Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Openregistrecil MEDIUM 6.8
CVE-2010-1946EPSS 6%

Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled, allow remote attackers to ex…

No fix yet
Fix from $1,600 2010-05-19
Opencimetiere MEDIUM 6.8
CVE-2010-1944EPSS 6%

Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to exec…

No fix yet
Fix from $1,600 2010-05-19
Openannuaire MEDIUM 6.8
CVE-2010-1921

Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allow remote attackers to execu…

No fix yet
Fix from $1,600 2010-05-12
29o3 Cms HIGH 7.5
CVE-2010-1922

Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the LibDir param…

No fix yet
Fix from $1,950 2010-05-12
Opencourrier MEDIUM 6.8
CVE-2010-1927

Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allow remote atta…

No fix yet
Fix from $1,600 2010-05-12
Openplanning MEDIUM 6.8
CVE-2010-1934

Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, allow remote attackers to execu…

No fix yet
Fix from $1,600 2010-05-12
Visual Basic For Applications HIGH 9.3
CVE-2010-0815EPSS 22%

VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 …

Mitigation only
Fix from $1,950 2010-05-12
0.1.0 MEDIUM 6.8
CVE-2010-1737

PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to…

No fix yet
Fix from $1,600 2010-05-06
Movie Php Script HIGH 7.5
CVE-2009-4836EPSS 6%

Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the antico…

No fix yet
Fix from $1,950 2010-05-06
Photoshop Cs4 HIGH 9.3
CVE-2010-1279

Multiple unspecified vulnerabilities in Adobe Photoshop CS4 11.x before 11.0.1 allow user-assisted remote attackers to execute arbitrary code via a c…

Patch available
Fix from $1,950 2010-05-05
Openttd MEDIUM 6.5
CVE-2010-0402

OpenTTD before 1.0.1 does not properly validate index values of certain items, which allows remote authenticated users to cause a denial of service (…

Fix: after 1.0.0
Fix from $1,600 2010-05-05
Zeroboard MEDIUM 6.8
CVE-2009-4834

lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php.

No fix yet
Fix from $1,600 2010-05-04
Proxy MEDIUM 6.8
CVE-2010-1528

PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute a…

No fix yet
Fix from $1,600 2010-04-26
Bandsite Cms MEDIUM 6.0
CVE-2009-4793

Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execut…

No fix yet
Fix from $1,600 2010-04-22
Mojoblog HIGH 7.5
CVE-2009-4789

Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code…

No fix yet
Fix from $1,950 2010-04-21
Nukehall HIGH 7.5
CVE-2009-4779

Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the …

Fix: after 0.3
Fix from $1,950 2010-04-21
TYPO3 MEDIUM 6.8
CVE-2010-1153

PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL…

Mitigation only
Fix from $1,600 2010-04-20
Jira HIGH 9.0
CVE-2010-1165

Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments…

Patch available
Fix from $1,950 2010-04-20
Warcraft 3 The Frozen Throne HIGH 9.3
CVE-2009-4768

Unspecified vulnerability in the JASS script interpreter in Warcraft III: The Frozen Throne 1.24b and earlier allows user-assisted remote attackers t…

Fix: after 1.2.4b
Fix from $1,950 2010-04-20
Openurgence Vaccin HIGH 7.5
CVE-2010-1467

Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrary PHP code via a URL in the p…

No fix yet
Fix from $1,950 2010-04-16
Visio HIGH 7.6
CVE-2010-0254EPSS 18%

Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers t…

Mitigation only
Fix from $1,950 2010-04-14
Visio HIGH 7.6
CVE-2010-0256EPSS 18%

Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which al…

Mitigation only
Fix from $1,950 2010-04-14
Acrobat HIGH 9.3
CVE-2010-0191EPSS 6%

Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified ve…

Patch available
Fix from $1,950 2010-04-14
Acrobat HIGH 9.3
CVE-2010-0195EPSS 6%

Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, do not properly handle fonts, which allows attackers to exec…

Patch available
Fix from $1,950 2010-04-14
Faqengine HIGH 7.5
CVE-2010-1360

Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_fa…

No fix yet
Fix from $1,950 2010-04-13
Tandberg Video Communication Server HIGH 10.0
CVE-2009-4509

The administrative web console on the TANDBERG Video Communication Server (VCS) before X4.3 uses predictable session cookies in (1) tandberg/web/lib/…

Patch available
Fix from $1,950 2010-04-13
Nodesforum MEDIUM 6.8
CVE-2010-1351

Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute…

No fix yet
Fix from $1,600 2010-04-12
Insky Cms MEDIUM 6.8
CVE-2010-1335

Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote attackers to execute arbitra…

No fix yet
Fix from $1,600 2010-04-09
Vanilla HIGH 7.5
CVE-2010-1337

Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote …

Fix: after 1.1.10
Fix from $1,950 2010-04-09
Direct News MEDIUM 6.8
CVE-2010-1342

Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote attackers to execute arbitra…

No fix yet
Fix from $1,600 2010-04-09