Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 9.3 CVE-2008-4387EPSS 16% Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unk… Sapgui Mitigation only Fix from $1,9502008-11-10 HIGH 7.5 CVE-2008-4911 PHP remote file inclusion vulnerability in read.php in Chattaitaliano Istant-Replay allows remote attackers to execute arbitrary PHP code via a URL i… Istant Replay No fix yet Fix from $1,9502008-11-04 HIGH 7.5 CVE-2008-4810 The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP cod… Smarty Mitigation only Fix from $1,9502008-10-31 HIGH 9.3 CVE-2008-4798 The loadModule function in lib/WebGUI/Asset.pm in WebGUI before 7.5.30 (stable) allows remote attackers to execute arbitrary code by uploading a Perl… Webgui after 7.5.10 Fix from $1,9502008-10-30 HIGH 8.5 CVE-2008-4735 PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute a… Coast No fix yet Fix from $1,9502008-10-24 CRITICAL 9.8 CVE-2008-4250 KEVEPSS 99% The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows rem… Windows 2000 Patch available Fix from $2,3002008-10-23 HIGH 9.3 CVE-2008-4719 PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remo… Openengine No fix yet Fix from $1,9502008-10-23 HIGH 9.3 CVE-2008-4720 Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lan… Gemini Portal No fix yet Fix from $1,9502008-10-23 HIGH 10.0 CVE-2008-4704 PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in … Sezhoo No fix yet Fix from $1,9502008-10-23 HIGH 9.0 CVE-2008-4687EPSS 67% manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences… Mantis after 1.1.3 Fix from $1,9502008-10-22 HIGH 10.0 CVE-2008-4673 PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote atta… Events Calendar No fix yet Fix from $1,9502008-10-22 HIGH 9.0 CVE-2008-4645EPSS 7% plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via P… Phpwebgallery after 1.7.2 Fix from $1,9502008-10-22 HIGH 9.3 CVE-2008-4624 PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execut… Fast Click Sql Lite No fix yet Fix from $1,9502008-10-21 HIGH 10.0 CVE-2008-4557EPSS 45% plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the te… Cutenews No fix yet Fix from $1,9502008-10-14 HIGH 9.3 CVE-2008-4385EPSS 38% Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary… System Requirements Lab Mitigation only Fix from $1,9502008-10-14 HIGH 7.5 CVE-2008-4529 Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[a… Asicms No fix yet Fix from $1,9502008-10-09 HIGH 10.0 CVE-2008-4502 Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a… Dff Framework Api No fix yet Fix from $1,9502008-10-09 HIGH 7.2 CVE-2008-4451 The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via … System Analyzer Tool No fix yet Fix from $1,9502008-10-06 HIGH 10.0 CVE-2008-4439 PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrar… Datafeed Studio after 1.6.2 Fix from $1,9502008-10-03 HIGH 9.3 CVE-2008-3638 Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary pro… Mac Os X Mitigation only Fix from $1,9502008-09-26 HIGH 7.5 CVE-2008-4206 PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attacke… Dolphin No fix yet Fix from $1,9502008-09-24 HIGH 10.0 CVE-2008-4138EPSS 10% PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute ar… Technote No fix yet Fix from $1,9502008-09-24 HIGH 7.5 CVE-2008-4141 Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code vi… .x10 Automatic Mp3 Script No fix yet Fix from $1,9502008-09-24 HIGH 10.0 CVE-2008-4188 Unspecified vulnerability in the TYPO3 Secure Directory (kw_secdir) extension before 1.0.2 allows remote attackers to execute arbitrary code via unkn… Secure Directory after 1.0.1 Fix from $1,9502008-09-23 HIGH 7.2 CVE-2008-3949 emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which… Suse Linux Mitigation only Fix from $1,9502008-09-22 HIGH 7.5 CVE-2008-4134EPSS 8% PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows rem… Phprealty after 0.03 Fix from $1,9502008-09-19 HIGH 9.3 CVE-2008-1093 Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect … Flexnet Connect Mitigation only Fix from $1,9502008-09-18 HIGH 7.5 CVE-2008-4047 Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL cod… Novell Forum Patch available Fix from $1,9502008-09-11 HIGH 9.3 CVE-2008-3956EPSS 13% orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute… Organization Chart No fix yet Fix from $1,9502008-09-11 HIGH 9.3 CVE-2008-2253EPSS 30% Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that i… Windows Media Player Mitigation only Fix from $1,9502008-09-11