Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Zen Cart HIGH 8.8
CVE-2017-11675

The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows re…

Mitigation only
Fix from $1,950 2017-07-27
Trex CRITICAL 9.8
CVE-2017-11459

SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr…

Mitigation only
Fix from $2,300 2017-07-25
Finecms CRITICAL 9.8
CVE-2017-11585

dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection.

No fix yet
Fix from $2,300 2017-07-24
Phpmybackuppro HIGH 8.8
CVE-2015-3638

phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts…

Fix: after 2.5
Fix from $1,950 2017-07-21
Phpmybackuppro HIGH 7.5
CVE-2015-3640

phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowled…

Fix: after 2.5
Fix from $1,950 2017-07-21
Dotnetnuke HIGH 8.8
CVE-2017-9822 KEVEPSS 95%

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

Fix: 9.1.1+
Fix from $1,950 2017-07-20
Gnome Exe Thumbnailer HIGH 7.8
CVE-2017-11421

gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a l…

Fix: after 0.9.4
Fix from $1,950 2017-07-18
Roller HIGH 7.2
CVE-2015-0249

The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary…

Mitigation only
Fix from $1,950 2017-07-17
Finecms CRITICAL 9.8
CVE-2017-11167

FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence i…

No fix yet
Fix from $2,300 2017-07-12
Finecms CRITICAL 9.8
CVE-2017-10968

In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code after "<?php" in a route…

No fix yet
Fix from $2,300 2017-07-07
Phpunit CRITICAL 9.8
CVE-2017-9841 KEVEPSS 100%

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginn…

Fix: 5.6.3+
Fix from $2,300 2017-06-27
Messaging Gateway MEDIUM 6.6
CVE-2017-6325

The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect w…

Fix: after 10.6.2
Fix from $1,600 2017-06-26
Openwebif CRITICAL 9.8
CVE-2017-9807

An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" p…

Fix: after 1.2.4
Fix from $2,300 2017-06-22
Horde Image Api HIGH 8.8
CVE-2017-9774

Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.

Mitigation only
Fix from $1,950 2017-06-21
Websitebaker CRITICAL 9.8
CVE-2017-9771

install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or database_…

Patch available
Fix from $2,300 2017-06-21
Oceanstor Uds Firmware HIGH 8.8
CVE-2015-2252

Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a…

Mitigation only
Fix from $1,950 2017-06-08
Bigtree Cms HIGH 8.8
CVE-2017-9442

BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, rel…

Fix: after 4.2.18
Fix from $1,950 2017-06-05
Pan Os HIGH 7.8
CVE-2015-6531

Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmwar…

Fix: after 6.0
Fix from $1,950 2017-06-01
Pivotx HIGH 8.8
CVE-2017-8402

PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.

Patch available
Fix from $1,950 2017-05-31
Debian Linux CRITICAL 9.8
CVE-2017-7494 KEVEPSS 99%

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to up…

Fix: 4.4.0 / 4.4.14+
Fix from $2,300 2017-05-30
Cms Made Simple HIGH 7.2
CVE-2017-8912

CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.ph…

Patch available
Fix from $1,950 2017-05-12
Kaa Iot Platform HIGH 8.8
CVE-2017-7911

A Code Injection issue was discovered in CyberVision Kaa IoT Platform, Version 0.7.4. An insufficient-encapsulation vulnerability has been identified…

Mitigation only
Fix from $1,950 2017-05-06
Qemu HIGH 7.0
CVE-2017-8284

The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the inst…

Fix: after 2.8.1.1
Fix from $1,950 2017-04-26
Setucocms HIGH 8.8
CVE-2016-4895

SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.

No fix yet
Fix from $1,950 2017-04-12
Symphony HIGH 8.8
CVE-2017-7694

Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to e…

Fix: after 2.6.11
Fix from $1,950 2017-04-11
Trex CRITICAL 9.8
CVE-2017-7691

A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.

Mitigation only
Fix from $2,300 2017-04-11
Fiyo Cms CRITICAL 9.8
CVE-2017-7625

In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execu…

No fix yet
Fix from $2,300 2017-04-10
Oxid Eshop HIGH 8.8
CVE-2016-5072

OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Ente…

Fix: after 5.2.8
Fix from $1,950 2017-04-10
Pivotx HIGH 8.8
CVE-2017-7570

PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .j…

No fix yet
Fix from $1,950 2017-04-07
Bosh Azure Cpi HIGH 8.8
CVE-2017-4964

Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the di…

Patch available
Fix from $1,950 2017-04-06