Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Livezilla HIGH 7.5
CVE-2013-7034

The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a …

Fix: after 5.1.2.0
Fix from $1,950 2014-05-05
Telepresence Te Software HIGH 9.0
CVE-2014-2170

Cisco TelePresence TC Software 4.x and 5.x before 5.1.7 and 6.x before 6.0.1 and TE Software 4.x and 6.0 allow remote authenticated users to execute …

Mitigation only
Fix from $1,950 2014-05-02
Pirpc MEDIUM 6.8
CVE-2013-7284

The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via a craft…

Fix: after 0.2020
Fix from $1,600 2014-04-29
Xcloner HIGH 7.1
CVE-2014-2996EPSS 10%

XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary co…

Fix: after 3.5
Fix from $1,950 2014-04-25
Simatic S7 Cpu 1200 Firmware MEDIUM 5.8
CVE-2014-2909

CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitr…

Mitigation only
Fix from $1,600 2014-04-25
Django MEDIUM 5.1
CVE-2014-0472EPSS 6%

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows rem…

Fix: after 1.4.10
Fix from $1,600 2014-04-23
Jboss Fuse Service Works MEDIUM 6.5
CVE-2013-6469

JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression …

Mitigation only
Fix from $1,600 2014-04-22
Pimcore HIGH 7.5
CVE-2014-2921EPSS 7%

The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an obje…

Patch available
Fix from $1,950 2014-04-21
Syncope MEDIUM 6.5
CVE-2014-0111

Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Co…

Fix: 1.0.9 / 1.1.7+
Fix from $1,600 2014-04-17
Commonspot Content Server HIGH 10.0
CVE-2014-2866

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to per…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Ccms Agent HIGH 7.5
CVE-2013-7362

An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors.

No fix yet
Fix from $1,950 2014-04-10
Jboss Bpm Suite MEDIUM 6.5
CVE-2013-6468

JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java c…

Mitigation only
Fix from $1,600 2014-04-10
Chrome HIGH 7.5
CVE-2014-1716

Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.1…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Horde Application Framework HIGH 7.5
CVE-2014-1691EPSS 43%

The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attac…

Fix: after 5.1.0
Fix from $1,950 2014-04-01
Spmode Mail Android MEDIUM 6.8
CVE-2014-1979

The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers…

Mitigation only
Fix from $1,600 2014-03-19
Cloudforms HIGH 7.5
CVE-2014-0057

The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remo…

Mitigation only
Fix from $1,950 2014-03-18
Owncloud Server MEDIUM 6.5
CVE-2013-1850

Multiple incomplete blacklist vulnerabilities in (1) import.php and (2) ajax/uploadimport.php in apps/contacts/ in ownCloud before 4.0.13 and 4.5.x b…

Fix: after 4.0.12
Fix from $1,600 2014-03-14
Netscaler Application Delivery Controller Firmware MEDIUM 5.0
CVE-2013-6943

Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attacke…

Mitigation only
Fix from $1,600 2014-03-11
Android HIGH 7.5
CVE-2014-1939

java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchB…

Fix: after 4.3.1
Fix from $1,950 2014-03-03
Ilias MEDIUM 6.8
CVE-2014-2089

ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain clien…

No fix yet
Fix from $1,600 2014-03-02
Mc Worx Suite HIGH 9.3
CVE-2013-2817EPSS 6%

An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary p…

Fix: after 8.02
Fix from $1,950 2014-02-24
Wemo Home Automation Firmware HIGH 7.8
CVE-2013-6948

The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document con…

Mitigation only
Fix from $1,950 2014-02-22
Autocad HIGH 7.5
CVE-2014-0818

Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a T…

Fix: after 2013
Fix from $1,950 2014-02-22
Microsoft Forefront Protection 2010 HIGH 10.0
CVE-2014-0294EPSS 21%

Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2014-02-12
Bing MEDIUM 6.8
CVE-2014-1670EPSS 14%

The Microsoft Bing application before 4.2.1 for Android allows remote attackers to install arbitrary APK files via vectors involving a crafted DNS re…

Fix: after 4.2.0
Fix from $1,600 2014-01-25
Soapui HIGH 9.3
CVE-2014-1202EPSS 8%

The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a…

Fix: after 4.6.3
Fix from $1,950 2014-01-25
Telepresence System Software HIGH 8.3
CVE-2014-0661

The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX131…

Fix: after 1.10.1
Fix from $1,950 2014-01-22
Nexus HIGH 7.5
CVE-2014-0792

Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors relate…

Patch available
Fix from $1,950 2014-01-17
Kingalarm\&event HIGH 7.5
CVE-2013-2827EPSS 48%

An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers…

Fix: after 3.1
Fix from $1,950 2014-01-15
Monitor HIGH 10.0
CVE-2012-0262EPSS 73%

op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary command…

Fix: after 5.5.1
Fix from $1,950 2013-12-31