Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2016-7110 Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a dif… Uma Mitigation only Fix from $2,3002016-09-07 CRITICAL 9.8 CVE-2016-7109 Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a dif… Uma Mitigation only Fix from $2,3002016-09-07 CRITICAL 9.8 CVE-2015-5721 Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data… Misp after 2.3.89 Fix from $2,3002016-09-03 HIGH 7.5 CVE-2016-2119 libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a clie… Samba 4.2.14 / 4.3.11+ Fix from $1,9502016-07-07 CRITICAL 9.8 CVE-2016-5734EPSS 81% phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_repla… phpMyAdmin Patch available Fix from $2,3002016-07-03 MEDIUM 6.5 CVE-2016-1413 The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted cod… Secure Firewall Management Center Mitigation only Fix from $1,6002016-05-28 CRITICAL 9.8 CVE-2016-3154 The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote att… Spip Patch available Fix from $2,3002016-04-08 CRITICAL 9.8 CVE-2016-3153 SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related … Debian Linux Patch available Fix from $2,3002016-04-08 MEDIUM 5.3 CVE-2015-5970 The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection atta… Zenworks Configuration Management Mitigation only Fix from $1,6002016-02-18 CRITICAL 9.8 CVE-2016-1986 HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t… Continuous Delivery Automation Patch available Fix from $2,3002016-02-12 HIGH 7.5 CVE-2016-0033EPSS 18% Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote at… .net Framework Mitigation only Fix from $1,9502016-02-10 CRITICAL 10.0 CVE-2016-1985EPSS 7% HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to … Operations Manager Patch available Fix from $2,3002016-01-30 CRITICAL 9.0 CVE-2015-8761 The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value se… Values Patch available Fix from $2,3002016-01-08 MEDIUM 6.0 CVE-2015-5242 OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authe… Gluster Storage Mitigation only Fix from $1,6002015-11-25 HIGH 7.5 CVE-2015-7905 Unitronics VisiLogic OPLC IDE before 9.8.02 allows remote attackers to execute unspecified code via unknown vectors. Visilogic Oplc Ide after 9.8.0.00 Fix from $1,9502015-11-13 HIGH 8.5 CVE-2015-6555 Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the cons… Endpoint Protection Manager after 12.1 Fix from $1,9502015-11-12 MEDIUM 6.5 CVE-2015-7729 Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenti… Hana No fix yet Fix from $1,6002015-10-15 HIGH 8.5 CVE-2015-5647 The RSS Reader component in Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via… Garoon Mitigation only Fix from $1,9502015-10-12 HIGH 8.5 CVE-2015-5646 Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka Cy… Garoon Patch available Fix from $1,9502015-10-12 MEDIUM 6.8 CVE-2015-5644 The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code vi… Matchasns after 1.3.6 Fix from $1,6002015-10-06 MEDIUM 6.8 CVE-2015-5643 The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP cod… Matchasns after 1.3.6 Fix from $1,6002015-10-06 HIGH 7.5 CVE-2015-5687 system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code … Anchor Cms Patch available Fix from $1,9502015-10-05 HIGH 7.5 CVE-2015-7381 Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to exe… Refbase after 0.9.6 Fix from $1,9502015-09-28 MEDIUM 6.5 CVE-2015-5603EPSS 59% The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors… Hipchat after 6.29.2 Fix from $1,6002015-09-21 HIGH 7.9 CVE-2015-5693 The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute… Web Gateway after 5.2.2 Fix from $1,9502015-09-20 HIGH 9.0 CVE-2014-8778 Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitr… Cxsast after 7.1.6 Fix from $1,9502015-09-16 HIGH 8.5 CVE-2014-2331 Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. … Check Mk after 1.2.3 Fix from $1,9502015-08-31 MEDIUM 6.8 CVE-2015-2308 Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6… Symfony Patch available Fix from $1,6002015-06-24 HIGH 7.5 CVE-2015-4726 PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arbitrary PHP code via a URL in … Audioshare No fix yet Fix from $1,9502015-06-23 MEDIUM 6.5 CVE-2015-4338 Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the… Xcloner No fix yet Fix from $1,6002015-06-17