Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Webkitgtk MEDIUM 5.3
CVE-2013-7324

Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via …

Fix: after 2.26.4
Fix from $1,600 2020-02-17
Suitecrm HIGH 8.8
CVE-2020-8800

SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.

Fix: after 7.11.11
Fix from $1,950 2020-02-13
Wp Super Cache CRITICAL 9.8
CVE-2013-2010EPSS 74%

WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

Fix: after 1.2
Fix from $2,300 2020-02-12
Libnotify CRITICAL 9.8
CVE-2013-7381

libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.

Fix: 1.0.4+
Fix from $2,300 2020-02-12
Hubot Scripts CRITICAL 9.8
CVE-2013-7378

scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary commands.

Fix: 2.4.4+
Fix from $2,300 2020-02-12
Sphider Plus HIGH 8.8
CVE-2014-5085EPSS 6%

A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicio…

No fix yet
Fix from $1,950 2020-02-10
Sphider HIGH 8.8
CVE-2014-5086EPSS 10%

A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let…

Fix: 1.3.6 / 3.2+
Fix from $1,950 2020-02-10
Sphider HIGH 8.8
CVE-2014-5083EPSS 6%

A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote mal…

Fix: 1.3.6+
Fix from $1,950 2020-02-10
Sphider Pro HIGH 8.8
CVE-2014-5084EPSS 8%

A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execu…

No fix yet
Fix from $1,950 2020-02-10
Statusnet MEDIUM 5.3
CVE-2010-4658

statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.

Mitigation only
Fix from $1,600 2020-02-07
Zabbix HIGH 8.8
CVE-2013-3628EPSS 67%

Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

No fix yet
Fix from $1,950 2020-02-07
Linksys E4200 Firmware HIGH 8.1
CVE-2013-2678EPSS 17%

Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive informat…

No fix yet
Fix from $1,950 2020-02-04
Opencast HIGH 7.5
CVE-2020-5230

Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and…

Fix: 7.6+
Fix from $1,950 2020-01-30
Antivirus HIGH 7.8
CVE-2020-8093

A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment …

Fix: 8.0.0+
Fix from $1,950 2020-01-30
Vtiger Crm HIGH 8.1
CVE-2013-3212EPSS 8%

vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execu…

Fix: after 5.4.0
Fix from $1,950 2020-01-28
Vtiger Crm CRITICAL 9.8
CVE-2013-3214EPSS 85%

vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

Fix: after 5.4.0
Fix from $2,300 2020-01-28
Module Metadata CRITICAL 9.8
CVE-2013-1437

Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $V…

Fix: 1.000015+
Fix from $2,300 2020-01-28
Zend Framework MEDIUM 6.1
CVE-2015-3154

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attack…

Fix: 1.12.12 / 2.3.8+
Fix from $1,600 2020-01-27
Webcalendar CRITICAL 9.8
CVE-2012-1495EPSS 80%

install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.

Fix: 1.2.5+
Fix from $2,300 2020-01-27
Webcalendar HIGH 8.8
CVE-2012-1496

Local file inclusion in WebCalendar before 1.2.5.

Fix: 1.2.5+
Fix from $1,950 2020-01-27
Tiki HIGH 7.2
CVE-2011-4558

Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.

Fix: after 8.2
Fix from $1,950 2020-01-27
Debian Linux CRITICAL 9.8
CVE-2014-4172EPSS 6%

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.…

Fix: 1.0.2 / 1.3.3+
Fix from $2,300 2020-01-24
Angular Expressions HIGH 8.8
CVE-2020-5219

Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userCon…

Fix: 1.0.1+
Fix from $1,950 2020-01-24
Secure Headers MEDIUM 5.8
CVE-2020-5216

In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-suppli…

Fix: 3.9.0 / 5.2.0+
Fix from $1,600 2020-01-23
Secure Headers MEDIUM 5.8
CVE-2020-5217

In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-suppli…

Fix: 3.8.0 / 5.1.0+
Fix from $1,600 2020-01-23
Experience Manager HIGH 7.5
CVE-2019-16468

Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead…

Fix: 6.3.3.7 / 6.4.7.0+
Fix from $1,950 2020-01-15
Spamdyke HIGH 7.5
CVE-2012-0070

spamdyke prior to 4.2.1: STARTTLS reveals plaintext

Fix: 4.2.1+
Fix from $1,950 2020-01-15
Enterprise Linux Desktop HIGH 7.8
CVE-2014-7844

BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.

Patch available
Fix from $1,950 2020-01-14
Ep Imageconvert CRITICAL 9.8
CVE-2013-7380

The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability

Fix: after 0.0.2
Fix from $2,300 2020-01-10
Tinywebgallery HIGH 7.2
CVE-2012-2931

PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.…

Fix: 1.8.8+
Fix from $1,950 2020-01-09