Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Rss Module MEDIUM 6.8
CVE-2008-7073

PHP remote file inclusion vulnerability in lib/action/rss.php in RSS module 0.1 for Pie Web M{a,e}sher, when register_globals is enabled, allows remo…

No fix yet
Fix from $1,600 2009-08-25
Fresh Email Script HIGH 7.5
CVE-2008-7042

PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2009-08-24
Phpecho Cms HIGH 7.5
CVE-2008-7034

PHP remote file inclusion vulnerability in kernel/smarty/Smarty.class.php in PHPEcho CMS 2.0 rc3 allows remote attackers to execute arbitrary PHP cod…

No fix yet
Fix from $1,950 2009-08-24
Lunchapp.aplunch HIGH 9.3
CVE-2009-2627

Insecure method vulnerability in the Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2009-08-19
Minb Is Not A Blog HIGH 7.5
CVE-2008-7005EPSS 9%

include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the quotes_to_edi…

No fix yet
Fix from $1,950 2009-08-19
Devalcms HIGH 7.5
CVE-2008-6983EPSS 6%

modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file spe…

No fix yet
Fix from $1,950 2009-08-19
Phpauction HIGH 7.5
CVE-2008-7000

PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan par…

No fix yet
Fix from $1,950 2009-08-19
Projectbutler HIGH 7.5
CVE-2009-2791

PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2009-08-17
Timesheet MEDIUM 6.8
CVE-2009-2769

PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attacker…

No fix yet
Fix from $1,600 2009-08-14
Php Paid 4 Mail Script HIGH 7.5
CVE-2009-2773

PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the …

No fix yet
Fix from $1,950 2009-08-14
Windows 2003 Server HIGH 9.3
CVE-2009-1545EPSS 29%

Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003…

Patch available
Fix from $1,950 2009-08-12
Crossday Discuz\! Board MEDIUM 6.5
CVE-2008-6958EPSS 6%

wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter.

No fix yet
Fix from $1,600 2009-08-12
Mxcamarchive MEDIUM 6.5
CVE-2008-6956

Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code in…

No fix yet
Fix from $1,600 2009-08-12
Free Simple Guestbook Php Script HIGH 7.5
CVE-2008-6934

Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remo…

No fix yet
Fix from $1,950 2009-08-11
Exodus HIGH 10.0
CVE-2008-6935EPSS 5%

Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and ca…

No fix yet
Fix from $1,950 2009-08-11
Exodus HIGH 9.3
CVE-2008-6936

Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and ca…

No fix yet
Fix from $1,950 2009-08-11
Exodus HIGH 10.0
CVE-2008-6937

Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and ca…

Mitigation only
Fix from $1,950 2009-08-11
Opennews MEDIUM 6.5
CVE-2009-2736

Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code i…

No fix yet
Fix from $1,600 2009-08-11
Zodb MEDIUM 6.5
CVE-2009-0668

Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows…

Fix: after 3.8.1
Fix from $1,600 2009-08-07
Availscript Article Script MEDIUM 6.5
CVE-2008-6900

Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users…

No fix yet
Fix from $1,600 2009-08-06
2532gigs MEDIUM 6.8
CVE-2008-6902

Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers to execute arbitrary code by…

No fix yet
Fix from $1,600 2009-08-06
Firefox HIGH 10.0
CVE-2009-2665

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are ena…

Patch available
Fix from $1,950 2009-08-04
Visual C\+\+ HIGH 8.8
CVE-2009-2493EPSS 38%

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and…

Patch available
Fix from $1,950 2009-07-29
Visual C\+\+ HIGH 8.8
CVE-2009-0901EPSS 37%

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Go…

Patch available
Fix from $1,950 2009-07-29
Com Vehiclemanager HIGH 7.5
CVE-2009-2633

PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote a…

No fix yet
Fix from $1,950 2009-07-28
Com Medialibrary HIGH 7.5
CVE-2009-2634

PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote at…

No fix yet
Fix from $1,950 2009-07-28
Com Realestatemanager HIGH 7.5
CVE-2009-2635

PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows re…

No fix yet
Fix from $1,950 2009-07-28
Com Booklibrary HIGH 7.5
CVE-2009-2637

PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote att…

No fix yet
Fix from $1,950 2009-07-28
School Data Nav MEDIUM 6.8
CVE-2009-2641

PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,600 2009-07-28
Android MEDIUM 6.9
CVE-2009-2348

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_R…

Mitigation only
Fix from $1,600 2009-07-17