Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Pixie CRITICAL 9.8
CVE-2017-7402EPSS 5%

Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanage…

No fix yet
Fix from $2,300 2017-04-03
Mrlg4php CRITICAL 9.8
CVE-2014-3927

mrlg-lib.php in mrlg4php before 1.0.8 allows remote attackers to execute arbitrary shell code.

Fix: after 1.0.7
Fix from $2,300 2017-04-03
Modx Revolution CRITICAL 9.8
CVE-2017-7321

setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parame…

Fix: after 2.5.4
Fix from $2,300 2017-03-30
Modx Revolution CRITICAL 9.8
CVE-2017-7324

setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path paramete…

Fix: after 2.5.4
Fix from $2,300 2017-03-30
Ambari CRITICAL 9.8
CVE-2014-3582

In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates fo…

Fix: after 2.2.2
Fix from $2,300 2017-03-29
Ntp HIGH 7.0
CVE-2017-6455

NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variab…

Patch available
Fix from $1,950 2017-03-27
Pitivi CRITICAL 9.8
CVE-2015-0855

The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file…

Fix: after 0.94
Fix from $2,300 2017-03-23
Linux Enterprise Desktop HIGH 7.8
CVE-2016-1602

A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise De…

Mitigation only
Fix from $1,950 2017-03-23
Antivirus Plus MEDIUM 6.7
CVE-2017-6186

Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and ear…

Fix: after 12.0
Fix from $1,600 2017-03-21
Virusscan Enterprise HIGH 8.0
CVE-2016-8020EPSS 11%

Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authentica…

Fix: after 2.0.3
Fix from $1,950 2017-03-14
Campaign CRITICAL 9.1
CVE-2017-2968

Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability.

Fix: after 16.4
Fix from $2,300 2017-02-15
Unity Pro HIGH 7.0
CVE-2016-8354

An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Si…

Fix: after 11.0
Fix from $1,950 2017-02-13
Gosa Plugin CRITICAL 9.8
CVE-2015-8771

The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.

Patch available
Fix from $2,300 2017-02-13
Simple Machines Forum CRITICAL 9.8
CVE-2016-5726

Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via th…

Patch available
Fix from $2,300 2017-02-09
Simple Machines Forum HIGH 8.8
CVE-2016-5727

LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via ve…

Patch available
Fix from $1,950 2017-02-09
Php Gettext CRITICAL 9.8
CVE-2016-6175EPSS 20%

Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms heade…

Fix: after 1.0.12
Fix from $2,300 2017-02-07
Owncloud Desktop Client HIGH 8.4
CVE-2016-7102

ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in t…

Fix: after 2.2.2
Fix from $1,950 2017-01-23
Exponent Cms CRITICAL 9.8
CVE-2016-2242EPSS 7%

Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.

Patch available
Fix from $2,300 2017-01-23
Netsession CRITICAL 9.8
CVE-2016-10157

Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated …

No fix yet
Fix from $2,300 2017-01-23
Subrion CRITICAL 9.8
CVE-2017-5543

includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data i…

Patch available
Fix from $2,300 2017-01-20
Wampserver MEDIUM 5.3
CVE-2016-10072

WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but…

No fix yet
Fix from $1,600 2016-12-27
Debian Linux HIGH 7.3
CVE-2016-7966

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on t…

Fix: after 4.4.0
Fix from $1,950 2016-12-23
Kmail HIGH 8.1
CVE-2016-7967

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security…

Fix: after 5.3.0
Fix from $1,950 2016-12-23
Kmail MEDIUM 6.5
CVE-2016-7968

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and includ…

Fix: after 5.3.0
Fix from $1,600 2016-12-23
Bundler CRITICAL 9.8
CVE-2016-7954EPSS 8%

Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. …

Patch available
Fix from $2,300 2016-12-22
Ubuntu Linux HIGH 7.8
CVE-2016-9949EPSS 18%

An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it…

Fix: after 12.10
Fix from $1,950 2016-12-17
phpMyAdmin HIGH 7.5
CVE-2016-9862

An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4…

Patch available
Fix from $1,950 2016-12-11
Debian Linux HIGH 7.1
CVE-2016-5424

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users…

Fix: after 9.1.22
Fix from $1,950 2016-12-09
Mirror Manager CRITICAL 9.8
CVE-2016-1000003

Mirror Manager version 0.7.2 and older is vulnerable to remote code execution in the checkin code.

Fix: after 0.7.2
Fix from $2,300 2016-10-07
Chrome HIGH 8.8
CVE-2016-5149

The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to …

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11