Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.5 CVE-2013-7034 The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a … Livezilla after 5.1.2.0 Fix from $1,9502014-05-05 HIGH 9.0 CVE-2014-2170 Cisco TelePresence TC Software 4.x and 5.x before 5.1.7 and 6.x before 6.0.1 and TE Software 4.x and 6.0 allow remote authenticated users to execute … Telepresence Te Software Mitigation only Fix from $1,9502014-05-02 MEDIUM 6.8 CVE-2013-7284 The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via a craft… Pirpc after 0.2020 Fix from $1,6002014-04-29 HIGH 7.1 CVE-2014-2996EPSS 10% XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary co… Xcloner after 3.5 Fix from $1,9502014-04-25 MEDIUM 5.8 CVE-2014-2909 CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitr… Simatic S7 Cpu 1200 Firmware Mitigation only Fix from $1,6002014-04-25 MEDIUM 5.1 CVE-2014-0472EPSS 6% The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows rem… Django after 1.4.10 Fix from $1,6002014-04-23 MEDIUM 6.5 CVE-2013-6469 JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression … Jboss Fuse Service Works Mitigation only Fix from $1,6002014-04-22 HIGH 7.5 CVE-2014-2921EPSS 7% The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an obje… Pimcore Patch available Fix from $1,9502014-04-21 MEDIUM 6.5 CVE-2014-0111 Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Co… Syncope 1.0.9 / 1.1.7+ Fix from $1,6002014-04-17 HIGH 10.0 CVE-2014-2866 PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to per… Commonspot Content Server after 7.0.1 Fix from $1,9502014-04-15 HIGH 7.5 CVE-2013-7362 An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors. Ccms Agent No fix yet Fix from $1,9502014-04-10 MEDIUM 6.5 CVE-2013-6468 JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java c… Jboss Bpm Suite Mitigation only Fix from $1,6002014-04-10 HIGH 7.5 CVE-2014-1716 Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.1… Chrome after 34.0.1847.115 Fix from $1,9502014-04-09 HIGH 7.5 CVE-2014-1691EPSS 43% The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attac… Horde Application Framework after 5.1.0 Fix from $1,9502014-04-01 MEDIUM 6.8 CVE-2014-1979 The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers… Spmode Mail Android Mitigation only Fix from $1,6002014-03-19 HIGH 7.5 CVE-2014-0057 The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remo… Cloudforms Mitigation only Fix from $1,9502014-03-18 MEDIUM 6.5 CVE-2013-1850 Multiple incomplete blacklist vulnerabilities in (1) import.php and (2) ajax/uploadimport.php in apps/contacts/ in ownCloud before 4.0.13 and 4.5.x b… Owncloud Server after 4.0.12 Fix from $1,6002014-03-14 MEDIUM 5.0 CVE-2013-6943 Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attacke… Netscaler Application Delivery Controller Firmware Mitigation only Fix from $1,6002014-03-11 HIGH 7.5 CVE-2014-1939 java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchB… Android after 4.3.1 Fix from $1,9502014-03-03 MEDIUM 6.8 CVE-2014-2089 ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain clien… Ilias No fix yet Fix from $1,6002014-03-02 HIGH 9.3 CVE-2013-2817EPSS 6% An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary p… Mc Worx Suite after 8.02 Fix from $1,9502014-02-24 HIGH 7.8 CVE-2013-6948 The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document con… Wemo Home Automation Firmware Mitigation only Fix from $1,9502014-02-22 HIGH 7.5 CVE-2014-0818 Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a T… Autocad after 2013 Fix from $1,9502014-02-22 HIGH 10.0 CVE-2014-0294EPSS 21% Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitra… Microsoft Forefront Protection 2010 Mitigation only Fix from $1,9502014-02-12 MEDIUM 6.8 CVE-2014-1670EPSS 14% The Microsoft Bing application before 4.2.1 for Android allows remote attackers to install arbitrary APK files via vectors involving a crafted DNS re… Bing after 4.2.0 Fix from $1,6002014-01-25 HIGH 9.3 CVE-2014-1202EPSS 8% The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a… Soapui after 4.6.3 Fix from $1,9502014-01-25 HIGH 8.3 CVE-2014-0661 The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX131… Telepresence System Software after 1.10.1 Fix from $1,9502014-01-22 HIGH 7.5 CVE-2014-0792 Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors relate… Nexus Patch available Fix from $1,9502014-01-17 HIGH 7.5 CVE-2013-2827EPSS 48% An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers… Kingalarm\&event after 3.1 Fix from $1,9502014-01-15 HIGH 10.0 CVE-2012-0262EPSS 73% op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary command… Monitor after 5.5.1 Fix from $1,9502013-12-31