Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Magmi HIGH 9.0
CVE-2014-8770EPSS 7%

Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Communi…

Fix: after 0.7.17a
Fix from $1,950 2014-11-13
Flash Player HIGH 10.0
CVE-2014-0577EPSS 5%

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…

Fix: 11.2.202.418 / 13.0.0.252+
Fix from $1,950 2014-11-11
Flash Player HIGH 10.0
CVE-2014-0584EPSS 5%

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…

Fix: 11.2.202.418 / 13.0.0.252+
Fix from $1,950 2014-11-11
Flash Player HIGH 10.0
CVE-2014-0585

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…

Fix: 11.2.202.418 / 13.0.0.252+
Fix from $1,950 2014-11-11
Flash Player HIGH 10.0
CVE-2014-0586EPSS 5%

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…

Fix: 11.2.202.418 / 13.0.0.252+
Fix from $1,950 2014-11-11
Flash Player HIGH 10.0
CVE-2014-0574EPSS 8%

Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on …

Fix: 11.2.202.418 / 13.0.0.252+
Fix from $1,950 2014-11-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6333EPSS 18%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office documen…

Mitigation only
Fix from $1,950 2014-11-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6334EPSS 17%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service…

Mitigation only
Fix from $1,950 2014-11-11
Office Compatibility Pack HIGH 9.3
CVE-2014-6335EPSS 16%

Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service…

Mitigation only
Fix from $1,950 2014-11-11
Windows 7 HIGH 9.3
CVE-2014-4118EPSS 14%

XML Core Services (aka MSXML) 3.0 in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows…

Patch available
Fix from $1,950 2014-11-11
Windows 7 HIGH 10.0
CVE-2014-6321EPSS 96%

Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows …

Patch available
Fix from $1,950 2014-11-11
Rv120w Firmware HIGH 9.0
CVE-2014-2177

The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.…

Fix: after 1.0.5.8
Fix from $1,950 2014-11-07
Document Management Services HIGH 7.2
CVE-2014-8660

SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Customer Relationship Management Internet Sales HIGH 10.0
CVE-2014-8661

The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Customer Relationship Management HIGH 10.0
CVE-2014-8669EPSS 5%

The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Qemu HIGH 7.5
CVE-2013-6399

Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a craf…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4151EPSS 5%

The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, wh…

Patch available
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4537

The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Smarty HIGH 7.5
CVE-2014-8350

Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/li…

Fix: after 3.1.20
Fix from $1,950 2014-11-03
Testlink HIGH 7.5
CVE-2014-8081

lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP co…

Fix: after 1.9.12
Fix from $1,950 2014-10-31
Libproxy HIGH 7.5
CVE-2012-5580

Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial …

No fix yet
Fix from $1,950 2014-10-27
Glibc MEDIUM 6.8
CVE-2011-2702EPSS 8%

Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allow…

Fix: after 2.12.2
Fix from $1,600 2014-10-27
WordPress HIGH 7.5
CVE-2003-1599

PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,950 2014-10-27
Egroupware HIGH 8.5
CVE-2014-2988

EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows re…

Fix: after 1.8006
Fix from $1,950 2014-10-27
Findmymobile HIGH 7.8
CVE-2014-8346

The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier f…

No fix yet
Fix from $1,950 2014-10-24
Centreon HIGH 10.0
CVE-2014-3829EPSS 81%

displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitr…

Patch available
Fix from $1,950 2014-10-23
Hana MEDIUM 6.0
CVE-2014-8313

Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via uns…

No fix yet
Fix from $1,600 2014-10-16
Openshift HIGH 7.5
CVE-2014-3666

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.

Fix: after 3.1
Fix from $1,950 2014-10-16
Luci MEDIUM 6.0
CVE-2014-3593

Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted…

Mitigation only
Fix from $1,600 2014-10-15
Windows 7 HIGH 8.8
CVE-2014-4148 KEVEPSS 60%

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-10-15