Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 9.3 CVE-2013-2135EPSS 14% Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" an… Struts 2.3.14.3+ Fix from $1,9502013-07-16 HIGH 10.0 CVE-2013-1777EPSS 10% The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o… Geronimo Patch available Fix from $1,9502013-07-11 HIGH 9.3 CVE-2013-1965EPSS 94% Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a cr… Struts 2.3.14.1+ Fix from $1,9502013-07-10 HIGH 9.3 CVE-2013-1966EPSS 74% Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using … Struts 2.3.14.1+ Fix from $1,9502013-07-10 HIGH 8.1 CVE-2013-2115EPSS 75% Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using … Struts after 2.3.14.1 Fix from $1,9502013-07-10 HIGH 9.3 CVE-2013-3132EPSS 22% Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, wh… .net Framework Mitigation only Fix from $1,9502013-07-10 HIGH 9.3 CVE-2013-3133EPSS 21% Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote … .net Framework Mitigation only Fix from $1,9502013-07-10 HIGH 9.3 CVE-2013-3134EPSS 21% The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays o… .net Framework Mitigation only Fix from $1,9502013-07-10 HIGH 9.3 CVE-2013-3171EPSS 21% The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of deleg… .net Framework Mitigation only Fix from $1,9502013-07-10 HIGH 9.3 CVE-2013-3127EPSS 22% The Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime… Windows Media Format Runtime Mitigation only Fix from $1,9502013-07-10 HIGH 7.8 CVE-2013-3129EPSS 32% Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWr… .net Framework Mitigation only Fix from $1,9502013-07-10 HIGH 9.3 CVE-2013-3131EPSS 22% Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidim… .net Framework Mitigation only Fix from $1,9502013-07-10 HIGH 7.5 CVE-2013-3651 LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/… Ec Cube Mitigation only Fix from $1,9502013-06-30 HIGH 9.0 CVE-2013-3384 The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email… Ironport Asyncos after 7.1.3 Fix from $1,9502013-06-27 HIGH 9.0 CVE-2013-3383 The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows… Ironport Asyncos after 7.1.3 Fix from $1,9502013-06-27 HIGH 9.3 CVE-2013-1688 The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to … Firefox after 21.0 Fix from $1,9502013-06-26 HIGH 7.5 CVE-2013-3520EPSS 56% VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via … Vcenter Chargeback Manager after 2.5.0 Fix from $1,9502013-06-17 MEDIUM 6.5 CVE-2013-0143EPSS 7% cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authen… Viostor Network Video Recorder Mitigation only Fix from $1,6002013-06-07 HIGH 9.3 CVE-2013-1323EPSS 21% Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code… Publisher Mitigation only Fix from $1,9502013-05-15 HIGH 9.3 CVE-2013-1335EPSS 21% Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape C… Word Mitigation only Fix from $1,9502013-05-15 MEDIUM 6.5 CVE-2013-3508 html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated us… Groundwork Monitor Mitigation only Fix from $1,6002013-05-08 HIGH 9.0 CVE-2013-3079 VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to execute arbitrary programs with root privileges by le… Vcenter Server Appliance Mitigation only Fix from $1,9502013-05-01 MEDIUM 6.8 CVE-2013-0132 The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to exec… Parallels Plesk Panel Mitigation only Fix from $1,6002013-04-18 HIGH 9.3 CVE-2013-1296EPSS 21% The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memor… Remote Desktop Connection Mitigation only Fix from $1,9502013-04-09 HIGH 7.5 CVE-2013-1898 lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. Thumbshooter Mitigation only Fix from $1,9502013-04-09 MEDIUM 6.5 CVE-2013-1899EPSS 54% Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a den… PostgreSQL Mitigation only Fix from $1,6002013-04-04 HIGH 7.5 CVE-2013-2615 lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. Fastreader No fix yet Fix from $1,9502013-03-20 HIGH 7.5 CVE-2013-2616 lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. Mini Magick No fix yet Fix from $1,9502013-03-20 HIGH 7.5 CVE-2013-2617 lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. Curl No fix yet Fix from $1,9502013-03-20 HIGH 7.5 CVE-2013-1875 command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename. Command Wrap No fix yet Fix from $1,9502013-03-20