Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Uma CRITICAL 9.8
CVE-2016-7110

Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a dif…

Mitigation only
Fix from $2,300 2016-09-07
Uma CRITICAL 9.8
CVE-2016-7109

Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a dif…

Mitigation only
Fix from $2,300 2016-09-07
Misp CRITICAL 9.8
CVE-2015-5721

Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data…

Fix: after 2.3.89
Fix from $2,300 2016-09-03
Samba HIGH 7.5
CVE-2016-2119

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a clie…

Fix: 4.2.14 / 4.3.11+
Fix from $1,950 2016-07-07
phpMyAdmin CRITICAL 9.8
CVE-2016-5734EPSS 81%

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_repla…

Patch available
Fix from $2,300 2016-07-03
Secure Firewall Management Center MEDIUM 6.5
CVE-2016-1413

The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted cod…

Mitigation only
Fix from $1,600 2016-05-28
Spip CRITICAL 9.8
CVE-2016-3154

The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote att…

Patch available
Fix from $2,300 2016-04-08
Debian Linux CRITICAL 9.8
CVE-2016-3153

SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related …

Patch available
Fix from $2,300 2016-04-08
Zenworks Configuration Management MEDIUM 5.3
CVE-2015-5970

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection atta…

Mitigation only
Fix from $1,600 2016-02-18
Continuous Delivery Automation CRITICAL 9.8
CVE-2016-1986

HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t…

Patch available
Fix from $2,300 2016-02-12
.net Framework HIGH 7.5
CVE-2016-0033EPSS 18%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote at…

Mitigation only
Fix from $1,950 2016-02-10
Operations Manager CRITICAL 10.0
CVE-2016-1985EPSS 7%

HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to …

Patch available
Fix from $2,300 2016-01-30
Values CRITICAL 9.0
CVE-2015-8761

The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value se…

Patch available
Fix from $2,300 2016-01-08
Gluster Storage MEDIUM 6.0
CVE-2015-5242

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authe…

Mitigation only
Fix from $1,600 2015-11-25
Visilogic Oplc Ide HIGH 7.5
CVE-2015-7905

Unitronics VisiLogic OPLC IDE before 9.8.02 allows remote attackers to execute unspecified code via unknown vectors.

Fix: after 9.8.0.00
Fix from $1,950 2015-11-13
Endpoint Protection Manager HIGH 8.5
CVE-2015-6555

Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the cons…

Fix: after 12.1
Fix from $1,950 2015-11-12
Hana MEDIUM 6.5
CVE-2015-7729

Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenti…

No fix yet
Fix from $1,600 2015-10-15
Garoon HIGH 8.5
CVE-2015-5647

The RSS Reader component in Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via…

Mitigation only
Fix from $1,950 2015-10-12
Garoon HIGH 8.5
CVE-2015-5646

Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka Cy…

Patch available
Fix from $1,950 2015-10-12
Matchasns MEDIUM 6.8
CVE-2015-5644

The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code vi…

Fix: after 1.3.6
Fix from $1,600 2015-10-06
Matchasns MEDIUM 6.8
CVE-2015-5643

The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP cod…

Fix: after 1.3.6
Fix from $1,600 2015-10-06
Anchor Cms HIGH 7.5
CVE-2015-5687

system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code …

Patch available
Fix from $1,950 2015-10-05
Refbase HIGH 7.5
CVE-2015-7381

Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to exe…

Fix: after 0.9.6
Fix from $1,950 2015-09-28
Hipchat MEDIUM 6.5
CVE-2015-5603EPSS 59%

The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors…

Fix: after 6.29.2
Fix from $1,600 2015-09-21
Web Gateway HIGH 7.9
CVE-2015-5693

The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute…

Fix: after 5.2.2
Fix from $1,950 2015-09-20
Cxsast HIGH 9.0
CVE-2014-8778

Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitr…

Fix: after 7.1.6
Fix from $1,950 2015-09-16
Check Mk HIGH 8.5
CVE-2014-2331

Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. …

Fix: after 1.2.3
Fix from $1,950 2015-08-31
Symfony MEDIUM 6.8
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6…

Patch available
Fix from $1,600 2015-06-24
Audioshare HIGH 7.5
CVE-2015-4726

PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arbitrary PHP code via a URL in …

No fix yet
Fix from $1,950 2015-06-23
Xcloner MEDIUM 6.5
CVE-2015-4338

Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the…

No fix yet
Fix from $1,600 2015-06-17