Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2013-4438
Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this…
Salt
after 0.17.0
MEDIUM 6.5
CVE-2013-6366EPSS 7%
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().…
Hyperic Hq
No fix yet
HIGH 8.5
CVE-2013-6349
McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vect…
Email Gateway
Mitigation only
MEDIUM 6.0
CVE-2013-3631EPSS 14%
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execu…
Nas4free
after 9.1.0.1.804
MEDIUM 6.8
CVE-2013-2208
tpp 1.3.1 allows remote attackers to execute arbitrary commands via a --exec command in a TPP template file.
Tpp
Patch available
MEDIUM 6.8
CVE-2013-4957
The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted report-specific type.
Puppet Enterprise
after 3.0.0
MEDIUM 6.0
CVE-2013-3244
Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for SAP ERP Central Component (EC…
Erp Central Component
Mitigation only
HIGH 7.5
CVE-2013-4830EPSS 6%
HP Service Manager 9.30 through 9.32 allows remote attackers to execute arbitrary code via an unspecified "injection" approach.
Service Manager
Mitigation only
HIGH 7.5
CVE-2013-4203
The self.run_gpg function in lib/rgpg/gpg_helper.rb in the rgpg gem before 0.2.3 for Ruby allows remote attackers to execute arbitrary commands via s…
Rgpg
after 0.2.2
HIGH 9.3
CVE-2013-5325
Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a javascript: URL via a crafte…
Acrobat
Mitigation only
MEDIUM 6.8
CVE-2013-4330EPSS 9%
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expres…
Camel
after 2.9.6
HIGH 10.0
CVE-2013-0689EPSS 5%
The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L R…
Ose
after 3.50
MEDIUM 6.8
CVE-2013-5942
Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialize…
Graphite
Patch available
MEDIUM 6.8
CVE-2013-5093EPSS 39%
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows…
Graphite
Patch available
HIGH 9.3
CVE-2013-5369
IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code…
Spss Analytical Decision Management
Mitigation only
HIGH 7.5
CVE-2013-5674
badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, whi…
Moodle
Patch available
CRITICAL 9.8
CVE-2013-4810 KEVEPSS 79%
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attac…
Application Lifecycle Management
Mitigation only
HIGH 10.0
CVE-2013-4813EPSS 9%
The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows re…
Identity Driven Manager
Mitigation only
HIGH 7.5
CVE-2013-4338EPSS 9%
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to ex…
WordPress
after 3.6
MEDIUM 5.0
CVE-2013-1647
Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attacke…
Open Xchange Server
No fix yet
MEDIUM 5.0
CVE-2013-2582
CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6,…
Open Xchange Appsuite
Mitigation only
HIGH 7.5
CVE-2013-5647
lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
Sounder
No fix yet
HIGH 7.5
CVE-2013-1435
(1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vec…
Cacti
Patch available
MEDIUM 5.0
CVE-2013-3373
CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP hea…
Rt
Patch available
HIGH 8.5
CVE-2013-4172
The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors.
Cloudforms Management Engine
Mitigation only
HIGH 10.0
CVE-2013-2802
The universal protocol implementation in Sixnet UDR before 2.0 and RTU firmware before 4.8 allows remote attackers to execute arbitrary code; read, m…
Udr
after 4.7
HIGH 7.5
CVE-2013-2161
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…
Folsom
Mitigation only
MEDIUM 6.0
CVE-2013-2121EPSS 25%
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with perm…
Openstack
after 1.2.0
MEDIUM 6.5
CVE-2013-3402
An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary c…
Unified Communications Manager
Mitigation only
HIGH 9.3
CVE-2013-2134EPSS 70%
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly …
Struts
2.3.14.3+