91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,501–1,550 of 1,734 in KEV · page 31 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2016-3718 | ImageMagick Server-Side Request Forgery (SSRF) Vulnerability KEVImageMagick | ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image. |
| CVE-2016-3715 | ImageMagick Arbitrary File Deletion Vulnerability KEVImageMagick | ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes file… |
| CVE-2016-3714 | ImageMagick Improper Input Validation Vulnerability KEVImageMagick | ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a rem… |
| CVE-2016-3643 | SolarWinds Virtualization Manager Privilege Escalation Vulnerability KEVSolarWinds | SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. |
| CVE-2016-3427 | Oracle Java SE and JRockit Unspecified Vulnerability KEVOracle | Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vector… |
| CVE-2016-3393 | Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this… |
| CVE-2016-3351 | Microsoft Internet Explorer and Edge Information Disclosure Vulnerability KEVCVSS 6.5Microsoft | An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability coul… |
| CVE-2016-3309 | Microsoft Windows Kernel Privilege Escalation Vulnerability KEVMicrosoft | A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vul… |
| CVE-2016-3298 | Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability KEVMicrosoft | An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exp… |
| CVE-2016-3235 | Microsoft Office OLE DLL Side Loading Vulnerability KEVMicrosoft | Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before… |
| CVE-2016-3088 | Apache ActiveMQ Improper Input Validation Vulnerability KEVApache | The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request |
| CVE-2016-2388 | SAP NetWeaver Information Disclosure Vulnerability KEVSAP | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request. |
| CVE-2016-2386 | SAP NetWeaver SQL Injection Vulnerability KEVSAP | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vect… |
| CVE-2016-20017 | D-Link DSL-2750B Devices Command Injection Vulnerability KEVD-Link | D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. |
| CVE-2016-1646 | Google Chromium V8 Out-of-Bounds Read Vulnerability KEVGoogle | Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unsp… |
| CVE-2016-1555 | NETGEAR Multiple WAP Devices Command Injection Vulnerability KEVNETGEAR | Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows … |
| CVE-2016-11021 | D-Link DCS-930L Devices OS Command Injection Vulnerability KEVD-Link | setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command. |
| CVE-2016-1019 | Adobe Flash Player Arbitrary Code Execution Vulnerability KEVCVSS 9.8Adobe | Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. |
| CVE-2016-10174 | NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability KEVNETGEAR | The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. |
| CVE-2016-1010 | Adobe Flash Player and AIR Integer Overflow Vulnerability KEVAdobe | Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code. |
| CVE-2016-10033 | PHPMailer Command Injection Vulnerability KEVPHP | PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function o… |
| CVE-2016-0984 | Adobe Flash Player and AIR Use-After-Free Vulnerability KEVAdobe | Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code. |
| CVE-2016-0752 | Ruby on Rails Directory Traversal Vulnerability KEVRails | Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files. |
| CVE-2016-0189 | Microsoft Internet Explorer Memory Corruption Vulnerability KEVMicrosoft | The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service… |
| CVE-2016-0185 | Microsoft Windows Media Center Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file… |
| CVE-2016-0167 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application |
| CVE-2016-0165 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2016-0162 | Microsoft Internet Explorer Information Disclosure Vulnerability KEVMicrosoft | An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect … |
| CVE-2016-0151 | Microsoft Windows CSRSS Security Feature Bypass Vulnerability KEVMicrosoft | The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. |
| CVE-2016-0099 | Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability KEVMicrosoft | A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An … |
| CVE-2016-0040 | Microsoft Windows Kernel Privilege Escalation Vulnerability KEVMicrosoft | The kernel in Microsoft Windows allows local users to gain privileges via a crafted application. |
| CVE-2016-0034 | Microsoft Silverlight Runtime Remote Code Execution Vulnerability KEVCVSS 8.8Microsoft | Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). |
| CVE-2015-8651 | Adobe Flash Player Integer Overflow Vulnerability KEVAdobe | Integer overflow in Adobe Flash Player allows attackers to execute code. |
| CVE-2015-7755 | Juniper ScreenOS Improper Authentication Vulnerability KEVJuniper | Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device. |
| CVE-2015-7645 | Adobe Flash Player Arbitrary Code Execution Vulnerability KEVAdobe | Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. |
| CVE-2015-7450 | IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. KEVIBM | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers … |
| CVE-2015-6175 | Microsoft Windows Kernel Privilege Escalation Vulnerability KEVMicrosoft | The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application. |
| CVE-2015-5317 | Jenkins User Interface (UI) Information Disclosure Vulnerability KEVJenkins | Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to th… |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability KEVCVSS 7.8Red Hat | Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privile… |
| CVE-2015-5123 | Adobe Flash Player Use-After-Free Vulnerability KEVAdobe | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code o… |
| CVE-2015-5122 | Adobe Flash Player Use-After-Free Vulnerability KEVAdobe | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute cod… |
| CVE-2015-5119 | Adobe Flash Player Use-After-Free Vulnerability KEVAdobe | A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. |
| CVE-2015-4902 | Oracle Java SE Integrity Check Vulnerability KEVOracle | Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment. |
| CVE-2015-4852 | Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability KEVOracle | Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution. |
| CVE-2015-4495 | Mozilla Firefox Security Feature Bypass Vulnerability KEVMozilla | Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. |
| CVE-2015-4068 | Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability KEVArcserve | Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service. |
| CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability KEVCVSS 7.4Red Hat | Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or p… |
| CVE-2015-3113 | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability KEVAdobe | Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code. |
| CVE-2015-3043 | Adobe Flash Player Memory Corruption Vulnerability KEVAdobe | A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. |
| CVE-2015-3035 | TP-Link Multiple Archer Devices Directory Traversal Vulnerability KEVTP-Link | Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to log… |