Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 10.0 CVE-2014-3177 Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attac… Chrome after 37.0.2062.93 Fix from $1,9502014-08-27 HIGH 7.5 CVE-2014-5261EPSS 11% The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharac… Cacti after 0.8.8b Fix from $1,9502014-08-22 MEDIUM 6.5 CVE-2014-4767 IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, wh… Websphere Application Server Mitigation only Fix from $1,6002014-08-22 HIGH 10.0 CVE-2014-5158 The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to exe… Open Source Security Information Management after 4.5 Fix from $1,9502014-08-21 HIGH 10.0 CVE-2014-5210EPSS 15% The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (… Open Source Security Information Management after 4.6.1 Fix from $1,9502014-08-21 MEDIUM 6.5 CVE-2014-5194 Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/… Sphider No fix yet Fix from $1,6002014-08-07 HIGH 9.0 CVE-2013-7394 The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOT… Splunk after 5.0.4 Fix from $1,9502014-08-07 MEDIUM 6.8 CVE-2014-3429 IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary c… Opensuse Patch available Fix from $1,6002014-08-07 MEDIUM 6.8 CVE-2014-0479 reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vectors related to compare_versio… Reportbug after 6.5.0 Fix from $1,6002014-08-06 HIGH 7.9 CVE-2014-3560EPSS 56% NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspec… Ubuntu Linux Mitigation only Fix from $1,9502014-08-06 MEDIUM 6.5 CVE-2014-5090 admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location … Status2k No fix yet Fix from $1,6002014-08-06 MEDIUM 6.0 CVE-2014-3545 Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to execu… Moodle Patch available Fix from $1,6002014-07-29 HIGH 7.5 CVE-2014-3541 The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remot… Moodle Patch available Fix from $1,9502014-07-29 HIGH 7.5 CVE-2014-5112EPSS 9% maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter. Trixbox No fix yet Fix from $1,9502014-07-28 HIGH 9.3 CVE-2014-1556 Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted W… Firefox after 30.0 Fix from $1,9502014-07-23 HIGH 9.3 CVE-2014-1557 The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does no… Firefox after 30.0 Fix from $1,9502014-07-23 MEDIUM 6.8 CVE-2014-3518 jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-07-22 HIGH 7.5 CVE-2014-1999 The auto-format feature in the Request_Curl class in FuelPHP 1.1 through 1.7.1 allows remote attackers to execute arbitrary code via a crafted respon… Fuelphp Mitigation only Fix from $1,9502014-07-20 MEDIUM 6.8 CVE-2014-4663EPSS 10% TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metachara… Timthumb No fix yet Fix from $1,6002014-07-15 HIGH 9.3 CVE-2014-1824EPSS 19% Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a… Windows 7 Patch available Fix from $1,9502014-07-08 MEDIUM 6.8 CVE-2014-0248 org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-07-07 HIGH 7.5 CVE-2014-0602 Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager through 6.5.4 allows remote a… Security Manager after 6.5.4 Fix from $1,9502014-07-07 HIGH 7.5 CVE-2014-4672 The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property. Yiiframework Mitigation only Fix from $1,9502014-07-03 MEDIUM 6.0 CVE-2013-6309 IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct… Marketing Platform Mitigation only Fix from $1,6002014-06-28 MEDIUM 5.0 CVE-2014-3011 IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors. Openpages Grc Platform No fix yet Fix from $1,6002014-06-27 HIGH 10.0 CVE-2014-3496EPSS 5% cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metach… Openshift Patch available Fix from $1,9502014-06-20 HIGH 10.0 CVE-2014-4151EPSS 7% The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a craft… Open Source Security Information Management after 4.7.0 Fix from $1,9502014-06-18 HIGH 10.0 CVE-2014-4152EPSS 6% The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, rel… Open Source Security Information Management after 4.7.0 Fix from $1,9502014-06-18 HIGH 10.0 CVE-2014-3804EPSS 72% The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_in… Open Source Security Information Management after 4.6.1 Fix from $1,9502014-06-13 HIGH 10.0 CVE-2014-3805EPSS 13% The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2)… Open Source Security Information Management after 4.6.1 Fix from $1,9502014-06-13