Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.8 CVE-2013-5352 Sharetronix 3.1.1.3, 3.1.1, and earlier allows remote attackers to execute arbitrary PHP code via the (1) activities_text parameter to services/activ… Sharetronix after 3.1.1 Fix from $1,6002014-06-13 HIGH 9.3 CVE-2014-3911EPSS 6% Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeContro… Ipolis Device Manager after 1.8.2 Fix from $1,9502014-06-11 HIGH 10.0 CVE-2014-3915 The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands vi… Rocket Servergraph Mitigation only Fix from $1,9502014-06-11 HIGH 7.5 CVE-2013-1756 The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code … Dragonfly Gem Patch available Fix from $1,9502014-06-09 HIGH 7.5 CVE-2014-2051 ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstr… Owncloud Server after 5.0.14 Fix from $1,9502014-06-05 HIGH 7.5 CVE-2012-6141 The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbit… App\ Mitigation only Fix from $1,9502014-06-04 HIGH 7.5 CVE-2012-6142 Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute ar… Html\ Mitigation only Fix from $1,9502014-06-04 HIGH 7.5 CVE-2012-6143 Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary… Spoon Mitigation only Fix from $1,9502014-06-04 MEDIUM 6.0 CVE-2014-3942 The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authen… TYPO3 Mitigation only Fix from $1,6002014-06-03 HIGH 7.5 CVE-2013-1412EPSS 40% DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a… Datalife Engine Patch available Fix from $1,9502014-06-02 HIGH 7.5 CVE-2013-1348 The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than… Symfony Mitigation only Fix from $1,9502014-06-02 HIGH 7.5 CVE-2013-1397 Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml… Symfony Mitigation only Fix from $1,9502014-06-02 HIGH 7.5 CVE-2013-5036EPSS 46% The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function … Square Squash Patch available Fix from $1,9502014-05-27 HIGH 7.5 CVE-2013-0724 PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote a… Wp Ecommerce Shop Styling after 1.7 Fix from $1,9502014-05-27 MEDIUM 6.8 CVE-2014-2720 IZArc 4.1.8 displays a file's name on the basis of a ZIP archive's Central Directory entry, but launches this file on the basis of a ZIP archive's lo… Izarc No fix yet Fix from $1,6002014-05-27 HIGH 9.3 CVE-2014-2196 Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers t… Wide Area Application Services Mitigation only Fix from $1,9502014-05-26 MEDIUM 6.8 CVE-2012-5649EPSS 7% Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, relat… Couchdb after 1.0.3 Fix from $1,6002014-05-23 HIGH 7.5 CVE-2014-3789EPSS 64% GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vect… Cogent Datahub after 7.3.4 Fix from $1,9502014-05-22 MEDIUM 6.5 CVE-2013-4321 The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code… TYPO3 Mitigation only Fix from $1,6002014-05-20 HIGH 9.3 CVE-2014-3444EPSS 6% The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a… Realplayer after 16.0.3.51 Fix from $1,9502014-05-20 MEDIUM 6.5 CVE-2014-3453 Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier f… Flag after 7.x-3.5 Fix from $1,6002014-05-17 HIGH 7.5 CVE-2014-1613 Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected p… Dotclear after 2.6.1 Fix from $1,9502014-05-16 HIGH 10.0 CVE-2014-1806EPSS 40% The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access… .net Framework Mitigation only Fix from $1,9502014-05-14 HIGH 8.5 CVE-2014-1813EPSS 10% Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka "Web Applicatio… Web Applications Mitigation only Fix from $1,9502014-05-14 HIGH 9.0 CVE-2014-0251EPSS 14% Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 an… Office Web Apps Server Mitigation only Fix from $1,9502014-05-14 MEDIUM 6.8 CVE-2013-4581 GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to exe… GitLab after 6.2.3 Fix from $1,6002014-05-12 HIGH 7.5 CVE-2013-0171 Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API. Foreman after 1.0 Fix from $1,9502014-05-08 HIGH 7.5 CVE-2013-0210 The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Pupp… Foreman after 1.0 Fix from $1,9502014-05-08 HIGH 7.5 CVE-2014-2936 The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder… Caldera No fix yet Fix from $1,9502014-05-08 MEDIUM 6.5 CVE-2014-2558 The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP co… File Gallery after 1.7.9 Fix from $1,6002014-05-06