Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Struts HIGH 9.3
CVE-2013-2135EPSS 14%

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" an…

Fix: 2.3.14.3+
Fix from $1,950 2013-07-16
Geronimo HIGH 10.0
CVE-2013-1777EPSS 10%

The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o…

Patch available
Fix from $1,950 2013-07-11
Struts HIGH 9.3
CVE-2013-1965EPSS 94%

Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a cr…

Fix: 2.3.14.1+
Fix from $1,950 2013-07-10
Struts HIGH 9.3
CVE-2013-1966EPSS 74%

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …

Fix: 2.3.14.1+
Fix from $1,950 2013-07-10
Struts HIGH 8.1
CVE-2013-2115EPSS 75%

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using …

Fix: after 2.3.14.1
Fix from $1,950 2013-07-10
.net Framework HIGH 9.3
CVE-2013-3132EPSS 22%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, wh…

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 9.3
CVE-2013-3133EPSS 21%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote …

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 9.3
CVE-2013-3134EPSS 21%

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays o…

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 9.3
CVE-2013-3171EPSS 21%

The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of deleg…

Mitigation only
Fix from $1,950 2013-07-10
Windows Media Format Runtime HIGH 9.3
CVE-2013-3127EPSS 22%

The Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime…

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 7.8
CVE-2013-3129EPSS 32%

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWr…

Mitigation only
Fix from $1,950 2013-07-10
.net Framework HIGH 9.3
CVE-2013-3131EPSS 22%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidim…

Mitigation only
Fix from $1,950 2013-07-10
Ec Cube HIGH 7.5
CVE-2013-3651

LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/…

Mitigation only
Fix from $1,950 2013-06-30
Ironport Asyncos HIGH 9.0
CVE-2013-3384

The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email…

Fix: after 7.1.3
Fix from $1,950 2013-06-27
Ironport Asyncos HIGH 9.0
CVE-2013-3383

The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows…

Fix: after 7.1.3
Fix from $1,950 2013-06-27
Firefox HIGH 9.3
CVE-2013-1688

The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to …

Fix: after 21.0
Fix from $1,950 2013-06-26
Vcenter Chargeback Manager HIGH 7.5
CVE-2013-3520EPSS 56%

VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via …

Fix: after 2.5.0
Fix from $1,950 2013-06-17
Viostor Network Video Recorder MEDIUM 6.5
CVE-2013-0143EPSS 7%

cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authen…

Mitigation only
Fix from $1,600 2013-06-07
Publisher HIGH 9.3
CVE-2013-1323EPSS 21%

Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2013-05-15
Word HIGH 9.3
CVE-2013-1335EPSS 21%

Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape C…

Mitigation only
Fix from $1,950 2013-05-15
Groundwork Monitor MEDIUM 6.5
CVE-2013-3508

html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated us…

Mitigation only
Fix from $1,600 2013-05-08
Vcenter Server Appliance HIGH 9.0
CVE-2013-3079

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by le…

Mitigation only
Fix from $1,950 2013-05-01
Parallels Plesk Panel MEDIUM 6.8
CVE-2013-0132

The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to exec…

Mitigation only
Fix from $1,600 2013-04-18
Remote Desktop Connection HIGH 9.3
CVE-2013-1296EPSS 21%

The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memor…

Mitigation only
Fix from $1,950 2013-04-09
Thumbshooter HIGH 7.5
CVE-2013-1898

lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

Mitigation only
Fix from $1,950 2013-04-09
PostgreSQL MEDIUM 6.5
CVE-2013-1899EPSS 54%

Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2013-04-04
Fastreader HIGH 7.5
CVE-2013-2615

lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

No fix yet
Fix from $1,950 2013-03-20
Mini Magick HIGH 7.5
CVE-2013-2616

lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

No fix yet
Fix from $1,950 2013-03-20
Curl HIGH 7.5
CVE-2013-2617

lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

No fix yet
Fix from $1,950 2013-03-20
Command Wrap HIGH 7.5
CVE-2013-1875

command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename.

No fix yet
Fix from $1,950 2013-03-20