Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Remote Support HIGH 7.5
CVE-2015-0935EPSS 12%

Bomgar Remote Support before 15.1.1 allows remote attackers to execute arbitrary PHP code via crafted serialized data to unspecified PHP scripts.

Fix: after 14.3.2
Fix from $1,950 2015-05-25
Mt Phpincgi HIGH 7.5
CVE-2015-2945

mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP object…

No fix yet
Fix from $1,950 2015-05-25
Windows 7 HIGH 9.3
CVE-2015-1699EPSS 14%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Windows 7 HIGH 9.3
CVE-2015-1698EPSS 18%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Windows 7 HIGH 9.3
CVE-2015-1697EPSS 18%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Windows 7 HIGH 9.3
CVE-2015-1696EPSS 18%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Windows 7 HIGH 9.3
CVE-2015-1695EPSS 14%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Windows 7 HIGH 9.3
CVE-2015-1675EPSS 14%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-05-13
Unified Security Management HIGH 9.3
CVE-2015-3446

The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plu…

Fix: after 4.14
Fix from $1,950 2015-05-01
Movabletype HIGH 7.5
CVE-2015-0845

Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attack…

Fix: after 5.2.11
Fix from $1,950 2015-04-17
Windows 7 CRITICAL 9.8
CVE-2015-1635 KEVEPSS 100%

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers …

Patch available
Fix from $2,300 2015-04-14
Egroupware HIGH 7.5
CVE-2014-2027

eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly execute arbi…

Fix: after 1.8006
Fix from $1,950 2015-03-31
Slim HIGH 7.5
CVE-2015-2171

Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via …

Fix: after 2.5.0
Fix from $1,950 2015-03-30
Richfaces MEDIUM 6.8
CVE-2015-0279

JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parame…

Fix: after 4.5.4
Fix from $1,600 2015-03-26
Mp Form Mail Cgi HIGH 7.5
CVE-2015-0898

futomi CGI Cafe MP Form Mail CGI eCommerce before 2.0.12 on Windows allows remote attackers to execute arbitrary Perl code via unspecified vectors.

Fix: after 2.0.11
Fix from $1,950 2015-03-21
Tvos HIGH 9.3
CVE-2015-1061

IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged con…

Fix: after 10.10.2
Fix from $1,950 2015-03-12
Windows 7 HIGH 9.3
CVE-2015-0093EPSS 21%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Windows 7 HIGH 9.3
CVE-2015-0092EPSS 17%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Windows 7 HIGH 9.3
CVE-2015-0091EPSS 20%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Windows 7 HIGH 9.3
CVE-2015-0090EPSS 20%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Windows 7 HIGH 9.3
CVE-2015-0088EPSS 20%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,950 2015-03-11
Spcanywhere MEDIUM 6.8
CVE-2015-1597

The Siemens SPCanywhere application for Android does not use encryption during the loading of code, which allows man-in-the-middle attackers to execu…

Fix: after 1.4.1
Fix from $1,600 2015-03-07
Server And Application Monitor MEDIUM 6.8
CVE-2015-1501EPSS 7%

The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to…

Mitigation only
Fix from $1,600 2015-02-16
Radia Client Automation HIGH 10.0
CVE-2015-1497EPSS 75%

radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a c…

Mitigation only
Fix from $1,950 2015-02-16
Reflection Ftp Client HIGH 10.0
CVE-2014-0603EPSS 6%

The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corr…

Fix: after 14.1.420
Fix from $1,950 2015-02-06
Hana Extended Application Services HIGH 10.0
CVE-2015-1311

The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 209890…

Mitigation only
Fix from $1,950 2015-01-22
Ipass Open Mobile HIGH 9.0
CVE-2015-0925EPSS 52%

The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted U…

Fix: after 2.4.4
Fix from $1,950 2015-01-22
Adaptcms MEDIUM 6.5
CVE-2015-1059EPSS 5%

Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by upload…

No fix yet
Fix from $1,600 2015-01-16
Firefox HIGH 7.5
CVE-2014-8636EPSS 66%

The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Projectsend HIGH 7.5
CVE-2014-9567EPSS 43%

Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbi…

No fix yet
Fix from $1,950 2015-01-07