Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Virtual Rooms HIGH 10.0
CVE-2009-0208EPSS 8%

Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unk…

Fix: after 7.0
Fix from $1,950 2009-02-26
Ace 4710 HIGH 7.8
CVE-2009-0625

Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 471…

Mitigation only
Fix from $1,950 2009-02-26
Broadcast Machine HIGH 7.5
CVE-2008-6287

Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the bas…

No fix yet
Fix from $1,950 2009-02-25
Excel HIGH 8.8
CVE-2009-0238 KEVEPSS 43%

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, …

Mitigation only
Fix from $1,950 2009-02-25
Phpfan MEDIUM 6.8
CVE-2008-6251

PHP remote file inclusion vulnerability in includes/init.php in phpFan 3.3.4 allows remote attackers to execute arbitrary PHP code via a URL in the i…

Patch available
Fix from $1,600 2009-02-24
Cybershadecms MEDIUM 6.8
CVE-2009-0701

Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to e…

No fix yet
Fix from $1,600 2009-02-23
Ravennuke MEDIUM 6.5
CVE-2009-0673

Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated…

No fix yet
Fix from $1,600 2009-02-22
Ravennuke MEDIUM 6.0
CVE-2009-0674

images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine t…

No fix yet
Fix from $1,600 2009-02-22
Ravennuke MEDIUM 6.5
CVE-2009-0677EPSS 9%

avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to exe…

No fix yet
Fix from $1,600 2009-02-22
Vim HIGH 9.3
CVE-2008-3075

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation…

Patch available
Fix from $1,950 2009-02-21
Way Of The Warrior HIGH 7.5
CVE-2008-6223

PHP remote file inclusion vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2009-02-20
Dada Mail Manager HIGH 7.5
CVE-2008-6221EPSS 38%

PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attack…

No fix yet
Fix from $1,950 2009-02-20
Simple Php News MEDIUM 5.1
CVE-2009-0643

Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via t…

No fix yet
Fix from $1,600 2009-02-20
Robotstats HIGH 7.5
CVE-2008-6206

Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_R…

No fix yet
Fix from $1,950 2009-02-20
Easysite HIGH 7.5
CVE-2008-6196

Multiple PHP remote file inclusion vulnerabilities in Philippe CROCHAT EasySite 2.0 allow remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,950 2009-02-20
Fckeditor HIGH 7.5
CVE-2008-6178EPSS 8%

Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuk…

No fix yet
Fix from $1,950 2009-02-19
Phpyabs HIGH 7.5
CVE-2009-0639

PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,950 2009-02-18
Simple Php News HIGH 7.5
CVE-2009-0610

Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news…

Mitigation only
Fix from $1,950 2009-02-17
Phpskelsite MEDIUM 5.1
CVE-2009-0595EPSS 22%

PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disab…

No fix yet
Fix from $1,600 2009-02-16
Modules Controller HIGH 7.5
CVE-2008-6138

PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote attackers to execute arbitra…

Fix: after 1.1
Fix from $1,950 2009-02-14
Phpscheduleit MEDIUM 6.8
CVE-2008-6132EPSS 26%

Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execut…

Fix: after 1.2.10
Fix from $1,600 2009-02-13
Flatnux MEDIUM 5.1
CVE-2009-0572EPSS 6%

PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is ena…

No fix yet
Fix from $1,600 2009-02-13
Adaptcms MEDIUM 6.8
CVE-2009-0527

PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP c…

No fix yet
Fix from $1,600 2009-02-11
Snippetmaster Webpage Editor MEDIUM 6.8
CVE-2009-0530

Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitr…

No fix yet
Fix from $1,600 2009-02-11
Phpslash HIGH 10.0
CVE-2009-0517EPSS 55%

Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parame…

Fix: after 0.8.1.1
Fix from $1,950 2009-02-11
Webframe HIGH 7.5
CVE-2009-0513

Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles …

No fix yet
Fix from $1,950 2009-02-11
Rportal HIGH 7.5
CVE-2008-6099

PHP remote file inclusion vulnerability in index.php in RPortal 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in th…

Fix: after 1.1
Fix from $1,950 2009-02-10
A4desk Flash Event Calendar MEDIUM 6.8
CVE-2008-6103

PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute …

No fix yet
Fix from $1,600 2009-02-10
Glinks MEDIUM 6.8
CVE-2009-0463

PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,600 2009-02-10
Gbook MEDIUM 5.1
CVE-2009-0464EPSS 5%

PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,600 2009-02-10