Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Orbit Downloader MEDIUM 5.8
CVE-2009-1064

Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwri…

Fix: after 2.8.7
Fix from $1,600 2009-03-26
Java MEDIUM 6.4
CVE-2009-1102

Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows r…

Patch available
Fix from $1,600 2009-03-25
Vidiscript MEDIUM 6.5
CVE-2008-6518

Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by…

No fix yet
Fix from $1,600 2009-03-25
Cascade HIGH 9.0
CVE-2009-1088EPSS 12%

Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT sty…

No fix yet
Fix from $1,950 2009-03-25
Java System Identity Manager HIGH 9.0
CVE-2009-1083

Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accoun…

Patch available
Fix from $1,950 2009-03-25
Aphpkb MEDIUM 6.8
CVE-2008-6513

Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by up…

Patch available
Fix from $1,600 2009-03-24
Xampp MEDIUM 5.5
CVE-2008-6499

security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof criti…

No fix yet
Fix from $1,600 2009-03-20
Phplinkadmin HIGH 7.5
CVE-2009-1025EPSS 40%

PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL …

No fix yet
Fix from $1,950 2009-03-20
Phpgkit HIGH 7.5
CVE-2008-6491

PHP remote file inclusion vulnerability in connexion.php in PHPGKit 0.9 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUME…

No fix yet
Fix from $1,950 2009-03-19
Mega File Hosting Script HIGH 7.5
CVE-2009-0966

PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL…

No fix yet
Fix from $1,950 2009-03-19
Php Pro Bid MEDIUM 6.8
CVE-2009-0970

PHP remote file inclusion vulnerability in includes/class_image.php in PHP Pro Bid 6.05, when register_globals is enabled, allows remote attackers to…

Mitigation only
Fix from $1,600 2009-03-19
Com Treeg MEDIUM 6.8
CVE-2008-6482EPSS 22%

PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is …

No fix yet
Fix from $1,600 2009-03-18
Com Googlebase HIGH 7.5
CVE-2008-6483EPSS 26%

PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) componen…

No fix yet
Fix from $1,950 2009-03-18
Sharedlog MEDIUM 6.8
CVE-2008-6486

PHP remote file inclusion vulnerability in slideshow_uploadvideo.content.php in SharedLog, when register_globals is enabled, allows remote attackers …

Mitigation only
Fix from $1,600 2009-03-18
Tmos HIGH 9.0
CVE-2008-6474

The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unsp…

Mitigation only
Fix from $1,950 2009-03-16
Foxit Reader HIGH 9.3
CVE-2009-0191EPSS 5%

Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 3.0.2009.1301, does not properly handle a JBIG2 symbol dictionary segment wit…

Patch available
Fix from $1,950 2009-03-10
Maxsite HIGH 7.5
CVE-2008-6446

Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook…

No fix yet
Fix from $1,950 2009-03-09
Social Site Generator HIGH 7.5
CVE-2008-6421

PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP c…

No fix yet
Fix from $1,950 2009-03-06
Openrat HIGH 7.5
CVE-2008-6403

PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to exe…

Fix: after 0.8-beta4
Fix from $1,950 2009-03-06
Ol\'bookmarks HIGH 7.5
CVE-2008-6408

PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,950 2009-03-06
Sofi Webgui HIGH 7.5
CVE-2008-6402

PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute ar…

Fix: after 0.6.3pre
Fix from $1,950 2009-03-06
Phpscheduleit HIGH 7.5
CVE-2009-0820

Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date paramete…

Fix: after 1.2.10
Fix from $1,950 2009-03-05
Sopcore Activex Control HIGH 9.3
CVE-2009-0811EPSS 6%

Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs vi…

No fix yet
Fix from $1,950 2009-03-04
Znc MEDIUM 6.5
CVE-2009-0759

Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file an…

Fix: after 0.062
Fix from $1,600 2009-03-03
Nagios MEDIUM 5.0
CVE-2008-6373

Unspecified vulnerability in Nagios before 3.0.6 has unspecified impact and remote attack vectors related to CGI programs, "adaptive external command…

Fix: after 3.0.5
Fix from $1,600 2009-03-02
Multi Seo Phpbb HIGH 7.5
CVE-2008-6377

PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2009-03-02
Onguma Time Sheet HIGH 7.5
CVE-2008-6347EPSS 20%

PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows …

No fix yet
Fix from $1,950 2009-03-02
Phpmygallery HIGH 7.5
CVE-2008-6315

PHP remote file inclusion vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to execute arbitrary PHP …

No fix yet
Fix from $1,950 2009-02-27
Phpmygallery HIGH 7.5
CVE-2008-6318

PHP remote file inclusion vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to execute arbitrary …

No fix yet
Fix from $1,950 2009-02-27
Free Directory Script MEDIUM 6.8
CVE-2008-6305

PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to exec…

No fix yet
Fix from $1,600 2009-02-26