Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Infinitewp HIGH 7.5
CVE-2014-9521

Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows…

Fix: after 2.4.3
Fix from $1,950 2015-01-05
Hiphop Virtual Machine HIGH 7.5
CVE-2014-2208

CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) bef…

Fix: after 2.4.1
Fix from $1,950 2014-12-28
Security Appscan HIGH 9.3
CVE-2014-6119

IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…

Mitigation only
Fix from $1,950 2014-12-23
Morfy Cms MEDIUM 6.5
CVE-2014-9185

Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php v…

Fix: after 1.04
Fix from $1,600 2014-12-19
Zenoss Core HIGH 9.3
CVE-2014-6261EPSS 20%

Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1…

Fix: after 5.0.0
Fix from $1,950 2014-12-15
I Httpd HIGH 7.5
CVE-2014-7260

The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2014-12-12
Node.js HIGH 10.0
CVE-2014-7192EPSS 13%

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer a…

Fix: after 0.10.32
Fix from $1,950 2014-12-11
Excel HIGH 9.3
CVE-2014-6361EPSS 13%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 Gold and SP1, Excel 2013 RT Gold and SP1, and Office Compatibility Pack allow remote attackers t…

Mitigation only
Fix from $1,950 2014-12-11
Excel HIGH 9.3
CVE-2014-6360EPSS 13%

Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack allow remote attackers to execute arbitrary code via a crafted Office documen…

Mitigation only
Fix from $1,950 2014-12-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6356EPSS 12%

Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2014-12-11
Acrobat HIGH 10.0
CVE-2014-9158EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …

Mitigation only
Fix from $1,950 2014-12-10
Acrobat Reader HIGH 10.0
CVE-2014-8461EPSS 9%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …

Mitigation only
Fix from $1,950 2014-12-10
Acrobat HIGH 10.0
CVE-2014-8459EPSS 9%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …

Mitigation only
Fix from $1,950 2014-12-10
Acrobat Reader HIGH 10.0
CVE-2014-8458EPSS 9%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …

Mitigation only
Fix from $1,950 2014-12-10
Acrobat Reader HIGH 10.0
CVE-2014-8456EPSS 9%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …

Mitigation only
Fix from $1,950 2014-12-10
Acrobat HIGH 10.0
CVE-2014-8447EPSS 9%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …

Mitigation only
Fix from $1,950 2014-12-10
Acrobat HIGH 10.0
CVE-2014-8445EPSS 9%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial …

Mitigation only
Fix from $1,950 2014-12-10
Fedora HIGH 7.5
CVE-2014-8485EPSS 7%

The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and pos…

Fix: after 2.24
Fix from $1,950 2014-12-09
Mantisbt HIGH 7.5
CVE-2014-9280

The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code…

Fix: after 1.2.17
Fix from $1,950 2014-12-08
Smart Viewer MEDIUM 6.8
CVE-2014-9266

The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,600 2014-12-08
Cm Download Manager HIGH 10.0
CVE-2014-8877EPSS 14%

The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress…

Fix: after 2.0.3
Fix from $1,950 2014-12-05
Tuleap MEDIUM 6.0
CVE-2014-8791EPSS 15%

project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object i…

No fix yet
Fix from $1,600 2014-12-02
Java MEDIUM 6.9
CVE-2014-3065

Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 b…

Mitigation only
Fix from $1,600 2014-12-02
Simatic Pcs 7 HIGH 10.0
CVE-2014-8551EPSS 5%

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through S…

Mitigation only
Fix from $1,950 2014-11-26
Incredible Pbx 11 MEDIUM 6.5
CVE-2014-9001

reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1…

No fix yet
Fix from $1,600 2014-11-20
X7 Chat MEDIUM 6.5
CVE-2014-8998EPSS 36%

lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.p…

No fix yet
Fix from $1,600 2014-11-20
Digi Online Examination System HIGH 7.5
CVE-2014-8997EPSS 9%

Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote attackers to exec…

No fix yet
Fix from $1,950 2014-11-20
Imember360 MEDIUM 6.0
CVE-2014-8949EPSS 8%

The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metach…

No fix yet
Fix from $1,600 2014-11-16
Openshift MEDIUM 6.5
CVE-2014-0233

Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters…

No fix yet
Fix from $1,600 2014-11-16
Ubercart MEDIUM 6.0
CVE-2012-2301

The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute a…

Patch available
Fix from $1,600 2014-11-16