Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2017-1000196 October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applicat… October after 1.0.412 Fix from $2,3002017-11-17 HIGH 8.8 CVE-2014-4000 Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized … Cacti 1.0.0+ Fix from $1,9502017-11-15 HIGH 8.1 CVE-2017-15806EPSS 11% The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the … Mail 1.8.2+ Fix from $1,9502017-11-15 CRITICAL 9.8 CVE-2017-16783EPSS 8% In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. Cms Made Simple No fix yet Fix from $2,3002017-11-10 HIGH 8.8 CVE-2017-7411EPSS 67% An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the … Tuleap after 9.6 Fix from $1,9502017-10-30 HIGH 7.2 CVE-2017-15935 Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrat… Pandora Fms Mitigation only Fix from $1,9502017-10-27 CRITICAL 9.8 CVE-2017-15376 The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP por… Mobaxterm No fix yet Fix from $2,3002017-10-16 HIGH 8.8 CVE-2017-14353 A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, cou… Ucmdb Foundation Software No fix yet Fix from $1,9502017-10-05 HIGH 8.8 CVE-2015-6576 Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an … Bamboo 5.8.5 / 5.9.7+ Fix from $1,9502017-10-03 HIGH 7.0 CVE-2017-13676 Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL f… Remove \& Reinstall Mitigation only Fix from $1,9502017-09-28 HIGH 8.8 CVE-2017-14764 In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module. Genixcms No fix yet Fix from $1,9502017-09-27 HIGH 8.8 CVE-2014-9463EPSS 15% functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to… Vbseo No fix yet Fix from $1,9502017-09-15 HIGH 7.8 CVE-2017-2809 An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary … Ansible Vault after 1.0.4 Fix from $1,9502017-09-14 HIGH 7.8 CVE-2017-8759 KEVEPSS 87% Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or app… .net Framework Patch available Fix from $1,9502017-09-13 CRITICAL 9.0 CVE-2015-8351EPSS 37% PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote a… Gwolle Guestbook after 1.5.3 Fix from $2,3002017-09-11 HIGH 7.2 CVE-2015-9227 PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote admini… Alegrocart No fix yet Fix from $1,9502017-09-11 HIGH 8.8 CVE-2017-14146 HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\… Helpdezk Mitigation only Fix from $1,9502017-09-05 CRITICAL 9.8 CVE-2017-3897EPSS 12% A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security… Livesafe after 16.0.2 Fix from $2,3002017-09-01 MEDIUM 5.3 CVE-2014-8677 The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing databa… Soplanning after 1.32 Fix from $1,6002017-08-31 CRITICAL 9.8 CVE-2017-0899EPSS 11% RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem… Debian Linux after 2.6.12 Fix from $2,3002017-08-31 HIGH 8.8 CVE-2017-1440 IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted… Emptoris Services Procurement Patch available Fix from $1,9502017-08-30 HIGH 8.8 CVE-2017-10844 baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors. Basercms after 4.0.5 Fix from $1,9502017-08-29 HIGH 7.8 CVE-2014-8872 Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other mod… Fritz\!box 6810 Lte Firmware No fix yet Fix from $1,9502017-08-29 HIGH 8.8 CVE-2017-10835 "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vect… Scr02hd Firmware after 1.0.3.1000 Fix from $1,9502017-08-29 MEDIUM 5.4 CVE-2017-6782 A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in t… Prime Infrastructure Mitigation only Fix from $1,6002017-08-17 CRITICAL 9.8 CVE-2011-0469 Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011. Opensuse Patch available Fix from $2,3002017-08-17 HIGH 7.8 CVE-2017-1469 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation… Infosphere Information Server Mitigation only Fix from $1,9502017-08-14 MEDIUM 6.8 CVE-2017-3753 A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnera… Ideacentre 300 20ish Firmware Mitigation only Fix from $1,6002017-08-10 HIGH 8.8 CVE-2017-11760 uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concat… Projeqtor after 6.3.1 Fix from $1,9502017-07-31 CRITICAL 9.8 CVE-2017-11715 job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins… Metinfo after 5.3.17 Fix from $2,3002017-07-28