Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.8 CVE-2008-7073 PHP remote file inclusion vulnerability in lib/action/rss.php in RSS module 0.1 for Pie Web M{a,e}sher, when register_globals is enabled, allows remo… Rss Module No fix yet Fix from $1,6002009-08-25 HIGH 7.5 CVE-2008-7042 PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary P… Fresh Email Script No fix yet Fix from $1,9502009-08-24 HIGH 7.5 CVE-2008-7034 PHP remote file inclusion vulnerability in kernel/smarty/Smarty.class.php in PHPEcho CMS 2.0 rc3 allows remote attackers to execute arbitrary PHP cod… Phpecho Cms No fix yet Fix from $1,9502009-08-24 HIGH 9.3 CVE-2009-2627 Insecure method vulnerability in the Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitra… Lunchapp.aplunch Mitigation only Fix from $1,9502009-08-19 HIGH 7.5 CVE-2008-7005EPSS 9% include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the quotes_to_edi… Minb Is Not A Blog No fix yet Fix from $1,9502009-08-19 HIGH 7.5 CVE-2008-6983EPSS 6% modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file spe… Devalcms No fix yet Fix from $1,9502009-08-19 HIGH 7.5 CVE-2008-7000 PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan par… Phpauction No fix yet Fix from $1,9502009-08-19 HIGH 7.5 CVE-2009-2791 PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code … Projectbutler No fix yet Fix from $1,9502009-08-17 MEDIUM 6.8 CVE-2009-2769 PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attacker… Timesheet No fix yet Fix from $1,6002009-08-14 HIGH 7.5 CVE-2009-2773 PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the … Php Paid 4 Mail Script No fix yet Fix from $1,9502009-08-14 HIGH 9.3 CVE-2009-1545EPSS 29% Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003… Windows 2003 Server Patch available Fix from $1,9502009-08-12 MEDIUM 6.5 CVE-2008-6958EPSS 6% wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter. Crossday Discuz\! Board No fix yet Fix from $1,6002009-08-12 MEDIUM 6.5 CVE-2008-6956 Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code in… Mxcamarchive No fix yet Fix from $1,6002009-08-12 HIGH 7.5 CVE-2008-6934 Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remo… Free Simple Guestbook Php Script No fix yet Fix from $1,9502009-08-11 HIGH 10.0 CVE-2008-6935EPSS 5% Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and ca… Exodus No fix yet Fix from $1,9502009-08-11 HIGH 9.3 CVE-2008-6936 Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and ca… Exodus No fix yet Fix from $1,9502009-08-11 HIGH 10.0 CVE-2008-6937 Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and ca… Exodus Mitigation only Fix from $1,9502009-08-11 MEDIUM 6.5 CVE-2009-2736 Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code i… Opennews No fix yet Fix from $1,6002009-08-11 MEDIUM 6.5 CVE-2009-0668 Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows… Zodb after 3.8.1 Fix from $1,6002009-08-07 MEDIUM 6.5 CVE-2008-6900 Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users… Availscript Article Script No fix yet Fix from $1,6002009-08-06 MEDIUM 6.8 CVE-2008-6902 Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers to execute arbitrary code by… 2532gigs No fix yet Fix from $1,6002009-08-06 HIGH 10.0 CVE-2009-2665 The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are ena… Firefox Patch available Fix from $1,9502009-08-04 HIGH 8.8 CVE-2009-2493EPSS 38% The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and… Visual C\+\+ Patch available Fix from $1,9502009-07-29 HIGH 8.8 CVE-2009-0901EPSS 37% The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Go… Visual C\+\+ Patch available Fix from $1,9502009-07-29 HIGH 7.5 CVE-2009-2633 PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote a… Com Vehiclemanager No fix yet Fix from $1,9502009-07-28 HIGH 7.5 CVE-2009-2634 PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote at… Com Medialibrary No fix yet Fix from $1,9502009-07-28 HIGH 7.5 CVE-2009-2635 PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows re… Com Realestatemanager No fix yet Fix from $1,9502009-07-28 HIGH 7.5 CVE-2009-2637 PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote att… Com Booklibrary No fix yet Fix from $1,9502009-07-28 MEDIUM 6.8 CVE-2009-2641 PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary P… School Data Nav No fix yet Fix from $1,6002009-07-28 MEDIUM 6.9 CVE-2009-2348 Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_R… Android Mitigation only Fix from $1,6002009-07-17