Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Flash Player HIGH 10.0
CVE-2014-0558EPSS 5%

Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.…

Fix: after 15.0.0.252
Fix from $1,950 2014-10-15
X2engine HIGH 7.5
CVE-2014-5297

The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP obj…

Patch available
Fix from $1,950 2014-10-10
Http File Server HIGH 7.5
CVE-2014-7226EPSS 9%

The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file wit…

Fix: after 2.3c
Fix from $1,950 2014-10-10
Spagobi MEDIUM 6.8
CVE-2014-7296

The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated user…

Mitigation only
Fix from $1,600 2014-10-08
Bassmaster HIGH 10.0
CVE-2014-7205EPSS 79%

Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for …

Fix: 1.5.2+
Fix from $1,950 2014-10-08
Chrome Os HIGH 10.0
CVE-2014-3188EPSS 6%

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remot…

Fix: after 38.0.2125.77
Fix from $1,950 2014-10-08
Freepbx HIGH 10.0
CVE-2014-7235EPSS 43%

htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.…

Fix: after 2.9.0.8
Fix from $1,950 2014-10-07
Gopro Hero Firmware HIGH 10.0
CVE-2014-6433

gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action.

Mitigation only
Fix from $1,950 2014-10-07
Adaptive Security Appliance Software MEDIUM 5.5
CVE-2014-3399

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information dur…

Fix: after 9.2
Fix from $1,600 2014-10-07
Http File Server CRITICAL 9.8
CVE-2014-6287 KEVEPSS 99%

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to exe…

Fix: 2.3c+
Fix from $2,300 2014-10-07
Owncloud HIGH 7.5
CVE-2014-2044EPSS 12%

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass in…

Fix: after 4.5.13
Fix from $1,950 2014-10-06
Glibc HIGH 7.5
CVE-2014-4043

The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which …

Fix: after 2.19
Fix from $1,950 2014-10-06
Phpcompta\/noalyss HIGH 7.5
CVE-2014-6389EPSS 9%

backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter.

Fix: after 6.7.1
Fix from $1,950 2014-10-06
Xmonad Contrab HIGH 7.5
CVE-2013-1436EPSS 9%

The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which …

Fix: after 0.11.1
Fix from $1,950 2014-10-06
Mm Forum HIGH 7.5
CVE-2014-6298

Unrestricted file upload vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to execute arbitrary code by uploadin…

Fix: after 1.9.2
Fix from $1,950 2014-10-03
Powermail HIGH 7.5
CVE-2014-3947

Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute ar…

Fix: after 1.6.10
Fix from $1,950 2014-10-03
Plone HIGH 8.5
CVE-2012-5493

gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execu…

Fix: after 4.2.2
Fix from $1,950 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5495

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back."

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 6.8
CVE-2012-5485

registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to t…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5488

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObje…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Infusionsoft Gravity Forms HIGH 7.5
CVE-2014-6446EPSS 46%

The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload a…

Patch available
Fix from $1,950 2014-09-26
N Media File Uploader MEDIUM 6.5
CVE-2014-5324

Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbi…

Fix: after 3.3
Fix from $1,600 2014-09-26
Office HIGH 9.3
CVE-2006-1318EPSS 15%

Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, wh…

Mitigation only
Fix from $1,950 2014-09-19
Tomcat MEDIUM 6.8
CVE-2013-4444EPSS 14%

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JM…

Fix: after 7.0.39
Fix from $1,600 2014-09-12
Plogger HIGH 7.5
CVE-2014-2223EPSS 10%

Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbi…

Fix: after 1.0
Fix from $1,950 2014-09-11
Phpwiki HIGH 7.5
CVE-2014-5519EPSS 65%

The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[conten…

No fix yet
Fix from $1,950 2014-09-11
Trafficdot HIGH 7.6
CVE-2014-2378

Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which…

Fix: after 2.10.2
Fix from $1,950 2014-09-05
S3ql HIGH 7.5
CVE-2014-0485

S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized obje…

Fix: after 1.18.1
Fix from $1,950 2014-09-02
Check Mk HIGH 9.3
CVE-2014-5340EPSS 6%

The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execu…

Fix: after 1.2.4
Fix from $1,950 2014-09-02
Chrome HIGH 10.0
CVE-2014-3176EPSS 10%

Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attac…

Fix: after 37.0.2062.93
Fix from $1,950 2014-08-27