91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,501–1,550 of 1,734 in KEV · page 31 of 35

IDTitleSummary
CVE-2016-3718ImageMagick Server-Side Request Forgery (SSRF) Vulnerability
KEVImageMagick
ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.
CVE-2016-3715ImageMagick Arbitrary File Deletion Vulnerability
KEVImageMagick
ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes file…
CVE-2016-3714ImageMagick Improper Input Validation Vulnerability
KEVImageMagick
ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a rem…
CVE-2016-3643SolarWinds Virtualization Manager Privilege Escalation Vulnerability
KEVSolarWinds
SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.
CVE-2016-3427Oracle Java SE and JRockit Unspecified Vulnerability
KEVOracle
Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vector…
CVE-2016-3393Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this…
CVE-2016-3351Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
KEVCVSS 6.5Microsoft
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability coul…
CVE-2016-3309Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vul…
CVE-2016-3298Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability
KEVMicrosoft
An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exp…
CVE-2016-3235Microsoft Office OLE DLL Side Loading Vulnerability
KEVMicrosoft
Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before…
CVE-2016-3088Apache ActiveMQ Improper Input Validation Vulnerability
KEVApache
The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2016-2388SAP NetWeaver Information Disclosure Vulnerability
KEVSAP
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.
CVE-2016-2386SAP NetWeaver SQL Injection Vulnerability
KEVSAP
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vect…
CVE-2016-20017D-Link DSL-2750B Devices Command Injection Vulnerability
KEVD-Link
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.
CVE-2016-1646Google Chromium V8 Out-of-Bounds Read Vulnerability
KEVGoogle
Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unsp…
CVE-2016-1555NETGEAR Multiple WAP Devices Command Injection Vulnerability
KEVNETGEAR
Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows …
CVE-2016-11021D-Link DCS-930L Devices OS Command Injection Vulnerability
KEVD-Link
setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
CVE-2016-1019Adobe Flash Player Arbitrary Code Execution Vulnerability
KEVCVSS 9.8Adobe
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
CVE-2016-10174NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability
KEVNETGEAR
The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
CVE-2016-1010Adobe Flash Player and AIR Integer Overflow Vulnerability
KEVAdobe
Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
CVE-2016-10033PHPMailer Command Injection Vulnerability
KEVPHP
PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function o…
CVE-2016-0984Adobe Flash Player and AIR Use-After-Free Vulnerability
KEVAdobe
Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.
CVE-2016-0752Ruby on Rails Directory Traversal Vulnerability
KEVRails
Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.
CVE-2016-0189Microsoft Internet Explorer Memory Corruption Vulnerability
KEVMicrosoft
The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service…
CVE-2016-0185Microsoft Windows Media Center Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file…
CVE-2016-0167Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
CVE-2016-0165Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2016-0162Microsoft Internet Explorer Information Disclosure Vulnerability
KEVMicrosoft
An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect …
CVE-2016-0151Microsoft Windows CSRSS Security Feature Bypass Vulnerability
KEVMicrosoft
The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
CVE-2016-0099Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An …
CVE-2016-0040Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVMicrosoft
The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
CVE-2016-0034Microsoft Silverlight Runtime Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
CVE-2015-8651Adobe Flash Player Integer Overflow Vulnerability
KEVAdobe
Integer overflow in Adobe Flash Player allows attackers to execute code.
CVE-2015-7755Juniper ScreenOS Improper Authentication Vulnerability
KEVJuniper
Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
CVE-2015-7645Adobe Flash Player Arbitrary Code Execution Vulnerability
KEVAdobe
Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
CVE-2015-7450IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.
KEVIBM
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers …
CVE-2015-6175Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVMicrosoft
The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
CVE-2015-5317Jenkins User Interface (UI) Information Disclosure Vulnerability
KEVJenkins
Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to th…
CVE-2015-5287Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
KEVCVSS 7.8Red Hat
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privile…
CVE-2015-5123Adobe Flash Player Use-After-Free Vulnerability
KEVAdobe
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code o…
CVE-2015-5122Adobe Flash Player Use-After-Free Vulnerability
KEVAdobe
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute cod…
CVE-2015-5119Adobe Flash Player Use-After-Free Vulnerability
KEVAdobe
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2015-4902Oracle Java SE Integrity Check Vulnerability
KEVOracle
Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
CVE-2015-4852Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
KEVOracle
Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.
CVE-2015-4495Mozilla Firefox Security Feature Bypass Vulnerability
KEVMozilla
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-4068Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability
KEVArcserve
Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
CVE-2015-3246Red Hat Libuser Race Condition Vulnerability
KEVCVSS 7.4Red Hat
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or p…
CVE-2015-3113Adobe Flash Player Heap-Based Buffer Overflow Vulnerability
KEVAdobe
Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-3043Adobe Flash Player Memory Corruption Vulnerability
KEVAdobe
A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2015-3035TP-Link Multiple Archer Devices Directory Traversal Vulnerability
KEVTP-Link
Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to log…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.