Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
October CRITICAL 9.8
CVE-2017-1000196

October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applicat…

Fix: after 1.0.412
Fix from $2,300 2017-11-17
Cacti HIGH 8.8
CVE-2014-4000

Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized …

Fix: 1.0.0+
Fix from $1,950 2017-11-15
Mail HIGH 8.1
CVE-2017-15806EPSS 11%

The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the …

Fix: 1.8.2+
Fix from $1,950 2017-11-15
Cms Made Simple CRITICAL 9.8
CVE-2017-16783EPSS 8%

In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.

No fix yet
Fix from $2,300 2017-11-10
Tuleap HIGH 8.8
CVE-2017-7411EPSS 67%

An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the …

Fix: after 9.6
Fix from $1,950 2017-10-30
Pandora Fms HIGH 7.2
CVE-2017-15935

Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrat…

Mitigation only
Fix from $1,950 2017-10-27
Mobaxterm CRITICAL 9.8
CVE-2017-15376

The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP por…

No fix yet
Fix from $2,300 2017-10-16
Ucmdb Foundation Software HIGH 8.8
CVE-2017-14353

A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, cou…

No fix yet
Fix from $1,950 2017-10-05
Bamboo HIGH 8.8
CVE-2015-6576

Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an …

Fix: 5.8.5 / 5.9.7+
Fix from $1,950 2017-10-03
Remove \& Reinstall HIGH 7.0
CVE-2017-13676

Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL f…

Mitigation only
Fix from $1,950 2017-09-28
Genixcms HIGH 8.8
CVE-2017-14764

In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.

No fix yet
Fix from $1,950 2017-09-27
Vbseo HIGH 8.8
CVE-2014-9463EPSS 15%

functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to…

No fix yet
Fix from $1,950 2017-09-15
Ansible Vault HIGH 7.8
CVE-2017-2809

An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary …

Fix: after 1.0.4
Fix from $1,950 2017-09-14
.net Framework HIGH 7.8
CVE-2017-8759 KEVEPSS 87%

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or app…

Patch available
Fix from $1,950 2017-09-13
Gwolle Guestbook CRITICAL 9.0
CVE-2015-8351EPSS 37%

PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote a…

Fix: after 1.5.3
Fix from $2,300 2017-09-11
Alegrocart HIGH 7.2
CVE-2015-9227

PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote admini…

No fix yet
Fix from $1,950 2017-09-11
Helpdezk HIGH 8.8
CVE-2017-14146

HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\…

Mitigation only
Fix from $1,950 2017-09-05
Livesafe CRITICAL 9.8
CVE-2017-3897EPSS 12%

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security…

Fix: after 16.0.2
Fix from $2,300 2017-09-01
Soplanning MEDIUM 5.3
CVE-2014-8677

The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing databa…

Fix: after 1.32
Fix from $1,600 2017-08-31
Debian Linux CRITICAL 9.8
CVE-2017-0899EPSS 11%

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem…

Fix: after 2.6.12
Fix from $2,300 2017-08-31
Emptoris Services Procurement HIGH 8.8
CVE-2017-1440

IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted…

Patch available
Fix from $1,950 2017-08-30
Basercms HIGH 8.8
CVE-2017-10844

baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.

Fix: after 4.0.5
Fix from $1,950 2017-08-29
Fritz\!box 6810 Lte Firmware HIGH 7.8
CVE-2014-8872

Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other mod…

No fix yet
Fix from $1,950 2017-08-29
Scr02hd Firmware HIGH 8.8
CVE-2017-10835

"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vect…

Fix: after 1.0.3.1000
Fix from $1,950 2017-08-29
Prime Infrastructure MEDIUM 5.4
CVE-2017-6782

A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in t…

Mitigation only
Fix from $1,600 2017-08-17
Opensuse CRITICAL 9.8
CVE-2011-0469

Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.

Patch available
Fix from $2,300 2017-08-17
Infosphere Information Server HIGH 7.8
CVE-2017-1469

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation…

Mitigation only
Fix from $1,950 2017-08-14
Ideacentre 300 20ish Firmware MEDIUM 6.8
CVE-2017-3753

A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnera…

Mitigation only
Fix from $1,600 2017-08-10
Projeqtor HIGH 8.8
CVE-2017-11760

uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concat…

Fix: after 6.3.1
Fix from $1,950 2017-07-31
Metinfo CRITICAL 9.8
CVE-2017-11715

job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins…

Fix: after 5.3.17
Fix from $2,300 2017-07-28