Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Flexcustomer0.0.6 HIGH 10.0
CVE-2008-6761EPSS 6%

Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.i…

No fix yet
Fix from $1,950 2009-04-28
Sma Db HIGH 7.5
CVE-2009-1452

Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2009-04-28
Razorcms HIGH 7.5
CVE-2009-1463

Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving content as a …

Fix: after 0.3
Fix from $1,950 2009-04-28
Sma Db HIGH 7.5
CVE-2009-1450

PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_c…

No fix yet
Fix from $1,950 2009-04-28
Webportal Cms HIGH 7.5
CVE-2009-1444

PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in th…

No fix yet
Fix from $1,950 2009-04-27
Megacubo HIGH 9.3
CVE-2008-6748

Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.

No fix yet
Fix from $1,950 2009-04-24
Homap MEDIUM 6.8
CVE-2008-6740

PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary PHP code…

No fix yet
Fix from $1,600 2009-04-21
phpMyAdmin HIGH 7.5
CVE-2009-1285EPSS 11%

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote at…

Patch available
Fix from $1,950 2009-04-16
Directx HIGH 9.3
CVE-2009-0084EPSS 32%

Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or vi…

Mitigation only
Fix from $1,950 2009-04-15
Ie HIGH 9.3
CVE-2009-0552EPSS 29%

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allow…

Mitigation only
Fix from $1,950 2009-04-15
Gravity Board X HIGH 7.5
CVE-2009-1278

Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP cod…

No fix yet
Fix from $1,950 2009-04-09
Xpdf MEDIUM 6.9
CVE-2009-1144

Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file…

Fix: after 3.02
Fix from $1,600 2009-04-09
Ananta Cms MEDIUM 6.8
CVE-2008-6665

change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email paramete…

No fix yet
Fix from $1,600 2009-04-08
Quickersite HIGH 7.5
CVE-2008-6677

Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to e…

No fix yet
Fix from $1,950 2009-04-08
Oxybox HIGH 10.0
CVE-2008-6651

Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory…

No fix yet
Fix from $1,950 2009-04-07
Dagger MEDIUM 6.8
CVE-2008-6635

PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, al…

Patch available
Fix from $1,600 2009-04-07
Dagger MEDIUM 6.8
CVE-2008-6636

PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, al…

No fix yet
Fix from $1,600 2009-04-07
Minimal Ablog MEDIUM 6.8
CVE-2008-6612

Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a fi…

No fix yet
Fix from $1,600 2009-04-06
Acute Control Panel HIGH 7.5
CVE-2009-1248

Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the…

No fix yet
Fix from $1,950 2009-04-06
Torrentflux MEDIUM 6.0
CVE-2008-6584

html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file containing an executable extensio…

No fix yet
Fix from $1,600 2009-04-03
Lightneasy MEDIUM 5.0
CVE-2008-6591

LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create arbitrary files via the page …

No fix yet
Fix from $1,600 2009-04-03
Office Powerpoint HIGH 8.8
CVE-2009-0556 KEVEPSS 68%

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arb…

Patch available
Fix from $1,950 2009-04-03
Podcast Generator MEDIUM 6.5
CVE-2009-1230

Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary …

Fix: after 1.1
Fix from $1,600 2009-04-02
Ixprim HIGH 7.5
CVE-2006-7237

PHP remote file inclusion vulnerability in mod/nc_phpmyadmin/core/libraries/Theme_Manager.class.php in Ixprim 2.0 allows remote attackers to execute …

No fix yet
Fix from $1,950 2009-03-31
Destar MEDIUM 6.5
CVE-2008-6539

Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject …

No fix yet
Fix from $1,600 2009-03-30
Quick Classifieds HIGH 7.5
CVE-2008-6543

Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) lo…

No fix yet
Fix from $1,950 2009-03-30
Simple Machines Forum HIGH 7.5
CVE-2008-6544

Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2009-03-30
Web Server Creator Web Portal HIGH 7.5
CVE-2008-6545

PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,950 2009-03-30
Jira MEDIUM 6.8
CVE-2008-6531

The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted U…

Fix: 3.13.2+
Fix from $1,600 2009-03-26
Debian Linux CRITICAL 9.8
CVE-2009-1151 KEVEPSS 95%

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitr…

Fix: 2.11.9.5 / 3.1.3.1+
Fix from $2,300 2009-03-26