Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Sharetronix MEDIUM 6.8
CVE-2013-5352

Sharetronix 3.1.1.3, 3.1.1, and earlier allows remote attackers to execute arbitrary PHP code via the (1) activities_text parameter to services/activ…

Fix: after 3.1.1
Fix from $1,600 2014-06-13
Ipolis Device Manager HIGH 9.3
CVE-2014-3911EPSS 6%

Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeContro…

Fix: after 1.8.2
Fix from $1,950 2014-06-11
Rocket Servergraph HIGH 10.0
CVE-2014-3915

The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands vi…

Mitigation only
Fix from $1,950 2014-06-11
Dragonfly Gem HIGH 7.5
CVE-2013-1756

The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code …

Patch available
Fix from $1,950 2014-06-09
Owncloud Server HIGH 7.5
CVE-2014-2051

ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstr…

Fix: after 5.0.14
Fix from $1,950 2014-06-05
App\ HIGH 7.5
CVE-2012-6141

The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2014-06-04
Html\ HIGH 7.5
CVE-2012-6142

Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2014-06-04
Spoon HIGH 7.5
CVE-2012-6143

Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2014-06-04
TYPO3 MEDIUM 6.0
CVE-2014-3942

The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authen…

Mitigation only
Fix from $1,600 2014-06-03
Datalife Engine HIGH 7.5
CVE-2013-1412EPSS 40%

DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a…

Patch available
Fix from $1,950 2014-06-02
Symfony HIGH 7.5
CVE-2013-1348

The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than…

Mitigation only
Fix from $1,950 2014-06-02
Symfony HIGH 7.5
CVE-2013-1397

Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml…

Mitigation only
Fix from $1,950 2014-06-02
Square Squash HIGH 7.5
CVE-2013-5036EPSS 46%

The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function …

Patch available
Fix from $1,950 2014-05-27
Wp Ecommerce Shop Styling HIGH 7.5
CVE-2013-0724

PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote a…

Fix: after 1.7
Fix from $1,950 2014-05-27
Izarc MEDIUM 6.8
CVE-2014-2720

IZArc 4.1.8 displays a file's name on the basis of a ZIP archive's Central Directory entry, but launches this file on the basis of a ZIP archive's lo…

No fix yet
Fix from $1,600 2014-05-27
Wide Area Application Services HIGH 9.3
CVE-2014-2196

Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers t…

Mitigation only
Fix from $1,950 2014-05-26
Couchdb MEDIUM 6.8
CVE-2012-5649EPSS 7%

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, relat…

Fix: after 1.0.3
Fix from $1,600 2014-05-23
Cogent Datahub HIGH 7.5
CVE-2014-3789EPSS 64%

GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vect…

Fix: after 7.3.4
Fix from $1,950 2014-05-22
TYPO3 MEDIUM 6.5
CVE-2013-4321

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code…

Mitigation only
Fix from $1,600 2014-05-20
Realplayer HIGH 9.3
CVE-2014-3444EPSS 6%

The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a…

Fix: after 16.0.3.51
Fix from $1,950 2014-05-20
Flag MEDIUM 6.5
CVE-2014-3453

Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier f…

Fix: after 7.x-3.5
Fix from $1,600 2014-05-17
Dotclear HIGH 7.5
CVE-2014-1613

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected p…

Fix: after 2.6.1
Fix from $1,950 2014-05-16
.net Framework HIGH 10.0
CVE-2014-1806EPSS 40%

The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access…

Mitigation only
Fix from $1,950 2014-05-14
Web Applications HIGH 8.5
CVE-2014-1813EPSS 10%

Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka "Web Applicatio…

Mitigation only
Fix from $1,950 2014-05-14
Office Web Apps Server HIGH 9.0
CVE-2014-0251EPSS 14%

Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 an…

Mitigation only
Fix from $1,950 2014-05-14
GitLab MEDIUM 6.8
CVE-2013-4581

GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to exe…

Fix: after 6.2.3
Fix from $1,600 2014-05-12
Foreman HIGH 7.5
CVE-2013-0171

Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.

Fix: after 1.0
Fix from $1,950 2014-05-08
Foreman HIGH 7.5
CVE-2013-0210

The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Pupp…

Fix: after 1.0
Fix from $1,950 2014-05-08
Caldera HIGH 7.5
CVE-2014-2936

The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder…

No fix yet
Fix from $1,950 2014-05-08
File Gallery MEDIUM 6.5
CVE-2014-2558

The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP co…

Fix: after 1.7.9
Fix from $1,600 2014-05-06