Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.5 CVE-2013-4438 Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this… Salt after 0.17.0 Fix from $1,9502013-11-05 MEDIUM 6.5 CVE-2013-6366EPSS 7% The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().… Hyperic Hq No fix yet Fix from $1,6002013-11-04 HIGH 8.5 CVE-2013-6349 McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vect… Email Gateway Mitigation only Fix from $1,9502013-11-02 MEDIUM 6.0 CVE-2013-3631EPSS 14% NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execu… Nas4free after 9.1.0.1.804 Fix from $1,6002013-11-02 MEDIUM 6.8 CVE-2013-2208 tpp 1.3.1 allows remote attackers to execute arbitrary commands via a --exec command in a TPP template file. Tpp Patch available Fix from $1,6002013-10-28 MEDIUM 6.8 CVE-2013-4957 The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted report-specific type. Puppet Enterprise after 3.0.0 Fix from $1,6002013-10-25 MEDIUM 6.0 CVE-2013-3244 Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for SAP ERP Central Component (EC… Erp Central Component Mitigation only Fix from $1,6002013-10-24 HIGH 7.5 CVE-2013-4830EPSS 6% HP Service Manager 9.30 through 9.32 allows remote attackers to execute arbitrary code via an unspecified "injection" approach. Service Manager Mitigation only Fix from $1,9502013-10-16 HIGH 7.5 CVE-2013-4203 The self.run_gpg function in lib/rgpg/gpg_helper.rb in the rgpg gem before 0.2.3 for Ruby allows remote attackers to execute arbitrary commands via s… Rgpg after 0.2.2 Fix from $1,9502013-10-11 HIGH 9.3 CVE-2013-5325 Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a javascript: URL via a crafte… Acrobat Mitigation only Fix from $1,9502013-10-09 MEDIUM 6.8 CVE-2013-4330EPSS 9% Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expres… Camel after 2.9.6 Fix from $1,6002013-10-04 HIGH 10.0 CVE-2013-0689EPSS 5% The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L R… Ose after 3.50 Fix from $1,9502013-10-03 MEDIUM 6.8 CVE-2013-5942 Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialize… Graphite Patch available Fix from $1,6002013-09-27 MEDIUM 6.8 CVE-2013-5093EPSS 39% The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows… Graphite Patch available Fix from $1,6002013-09-27 HIGH 9.3 CVE-2013-5369 IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code… Spss Analytical Decision Management Mitigation only Fix from $1,9502013-09-16 HIGH 7.5 CVE-2013-5674 badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, whi… Moodle Patch available Fix from $1,9502013-09-16 CRITICAL 9.8 CVE-2013-4810 KEVEPSS 79% HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attac… Application Lifecycle Management Mitigation only Fix from $2,3002013-09-16 HIGH 10.0 CVE-2013-4813EPSS 9% The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows re… Identity Driven Manager Mitigation only Fix from $1,9502013-09-16 HIGH 7.5 CVE-2013-4338EPSS 9% wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to ex… WordPress after 3.6 Fix from $1,9502013-09-12 MEDIUM 5.0 CVE-2013-1647 Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attacke… Open Xchange Server No fix yet Fix from $1,6002013-09-05 MEDIUM 5.0 CVE-2013-2582 CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6,… Open Xchange Appsuite Mitigation only Fix from $1,6002013-09-05 HIGH 7.5 CVE-2013-5647 lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. Sounder No fix yet Fix from $1,9502013-08-29 HIGH 7.5 CVE-2013-1435 (1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vec… Cacti Patch available Fix from $1,9502013-08-23 MEDIUM 5.0 CVE-2013-3373 CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP hea… Rt Patch available Fix from $1,6002013-08-23 HIGH 8.5 CVE-2013-4172 The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors. Cloudforms Management Engine Mitigation only Fix from $1,9502013-08-23 HIGH 10.0 CVE-2013-2802 The universal protocol implementation in Sixnet UDR before 2.0 and RTU firmware before 4.8 allows remote attackers to execute arbitrary code; read, m… Udr after 4.7 Fix from $1,9502013-08-21 HIGH 7.5 CVE-2013-2161 XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r… Folsom Mitigation only Fix from $1,9502013-08-20 MEDIUM 6.0 CVE-2013-2121EPSS 25% Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with perm… Openstack after 1.2.0 Fix from $1,6002013-07-31 MEDIUM 6.5 CVE-2013-3402 An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary c… Unified Communications Manager Mitigation only Fix from $1,6002013-07-18 HIGH 9.3 CVE-2013-2134EPSS 70% Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly … Struts 2.3.14.3+ Fix from $1,9502013-07-16