14,642 vulnerabilities published in 2017
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementR
In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not suf
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a use-after-free vulnerability exists in
In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerabili
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable i
In all Qualcomm products with Android releases from CAF using the Linux kernel, a configuration vulnerability exists whe
In all Qualcomm products with Android releases from CAF using the Linux kernel, when downloading a file, an excessive am
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not prop
In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel mem
In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow to buffer overflow v
In all Qualcomm products with Android releases from CAF using the Linux kernel, arguments to several QTEE syscalls are n
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function __mdss_fb_copy_destscaler_da
A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.
Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because sh
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Ent
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through N
WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management.
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.
Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecifie
The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name coll
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1
The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log
Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2
A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Op
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, w
Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges
The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.
Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
Multiple SQL injection vulnerabilities in SmartCMS v.2.
Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
Buffer overflow in xymon 4.3.17-1.
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started