Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Sapgui HIGH 9.3
CVE-2008-4387EPSS 16%

Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unk…

Mitigation only
Fix from $1,950 2008-11-10
Istant Replay HIGH 7.5
CVE-2008-4911

PHP remote file inclusion vulnerability in read.php in Chattaitaliano Istant-Replay allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,950 2008-11-04
Smarty HIGH 7.5
CVE-2008-4810

The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP cod…

Mitigation only
Fix from $1,950 2008-10-31
Webgui HIGH 9.3
CVE-2008-4798

The loadModule function in lib/WebGUI/Asset.pm in WebGUI before 7.5.30 (stable) allows remote attackers to execute arbitrary code by uploading a Perl…

Fix: after 7.5.10
Fix from $1,950 2008-10-30
Coast HIGH 8.5
CVE-2008-4735

PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute a…

No fix yet
Fix from $1,950 2008-10-24
Windows 2000 CRITICAL 9.8
CVE-2008-4250 KEVEPSS 99%

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows rem…

Patch available
Fix from $2,300 2008-10-23
Openengine HIGH 9.3
CVE-2008-4719

PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remo…

No fix yet
Fix from $1,950 2008-10-23
Gemini Portal HIGH 9.3
CVE-2008-4720

Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lan…

No fix yet
Fix from $1,950 2008-10-23
Sezhoo HIGH 10.0
CVE-2008-4704

PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in …

No fix yet
Fix from $1,950 2008-10-23
Mantis HIGH 9.0
CVE-2008-4687EPSS 67%

manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences…

Fix: after 1.1.3
Fix from $1,950 2008-10-22
Events Calendar HIGH 10.0
CVE-2008-4673

PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote atta…

No fix yet
Fix from $1,950 2008-10-22
Phpwebgallery HIGH 9.0
CVE-2008-4645EPSS 7%

plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via P…

Fix: after 1.7.2
Fix from $1,950 2008-10-22
Fast Click Sql Lite HIGH 9.3
CVE-2008-4624

PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execut…

No fix yet
Fix from $1,950 2008-10-21
Cutenews HIGH 10.0
CVE-2008-4557EPSS 45%

plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the te…

No fix yet
Fix from $1,950 2008-10-14
System Requirements Lab HIGH 9.3
CVE-2008-4385EPSS 38%

Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary…

Mitigation only
Fix from $1,950 2008-10-14
Asicms HIGH 7.5
CVE-2008-4529

Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[a…

No fix yet
Fix from $1,950 2008-10-09
Dff Framework Api HIGH 10.0
CVE-2008-4502

Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a…

No fix yet
Fix from $1,950 2008-10-09
System Analyzer Tool HIGH 7.2
CVE-2008-4451

The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via …

No fix yet
Fix from $1,950 2008-10-06
Datafeed Studio HIGH 10.0
CVE-2008-4439

PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrar…

Fix: after 1.6.2
Fix from $1,950 2008-10-03
Mac Os X HIGH 9.3
CVE-2008-3638

Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary pro…

Mitigation only
Fix from $1,950 2008-09-26
Dolphin HIGH 7.5
CVE-2008-4206

PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attacke…

No fix yet
Fix from $1,950 2008-09-24
Technote HIGH 10.0
CVE-2008-4138EPSS 10%

PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute ar…

No fix yet
Fix from $1,950 2008-09-24
.x10 Automatic Mp3 Script HIGH 7.5
CVE-2008-4141

Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code vi…

No fix yet
Fix from $1,950 2008-09-24
Secure Directory HIGH 10.0
CVE-2008-4188

Unspecified vulnerability in the TYPO3 Secure Directory (kw_secdir) extension before 1.0.2 allows remote attackers to execute arbitrary code via unkn…

Fix: after 1.0.1
Fix from $1,950 2008-09-23
Suse Linux HIGH 7.2
CVE-2008-3949

emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which…

Mitigation only
Fix from $1,950 2008-09-22
Phprealty HIGH 7.5
CVE-2008-4134EPSS 8%

PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows rem…

Fix: after 0.03
Fix from $1,950 2008-09-19
Flexnet Connect HIGH 9.3
CVE-2008-1093

Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect …

Mitigation only
Fix from $1,950 2008-09-18
Novell Forum HIGH 7.5
CVE-2008-4047

Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL cod…

Patch available
Fix from $1,950 2008-09-11
Organization Chart HIGH 9.3
CVE-2008-3956EPSS 13%

orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute…

No fix yet
Fix from $1,950 2008-09-11
Windows Media Player HIGH 9.3
CVE-2008-2253EPSS 30%

Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that i…

Mitigation only
Fix from $1,950 2008-09-11