Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2017-7402EPSS 5% Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanage… Pixie No fix yet Fix from $2,3002017-04-03 CRITICAL 9.8 CVE-2014-3927 mrlg-lib.php in mrlg4php before 1.0.8 allows remote attackers to execute arbitrary shell code. Mrlg4php after 1.0.7 Fix from $2,3002017-04-03 CRITICAL 9.8 CVE-2017-7321 setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parame… Modx Revolution after 2.5.4 Fix from $2,3002017-03-30 CRITICAL 9.8 CVE-2017-7324 setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path paramete… Modx Revolution after 2.5.4 Fix from $2,3002017-03-30 CRITICAL 9.8 CVE-2014-3582 In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates fo… Ambari after 2.2.2 Fix from $2,3002017-03-29 HIGH 7.0 CVE-2017-6455 NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variab… Ntp Patch available Fix from $1,9502017-03-27 CRITICAL 9.8 CVE-2015-0855 The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file… Pitivi after 0.94 Fix from $2,3002017-03-23 HIGH 7.8 CVE-2016-1602 A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise De… Linux Enterprise Desktop Mitigation only Fix from $1,9502017-03-23 MEDIUM 6.7 CVE-2017-6186 Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and ear… Antivirus Plus after 12.0 Fix from $1,6002017-03-21 HIGH 8.0 CVE-2016-8020EPSS 11% Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authentica… Virusscan Enterprise after 2.0.3 Fix from $1,9502017-03-14 CRITICAL 9.1 CVE-2017-2968 Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability. Campaign after 16.4 Fix from $2,3002017-02-15 HIGH 7.0 CVE-2016-8354 An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Si… Unity Pro after 11.0 Fix from $1,9502017-02-13 CRITICAL 9.8 CVE-2015-8771 The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password. Gosa Plugin Patch available Fix from $2,3002017-02-13 CRITICAL 9.8 CVE-2016-5726 Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via th… Simple Machines Forum Patch available Fix from $2,3002017-02-09 HIGH 8.8 CVE-2016-5727 LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via ve… Simple Machines Forum Patch available Fix from $1,9502017-02-09 CRITICAL 9.8 CVE-2016-6175EPSS 20% Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms heade… Php Gettext after 1.0.12 Fix from $2,3002017-02-07 HIGH 8.4 CVE-2016-7102 ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in t… Owncloud Desktop Client after 2.2.2 Fix from $1,9502017-01-23 CRITICAL 9.8 CVE-2016-2242EPSS 7% Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php. Exponent Cms Patch available Fix from $2,3002017-01-23 CRITICAL 9.8 CVE-2016-10157 Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated … Netsession No fix yet Fix from $2,3002017-01-23 CRITICAL 9.8 CVE-2017-5543 includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data i… Subrion Patch available Fix from $2,3002017-01-20 MEDIUM 5.3 CVE-2016-10072 WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but… Wampserver No fix yet Fix from $1,6002016-12-27 HIGH 7.3 CVE-2016-7966 Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on t… Debian Linux after 4.4.0 Fix from $1,9502016-12-23 HIGH 8.1 CVE-2016-7967 KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security… Kmail after 5.3.0 Fix from $1,9502016-12-23 MEDIUM 6.5 CVE-2016-7968 KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and includ… Kmail after 5.3.0 Fix from $1,6002016-12-23 CRITICAL 9.8 CVE-2016-7954EPSS 8% Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. … Bundler Patch available Fix from $2,3002016-12-22 HIGH 7.8 CVE-2016-9949EPSS 18% An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it… Ubuntu Linux after 12.10 Fix from $1,9502016-12-17 HIGH 7.5 CVE-2016-9862 An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4… phpMyAdmin Patch available Fix from $1,9502016-12-11 HIGH 7.1 CVE-2016-5424 PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users… Debian Linux after 9.1.22 Fix from $1,9502016-12-09 CRITICAL 9.8 CVE-2016-1000003 Mirror Manager version 0.7.2 and older is vulnerable to remote code execution in the checkin code. Mirror Manager after 0.7.2 Fix from $2,3002016-10-07 HIGH 8.8 CVE-2016-5149 The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to … Chrome after 52.0.2743.116 Fix from $1,9502016-09-11