Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2012-1010EPSS 9% Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote attackers to execute arbitra… Allwebmenus Plugin after 1.1.7 Fix from $1,9502012-02-07 HIGH 8.5 CVE-2012-0992 interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file … Openemr Patch available Fix from $1,9502012-02-07 HIGH 8.5 CVE-2011-4879EPSS 13% miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; th… Wincc Flexible No fix yet Fix from $1,9502012-02-03 HIGH 7.1 CVE-2011-4877EPSS 8% HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and M… Wincc Flexible No fix yet Fix from $1,9502012-02-03 MEDIUM 5.8 CVE-2011-4314 message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework … Jboss Enterprise Application Platform after 1.0.1 Fix from $1,6002012-01-27 MEDIUM 5.0 CVE-2012-0193 IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values fo… Websphere Application Server Patch available Fix from $1,6002012-01-20 HIGH 9.3 CVE-2012-0267EPSS 39% The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter tha… Ntr Activex Control after 1.1.8 Fix from $1,9502012-01-15 HIGH 7.5 CVE-2011-3597EPSS 14% Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new c… Digest Patch available Fix from $1,9502012-01-13 MEDIUM 5.0 CVE-2011-4530 Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers … Automation License Manager after 5.1 Fix from $1,6002012-01-08 MEDIUM 5.0 CVE-2011-4531EPSS 8% Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and … Automation License Manager after 5.1 Fix from $1,6002012-01-08 MEDIUM 5.0 CVE-2011-5055 MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which… Maradns Patch available Fix from $1,6002012-01-08 MEDIUM 5.0 CVE-2011-4462 Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows… Plone after 4.1.3 Fix from $1,6002011-12-30 HIGH 7.8 CVE-2011-4815 Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-… Ruby after 1.8.7-p352 Fix from $1,9502011-12-30 HIGH 7.8 CVE-2011-5034EPSS 81% Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, wh… Geronimo after 2.2.1 Fix from $1,9502011-12-30 MEDIUM 5.0 CVE-2011-5035EPSS 68% Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other pr… Glassfish Server after 3.1.1 Fix from $1,6002011-12-30 MEDIUM 5.0 CVE-2011-5037 Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attack… V8 Mitigation only Fix from $1,6002011-12-30 HIGH 9.3 CVE-2011-4783 The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to imp… Idapython after 1.5.2 Fix from $1,9502011-12-27 HIGH 7.2 CVE-2011-4784 The NVIDIA Stereoscopic 3D driver before 7.17.12.7565 does not properly handle commands sent to a named pipe, which allows local users to gain privil… Stereoscopic 3d Driver after 7.17.12.7536 Fix from $1,9502011-12-27 MEDIUM 5.0 CVE-2011-4601 family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, wh… Pidgin after 2.10.0 Fix from $1,6002011-12-25 MEDIUM 5.0 CVE-2011-4603 The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 valid… Pidgin after 2.10.0 Fix from $1,6002011-12-17 MEDIUM 5.0 CVE-2011-4602 The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, w… Pidgin after 2.10.0 Fix from $1,6002011-12-17 HIGH 10.0 CVE-2011-4755 Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remo… Parallels Plesk Small Business Panel Mitigation only Fix from $1,9502011-12-16 HIGH 10.0 CVE-2011-4727 The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended for storag… Parallels Plesk Panel Mitigation only Fix from $1,9502011-12-16 HIGH 9.3 CVE-2011-3410EPSS 29% Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher fi… Publisher Mitigation only Fix from $1,9502011-12-14 MEDIUM 5.0 CVE-2011-4539EPSS 15% dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote a… Ubuntu Linux Mitigation only Fix from $1,6002011-12-08 MEDIUM 5.0 CVE-2011-4685 Dragonfly in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unspecified content on a web page, as de… Opera Browser after 11.60 Fix from $1,6002011-12-07 MEDIUM 5.5 CVE-2011-4554 One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an o… One Click Orgs after 1.2.2 Fix from $1,6002011-12-06 MEDIUM 5.8 CVE-2011-4553 Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct… One Click Orgs after 1.2.2 Fix from $1,6002011-12-06 HIGH 10.0 CVE-2011-2397EPSS 5% The Agent service in Iron Mountain Connected Backup 8.4 allows remote attackers to execute arbitrary code via a crafted opcode 13 request that trigge… Connected Backup Mitigation only Fix from $1,9502011-12-05 MEDIUM 5.0 CVE-2011-3367 Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote atta… Arora Mitigation only Fix from $1,6002011-11-29