Vulnerability index

Browse CVEs

480 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2015-8565 Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknow… Joomla\! Mitigation only Fix from $1,9502015-12-16 HIGH 7.5 CVE-2015-8564 Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences … Joomla\! Mitigation only Fix from $1,9502015-12-16 MEDIUM 6.8 CVE-2015-8563 Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote at… Joomla\! Mitigation only Fix from $1,6002015-12-16 HIGH 7.5 CVE-2015-8562EPSS 98% Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP U… Joomla\! No fix yet Fix from $1,9502015-12-16 MEDIUM 5.0 CVE-2015-7859 The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive informat… Joomla\! Mitigation only Fix from $1,6002015-10-29 MEDIUM 5.0 CVE-2015-7899 The com_content component in Joomla! 3.x before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via… Joomla\! Mitigation only Fix from $1,6002015-10-29 HIGH 7.5 CVE-2015-7858EPSS 86% SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a differen… Joomla\! No fix yet Fix from $1,9502015-10-29 HIGH 7.5 CVE-2015-7857EPSS 94% SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.… Joomla\! No fix yet Fix from $1,9502015-10-29 HIGH 7.5 CVE-2015-7297EPSS 100% SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a differen… Joomla\! No fix yet Fix from $1,9502015-10-29 MEDIUM 6.8 CVE-2015-5397 Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentic… Joomla\! Mitigation only Fix from $1,6002015-07-14 HIGH 7.5 CVE-2015-4654 SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id param… Joomla\! No fix yet Fix from $1,9502015-06-18 HIGH 7.5 CVE-2014-7228EPSS 55% Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professi… Joomla\! No fix yet Fix from $1,9502014-11-03 HIGH 7.5 CVE-2014-7981EPSS 9% SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL commands via unspecified vec… Joomla\! Mitigation only Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-7984 Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving G… Joomla\! Mitigation only Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-6632 Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions… Joomla\! Mitigation only Fix from $1,9502014-10-08 MEDIUM 5.0 CVE-2014-7229 Unspecified vulnerability in Joomla! before 2.5.4 before 2.5.26, 3.x before 3.2.6, and 3.3.x before 3.3.5 allows attackers to cause a denial of servi… Joomla\! No fix yet Fix from $1,6002014-10-08 MEDIUM 6.8 CVE-2013-5576EPSS 48% administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authentic… Joomla\! Patch available Fix from $1,6002013-10-09 MEDIUM 5.5 CVE-2013-3242 plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializi… Joomla\! No fix yet Fix from $1,6002013-05-03 HIGH 7.5 CVE-2013-1453 plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects t… Joomla\! No fix yet Fix from $1,9502013-02-13 MEDIUM 5.0 CVE-2013-1454 Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to "Coding errors." Joomla\! No fix yet Fix from $1,6002013-02-13 MEDIUM 5.0 CVE-2013-1455 Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to an "Undefined variable." Joomla\! Mitigation only Fix from $1,6002013-02-13 HIGH 7.5 CVE-2012-1598 Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability." Joomla\! Mitigation only Fix from $1,9502012-12-03 MEDIUM 5.0 CVE-2012-1599 Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via… Joomla\! Mitigation only Fix from $1,6002012-12-03 MEDIUM 5.0 CVE-2011-4911 Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecif… Joomla\! after 1.5.11 Fix from $1,6002012-10-07 HIGH 7.5 CVE-2012-1116 SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Joomla\! Mitigation only Fix from $1,9502012-09-26 MEDIUM 5.0 CVE-2012-1611 Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via … Joomla\! Mitigation only Fix from $1,6002012-09-06 MEDIUM 5.0 CVE-2012-0819 Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a diff… Joomla\! Patch available Fix from $1,6002012-09-06 MEDIUM 5.0 CVE-2012-0821 Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a diff… Joomla\! Patch available Fix from $1,6002012-09-06 MEDIUM 5.0 CVE-2012-0835 Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain sensitive information via unknown vectors r… Joomla\! Patch available Fix from $1,6002012-09-06 MEDIUM 5.0 CVE-2012-0836 Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 allows attackers to read the error log via unknown vectors. Joomla\! Patch available Fix from $1,6002012-09-06