Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 10.0 CVE-2014-0558EPSS 5% Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.… Flash Player after 15.0.0.252 Fix from $1,9502014-10-15 HIGH 7.5 CVE-2014-5297 The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP obj… X2engine Patch available Fix from $1,9502014-10-10 HIGH 7.5 CVE-2014-7226EPSS 9% The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file wit… Http File Server after 2.3c Fix from $1,9502014-10-10 MEDIUM 6.8 CVE-2014-7296 The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated user… Spagobi Mitigation only Fix from $1,6002014-10-08 HIGH 10.0 CVE-2014-7205EPSS 79% Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for … Bassmaster 1.5.2+ Fix from $1,9502014-10-08 HIGH 10.0 CVE-2014-3188EPSS 6% Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remot… Chrome Os after 38.0.2125.77 Fix from $1,9502014-10-08 HIGH 10.0 CVE-2014-7235EPSS 43% htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.… Freepbx after 2.9.0.8 Fix from $1,9502014-10-07 HIGH 10.0 CVE-2014-6433 gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action. Gopro Hero Firmware Mitigation only Fix from $1,9502014-10-07 MEDIUM 5.5 CVE-2014-3399 The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information dur… Adaptive Security Appliance Software after 9.2 Fix from $1,6002014-10-07 CRITICAL 9.8 CVE-2014-6287 KEVEPSS 99% The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to exe… Http File Server 2.3c+ Fix from $2,3002014-10-07 HIGH 7.5 CVE-2014-2044EPSS 12% Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass in… Owncloud after 4.5.13 Fix from $1,9502014-10-06 HIGH 7.5 CVE-2014-4043 The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which … Glibc after 2.19 Fix from $1,9502014-10-06 HIGH 7.5 CVE-2014-6389EPSS 9% backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter. Phpcompta\/noalyss after 6.7.1 Fix from $1,9502014-10-06 HIGH 7.5 CVE-2013-1436EPSS 9% The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which … Xmonad Contrab after 0.11.1 Fix from $1,9502014-10-06 HIGH 7.5 CVE-2014-6298 Unrestricted file upload vulnerability in the mm_forum extension before 1.9.3 for TYPO3 allows remote attackers to execute arbitrary code by uploadin… Mm Forum after 1.9.2 Fix from $1,9502014-10-03 HIGH 7.5 CVE-2014-3947 Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute ar… Powermail after 1.6.10 Fix from $1,9502014-10-03 HIGH 8.5 CVE-2012-5493 gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execu… Plone after 4.2.2 Fix from $1,9502014-09-30 MEDIUM 5.0 CVE-2012-5495 python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back." Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 6.8 CVE-2012-5485 registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to t… Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5488 python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObje… Plone after 4.2.2 Fix from $1,6002014-09-30 HIGH 7.5 CVE-2014-6446EPSS 46% The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload a… Infusionsoft Gravity Forms Patch available Fix from $1,9502014-09-26 MEDIUM 6.5 CVE-2014-5324 Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbi… N Media File Uploader after 3.3 Fix from $1,6002014-09-26 HIGH 9.3 CVE-2006-1318EPSS 15% Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, wh… Office Mitigation only Fix from $1,9502014-09-19 MEDIUM 6.8 CVE-2013-4444EPSS 14% Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JM… Tomcat after 7.0.39 Fix from $1,6002014-09-12 HIGH 7.5 CVE-2014-2223EPSS 10% Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbi… Plogger after 1.0 Fix from $1,9502014-09-11 HIGH 7.5 CVE-2014-5519EPSS 65% The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[conten… Phpwiki No fix yet Fix from $1,9502014-09-11 HIGH 7.6 CVE-2014-2378 Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which… Trafficdot after 2.10.2 Fix from $1,9502014-09-05 HIGH 7.5 CVE-2014-0485 S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized obje… S3ql after 1.18.1 Fix from $1,9502014-09-02 HIGH 9.3 CVE-2014-5340EPSS 6% The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execu… Check Mk after 1.2.4 Fix from $1,9502014-09-02 HIGH 10.0 CVE-2014-3176EPSS 10% Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attac… Chrome after 37.0.2062.93 Fix from $1,9502014-08-27