Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Salt HIGH 7.5
CVE-2013-4438

Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this…

Fix: after 0.17.0
Fix from $1,950 2013-11-05
Hyperic Hq MEDIUM 6.5
CVE-2013-6366EPSS 7%

The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().…

No fix yet
Fix from $1,600 2013-11-04
Email Gateway HIGH 8.5
CVE-2013-6349

McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vect…

Mitigation only
Fix from $1,950 2013-11-02
Nas4free MEDIUM 6.0
CVE-2013-3631EPSS 14%

NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execu…

Fix: after 9.1.0.1.804
Fix from $1,600 2013-11-02
Tpp MEDIUM 6.8
CVE-2013-2208

tpp 1.3.1 allows remote attackers to execute arbitrary commands via a --exec command in a TPP template file.

Patch available
Fix from $1,600 2013-10-28
Puppet Enterprise MEDIUM 6.8
CVE-2013-4957

The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted report-specific type.

Fix: after 3.0.0
Fix from $1,600 2013-10-25
Erp Central Component MEDIUM 6.0
CVE-2013-3244

Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for SAP ERP Central Component (EC…

Mitigation only
Fix from $1,600 2013-10-24
Service Manager HIGH 7.5
CVE-2013-4830EPSS 6%

HP Service Manager 9.30 through 9.32 allows remote attackers to execute arbitrary code via an unspecified "injection" approach.

Mitigation only
Fix from $1,950 2013-10-16
Rgpg HIGH 7.5
CVE-2013-4203

The self.run_gpg function in lib/rgpg/gpg_helper.rb in the rgpg gem before 0.2.3 for Ruby allows remote attackers to execute arbitrary commands via s…

Fix: after 0.2.2
Fix from $1,950 2013-10-11
Acrobat HIGH 9.3
CVE-2013-5325

Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a javascript: URL via a crafte…

Mitigation only
Fix from $1,950 2013-10-09
Camel MEDIUM 6.8
CVE-2013-4330EPSS 9%

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expres…

Fix: after 2.9.6
Fix from $1,600 2013-10-04
Ose HIGH 10.0
CVE-2013-0689EPSS 5%

The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L R…

Fix: after 3.50
Fix from $1,950 2013-10-03
Graphite MEDIUM 6.8
CVE-2013-5942

Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialize…

Patch available
Fix from $1,600 2013-09-27
Graphite MEDIUM 6.8
CVE-2013-5093EPSS 39%

The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows…

Patch available
Fix from $1,600 2013-09-27
Spss Analytical Decision Management HIGH 9.3
CVE-2013-5369

IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2013-09-16
Moodle HIGH 7.5
CVE-2013-5674

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, whi…

Patch available
Fix from $1,950 2013-09-16
Application Lifecycle Management CRITICAL 9.8
CVE-2013-4810 KEVEPSS 79%

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attac…

Mitigation only
Fix from $2,300 2013-09-16
Identity Driven Manager HIGH 10.0
CVE-2013-4813EPSS 9%

The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows re…

Mitigation only
Fix from $1,950 2013-09-16
WordPress HIGH 7.5
CVE-2013-4338EPSS 9%

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to ex…

Fix: after 3.6
Fix from $1,950 2013-09-12
Open Xchange Server MEDIUM 5.0
CVE-2013-1647

Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attacke…

No fix yet
Fix from $1,600 2013-09-05
Open Xchange Appsuite MEDIUM 5.0
CVE-2013-2582

CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6,…

Mitigation only
Fix from $1,600 2013-09-05
Sounder HIGH 7.5
CVE-2013-5647

lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.

No fix yet
Fix from $1,950 2013-08-29
Cacti HIGH 7.5
CVE-2013-1435

(1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vec…

Patch available
Fix from $1,950 2013-08-23
Rt MEDIUM 5.0
CVE-2013-3373

CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP hea…

Patch available
Fix from $1,600 2013-08-23
Cloudforms Management Engine HIGH 8.5
CVE-2013-4172

The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors.

Mitigation only
Fix from $1,950 2013-08-23
Udr HIGH 10.0
CVE-2013-2802

The universal protocol implementation in Sixnet UDR before 2.0 and RTU firmware before 4.8 allows remote attackers to execute arbitrary code; read, m…

Fix: after 4.7
Fix from $1,950 2013-08-21
Folsom HIGH 7.5
CVE-2013-2161

XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…

Mitigation only
Fix from $1,950 2013-08-20
Openstack MEDIUM 6.0
CVE-2013-2121EPSS 25%

Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with perm…

Fix: after 1.2.0
Fix from $1,600 2013-07-31
Unified Communications Manager MEDIUM 6.5
CVE-2013-3402

An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary c…

Mitigation only
Fix from $1,600 2013-07-18
Struts HIGH 9.3
CVE-2013-2134EPSS 70%

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly …

Fix: 2.3.14.3+
Fix from $1,950 2013-07-16