Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2017-11675 The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows re… Zen Cart Mitigation only Fix from $1,9502017-07-27 CRITICAL 9.8 CVE-2017-11459 SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr… Trex Mitigation only Fix from $2,3002017-07-25 CRITICAL 9.8 CVE-2017-11585 dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection. Finecms No fix yet Fix from $2,3002017-07-24 HIGH 8.8 CVE-2015-3638 phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts… Phpmybackuppro after 2.5 Fix from $1,9502017-07-21 HIGH 7.5 CVE-2015-3640 phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowled… Phpmybackuppro after 2.5 Fix from $1,9502017-07-21 HIGH 8.8 CVE-2017-9822 KEVEPSS 95% DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." Dotnetnuke 9.1.1+ Fix from $1,9502017-07-20 HIGH 7.8 CVE-2017-11421 gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a l… Gnome Exe Thumbnailer after 0.9.4 Fix from $1,9502017-07-18 HIGH 7.2 CVE-2015-0249 The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary… Roller Mitigation only Fix from $1,9502017-07-17 CRITICAL 9.8 CVE-2017-11167 FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence i… Finecms No fix yet Fix from $2,3002017-07-12 CRITICAL 9.8 CVE-2017-10968 In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code after "<?php" in a route… Finecms No fix yet Fix from $2,3002017-07-07 CRITICAL 9.8 CVE-2017-9841 KEVEPSS 100% Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginn… Phpunit 5.6.3+ Fix from $2,3002017-06-27 MEDIUM 6.6 CVE-2017-6325 The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect w… Messaging Gateway after 10.6.2 Fix from $1,6002017-06-26 CRITICAL 9.8 CVE-2017-9807 An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" p… Openwebif after 1.2.4 Fix from $2,3002017-06-22 HIGH 8.8 CVE-2017-9774 Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication. Horde Image Api Mitigation only Fix from $1,9502017-06-21 CRITICAL 9.8 CVE-2017-9771 install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or database_… Websitebaker Patch available Fix from $2,3002017-06-21 HIGH 8.8 CVE-2015-2252 Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a… Oceanstor Uds Firmware Mitigation only Fix from $1,9502017-06-08 HIGH 8.8 CVE-2017-9442 BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, rel… Bigtree Cms after 4.2.18 Fix from $1,9502017-06-05 HIGH 7.8 CVE-2015-6531 Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmwar… Pan Os after 6.0 Fix from $1,9502017-06-01 HIGH 8.8 CVE-2017-8402 PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file. Pivotx Patch available Fix from $1,9502017-05-31 CRITICAL 9.8 CVE-2017-7494 KEVEPSS 99% Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to up… Debian Linux 4.4.0 / 4.4.14+ Fix from $2,3002017-05-30 HIGH 7.2 CVE-2017-8912 CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.ph… Cms Made Simple Patch available Fix from $1,9502017-05-12 HIGH 8.8 CVE-2017-7911 A Code Injection issue was discovered in CyberVision Kaa IoT Platform, Version 0.7.4. An insufficient-encapsulation vulnerability has been identified… Kaa Iot Platform Mitigation only Fix from $1,9502017-05-06 HIGH 7.0 CVE-2017-8284 The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the inst… Qemu after 2.8.1.1 Fix from $1,9502017-04-26 HIGH 8.8 CVE-2016-4895 SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors. Setucocms No fix yet Fix from $1,9502017-04-12 HIGH 8.8 CVE-2017-7694 Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to e… Symphony after 2.6.11 Fix from $1,9502017-04-11 CRITICAL 9.8 CVE-2017-7691 A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592. Trex Mitigation only Fix from $2,3002017-04-11 CRITICAL 9.8 CVE-2017-7625 In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execu… Fiyo Cms No fix yet Fix from $2,3002017-04-10 HIGH 8.8 CVE-2016-5072 OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Ente… Oxid Eshop after 5.2.8 Fix from $1,9502017-04-10 HIGH 8.8 CVE-2017-7570 PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .j… Pivotx No fix yet Fix from $1,9502017-04-07 HIGH 8.8 CVE-2017-4964 Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the di… Bosh Azure Cpi Patch available Fix from $1,9502017-04-06