
| CVE-2017-12235 | Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability KEVCisco | A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attack… |
| CVE-2017-12234 | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability KEVCisco | There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to … |
| CVE-2017-12233 | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability KEVCisco | There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to … |
| CVE-2017-12232 | Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability KEVCisco | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthe… |
| CVE-2017-12231 | Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability KEVCisco | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause … |
| CVE-2017-12149 | CVE-2017-12149 KEVCVSS 9.8redhat | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of t… |
| CVE-2017-11882 | Microsoft Office Memory Corruption Vulnerability KEVMicrosoft | Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. |
| CVE-2017-11826 | Microsoft Office Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who success… |
| CVE-2017-11774 | Microsoft Office Outlook Security Feature Bypass Vulnerability KEVMicrosoft | Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attac… |
| CVE-2017-11357 | Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability KEVCVSS 9.8Telerik | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location … |
| CVE-2017-11317 | Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability KEVTelerik | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code. |
| CVE-2017-11292 | Adobe Flash Player Type Confusion Vulnerability KEVAdobe | Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. |
| CVE-2017-10271 | Oracle Corporation WebLogic Server Remote Code Execution Vulnerability KEVCVSS 7.5Oracle | Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. |