Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Swfupload CRITICAL 9.8
CVE-2013-4144

There is an object injection vulnerability in swfupload plugin for wordpress.

No fix yet
Fix from $2,300 2022-06-30
Mermaid MEDIUM 6.1
CVE-2022-31108

Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex …

Fix: 9.1.3+
Fix from $1,600 2022-06-28
Debian Linux HIGH 8.8
CVE-2022-31086

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Debian Linux HIGH 7.8
CVE-2022-31087

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Debian Linux MEDIUM 5.3
CVE-2022-31088

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,600 2022-06-27
Flume CRITICAL 9.8
CVE-2022-25167

Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…

Fix: 1.10.0+
Fix from $2,300 2022-06-14
Sevone Network Performance Management HIGH 8.8
CVE-2020-36531

A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device M…

Fix: after 5.7.2.22
Fix from $1,950 2022-06-07
Jodd Http HIGH 7.5
CVE-2022-29631

Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRe…

Fix: 6.2.1+
Fix from $1,950 2022-06-06
Form.io CRITICAL 9.8
CVE-2020-28246

A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email tem…

Mitigation only
Fix from $2,300 2022-06-02
Cyber Protect MEDIUM 6.1
CVE-2022-30991

HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

Fix: 15+
Fix from $1,600 2022-05-18
Tooljet MEDIUM 5.4
CVE-2022-23068

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name f…

Fix: after 1.10.2
Fix from $1,600 2022-05-18
Pinniped MEDIUM 6.6
CVE-2022-22975

An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would inv…

Fix: 0.17.0+
Fix from $1,600 2022-05-11
Sourcegraph HIGH 7.2
CVE-2022-29171

Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserv…

Fix: 3.38.0+
Fix from $1,950 2022-05-06
Matrix Irc Bridge HIGH 8.8
CVE-2022-29166

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing…

Fix: 0.33.2+
Fix from $1,950 2022-05-05
Snipe It HIGH 8.8
CVE-2022-23064

In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password …

Fix: after 5.3.7
Fix from $1,950 2022-05-02
Zimbra Collaboration Suite HIGH 7.5
CVE-2022-27924 KEVEPSS 85%

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. Thes…

Mitigation only
Fix from $1,950 2022-04-21
Ios Xe HIGH 7.2
CVE-2022-20693

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a…

Mitigation only
Fix from $1,950 2022-04-15
Signal HIGH 7.5
CVE-2022-28345

The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking spa…

Fix: 5.34+
Fix from $1,950 2022-04-15
Gocd MEDIUM 6.8
CVE-2022-24832

GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly esc…

Fix: 22.1.0+
Fix from $1,600 2022-04-11
Calendar CRITICAL 9.8
CVE-2022-24838EPSS 33%

Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and …

Fix: 3.2.2+
Fix from $2,300 2022-04-11
Photon Os MEDIUM 5.3
CVE-2021-22055

The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious …

Fix: 2022-02-16+
Fix from $1,600 2022-04-11
School Club Application System CRITICAL 9.8
CVE-2022-1287

A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classe…

Mitigation only
Fix from $2,300 2022-04-09
Flex 1085 Firmware MEDIUM 5.4
CVE-2022-1074

A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection</h1> in the WiFi settings of …

Mitigation only
Fix from $1,600 2022-03-29
Goo Blog CRITICAL 9.8
CVE-2022-25420

NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary …

No fix yet
Fix from $2,300 2022-03-29
Marky CRITICAL 9.8
CVE-2022-26205

Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability …

Mitigation only
Fix from $2,300 2022-03-27
Fedora HIGH 7.8
CVE-2022-20001

fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-re…

Fix: after 3.3.1
Fix from $1,950 2022-03-14
Spectrum Copy Data Management MEDIUM 6.1
CVE-2022-22344

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST…

Fix: 2.2.15.0+
Fix from $1,600 2022-03-14
Parse Server CRITICAL 10.0
CVE-2022-24760EPSS 49%

Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Ser…

Fix: 4.10.7+
Fix from $2,300 2022-03-12
Pfsense HIGH 8.8
CVE-2021-41282EPSS 87%

diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the fire…

No fix yet
Fix from $1,950 2022-03-01
Integrated Lights Out MEDIUM 5.3
CVE-2022-23701

A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior…

Fix: 2.60+
Fix from $1,600 2022-02-24