Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 10.0 CVE-2008-6761EPSS 6% Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.i… Flexcustomer0.0.6 No fix yet Fix from $1,9502009-04-28 HIGH 7.5 CVE-2009-1452 Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a UR… Sma Db No fix yet Fix from $1,9502009-04-28 HIGH 7.5 CVE-2009-1463 Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving content as a … Razorcms after 0.3 Fix from $1,9502009-04-28 HIGH 7.5 CVE-2009-1450 PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_c… Sma Db No fix yet Fix from $1,9502009-04-28 HIGH 7.5 CVE-2009-1444 PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in th… Webportal Cms No fix yet Fix from $1,9502009-04-27 HIGH 9.3 CVE-2008-6748 Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI. Megacubo No fix yet Fix from $1,9502009-04-24 MEDIUM 6.8 CVE-2008-6740 PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary PHP code… Homap No fix yet Fix from $1,6002009-04-21 HIGH 7.5 CVE-2009-1285EPSS 11% Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote at… phpMyAdmin Patch available Fix from $1,9502009-04-16 HIGH 9.3 CVE-2009-0084EPSS 32% Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or vi… Directx Mitigation only Fix from $1,9502009-04-15 HIGH 9.3 CVE-2009-0552EPSS 29% Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allow… Ie Mitigation only Fix from $1,9502009-04-15 HIGH 7.5 CVE-2009-1278 Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP cod… Gravity Board X No fix yet Fix from $1,9502009-04-09 MEDIUM 6.9 CVE-2009-1144 Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file… Xpdf after 3.02 Fix from $1,6002009-04-09 MEDIUM 6.8 CVE-2008-6665 change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email paramete… Ananta Cms No fix yet Fix from $1,6002009-04-08 HIGH 7.5 CVE-2008-6677 Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to e… Quickersite No fix yet Fix from $1,9502009-04-08 HIGH 10.0 CVE-2008-6651 Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory… Oxybox No fix yet Fix from $1,9502009-04-07 MEDIUM 6.8 CVE-2008-6635 PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, al… Dagger Patch available Fix from $1,6002009-04-07 MEDIUM 6.8 CVE-2008-6636 PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, al… Dagger No fix yet Fix from $1,6002009-04-07 MEDIUM 6.8 CVE-2008-6612 Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a fi… Minimal Ablog No fix yet Fix from $1,6002009-04-06 HIGH 7.5 CVE-2009-1248 Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the… Acute Control Panel No fix yet Fix from $1,9502009-04-06 MEDIUM 6.0 CVE-2008-6584 html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file containing an executable extensio… Torrentflux No fix yet Fix from $1,6002009-04-03 MEDIUM 5.0 CVE-2008-6591 LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create arbitrary files via the page … Lightneasy No fix yet Fix from $1,6002009-04-03 HIGH 8.8 CVE-2009-0556 KEVEPSS 68% Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arb… Office Powerpoint Patch available Fix from $1,9502009-04-03 MEDIUM 6.5 CVE-2009-1230 Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary … Podcast Generator after 1.1 Fix from $1,6002009-04-02 HIGH 7.5 CVE-2006-7237 PHP remote file inclusion vulnerability in mod/nc_phpmyadmin/core/libraries/Theme_Manager.class.php in Ixprim 2.0 allows remote attackers to execute … Ixprim No fix yet Fix from $1,9502009-03-31 MEDIUM 6.5 CVE-2008-6539 Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject … Destar No fix yet Fix from $1,6002009-03-30 HIGH 7.5 CVE-2008-6543 Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) lo… Quick Classifieds No fix yet Fix from $1,9502009-03-30 HIGH 7.5 CVE-2008-6544 Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a UR… Simple Machines Forum No fix yet Fix from $1,9502009-03-30 HIGH 7.5 CVE-2008-6545 PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrar… Web Server Creator Web Portal No fix yet Fix from $1,9502009-03-30 MEDIUM 6.8 CVE-2008-6531 The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted U… Jira 3.13.2+ Fix from $1,6002009-03-26 CRITICAL 9.8 CVE-2009-1151 KEVEPSS 95% Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitr… Debian Linux 2.11.9.5 / 3.1.3.1+ Fix from $2,3002009-03-26