Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Monitor HIGH 10.0
CVE-2012-0261EPSS 74%

license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via she…

Fix: after 5.5.1
Fix from $1,950 2013-12-31
Openstack Windows Guest Agent HIGH 9.3
CVE-2013-6795EPSS 5%

The Updater in Rackspace Openstack Windows Guest Agent for XenServer before 1.2.6.0 allows remote attackers to execute arbitrary code via a crafted s…

Fix: after 1.2.5.0
Fix from $1,950 2013-12-24
Zabbix HIGH 7.5
CVE-2013-6824

Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a n…

Fix: after 1.8.18
Fix from $1,950 2013-12-19
Webbynode HIGH 7.5
CVE-2013-7086

The message function in lib/webbynode/notify.rb in the Webbynode gem 1.0.5.3 and earlier for Ruby allows context-dependent attackers to execute arbit…

Fix: after 1.0.5.3
Fix from $1,950 2013-12-19
Ack MEDIUM 6.8
CVE-2013-7069

ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in…

Mitigation only
Fix from $1,600 2013-12-14
Devscripts MEDIUM 6.8
CVE-2013-7050

The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbi…

Fix: after 2.13.7
Fix from $1,600 2013-12-13
Sprout HIGH 7.5
CVE-2013-6421

The unpack_zip function in archive_unpacker.rb in the sprout gem 0.7.246 for Ruby allows context-dependent attackers to execute arbitrary commands vi…

No fix yet
Fix from $1,950 2013-12-12
Raidiator HIGH 10.0
CVE-2013-2751EPSS 72%

Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x befo…

Fix: 4.1.12 / 4.2.24+
Fix from $1,950 2013-12-12
Connectrix Manager HIGH 10.0
CVE-2013-6810EPSS 17%

The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Adv…

Mitigation only
Fix from $1,950 2013-12-12
Firefox CRITICAL 9.8
CVE-2013-6671EPSS 11%

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Flash Player HIGH 9.3
CVE-2013-5332EPSS 5%

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR …

Fix: 3.9.0.1380 / 11.2.202.332+
Fix from $1,950 2013-12-11
Flash Player HIGH 9.3
CVE-2013-5331EPSS 72%

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR …

Fix: 3.9.0.1380 / 11.2.202.332+
Fix from $1,950 2013-12-11
Office Web Apps MEDIUM 6.8
CVE-2013-5059EPSS 11%

Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page c…

Mitigation only
Fix from $1,600 2013-12-11
Linux Imaging And Printing Project MEDIUM 6.8
CVE-2013-6427

upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows m…

No fix yet
Fix from $1,600 2013-12-09
X2go Server HIGH 7.5
CVE-2013-4376

The setgid wrapper libx2go-server-db-sqlite3-wrapper.c in X2Go Server before 4.0.0.2 allows remote attackers to execute arbitrary code via unspecifie…

Fix: after 4.0.0.1
Fix from $1,950 2013-12-09
Opensis HIGH 7.5
CVE-2013-1349EPSS 23%

Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.

Patch available
Fix from $1,950 2013-12-09
Drupal MEDIUM 5.1
CVE-2013-6385

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF v…

Patch available
Fix from $1,600 2013-12-07
Roller MEDIUM 6.8
CVE-2013-4212EPSS 81%

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions vi…

Fix: after 5.0.1
Fix from $1,600 2013-12-07
Context MEDIUM 6.8
CVE-2013-4446

The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, w…

Patch available
Fix from $1,600 2013-12-07
Sup MEDIUM 6.8
CVE-2013-4478

Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an e…

Fix: after 0.13.2
Fix from $1,600 2013-12-07
Sup MEDIUM 6.8
CVE-2013-4479

lib/sup/message_chunks.rb in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metachara…

Fix: after 0.13.2
Fix from $1,600 2013-12-07
Djvulibre HIGH 9.3
CVE-2012-6535

DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or c…

Fix: after 3.5.25
Fix from $1,950 2013-12-02
Velocity Analytics Vhayu Analytic Server HIGH 10.0
CVE-2013-5912EPSS 31%

VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in …

Mitigation only
Fix from $1,950 2013-11-28
Adaptive Server Enterprise HIGH 9.0
CVE-2013-6865

SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows re…

Mitigation only
Fix from $1,950 2013-11-23
Adaptive Server Enterprise HIGH 9.0
CVE-2013-6866

SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote au…

Mitigation only
Fix from $1,950 2013-11-23
Mail Secure HIGH 7.5
CVE-2013-6829EPSS 80%

admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost param…

Mitigation only
Fix from $1,950 2013-11-20
Mail Secure 5099sk HIGH 7.5
CVE-2013-6830EPSS 9%

admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary comman…

No fix yet
Fix from $1,950 2013-11-20
Torque Resource Manager HIGH 10.0
CVE-2013-4495

The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows…

Fix: after 4.2.5
Fix from $1,950 2013-11-20
Spip HIGH 7.5
CVE-2013-4557EPSS 25%

The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execu…

Patch available
Fix from $1,950 2013-11-18
Excel Viewer HIGH 7.8
CVE-2013-3906 KEVEPSS 85%

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 201…

Patch available
Fix from $1,950 2013-11-06