Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Corenlp CRITICAL 9.8
CVE-2021-44550

An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).

No fix yet
Fix from $2,300 2022-02-24
October HIGH 7.2
CVE-2022-21705EPSS 9%

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before render…

Fix: 1.0.474 / 1.1.10+
Fix from $1,950 2022-02-23
Ez Platform Kernel CRITICAL 9.8
CVE-2022-25337

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.

Fix: 1.3.12 / 7.5.26+
Fix from $2,300 2022-02-18
Python HIGH 7.5
CVE-2022-0391EPSS 8%

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into componen…

Fix: 3.6.14 / 3.7.11+
Fix from $1,950 2022-02-09
Xwiki HIGH 8.8
CVE-2022-23616

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an un…

Fix: after 13.1
Fix from $1,950 2022-02-09
Diskstation Manager MEDIUM 5.4
CVE-2021-43929

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology …

Fix: 6.2.4-25556-3 / 7.0.1-42218-2+
Fix from $1,600 2022-02-07
Twig CRITICAL 9.8
CVE-2022-23614EPSS 8%

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attac…

Fix: 2.14.11 / 3.3.8+
Fix from $2,300 2022-02-04
Ryzen Pro 5650g Firmware HIGH 7.5
CVE-2020-12965

When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits p…

Mitigation only
Fix from $1,950 2022-02-04
Integrated Dell Remote Access Controller 9 Firmware HIGH 8.1
CVE-2021-36348

iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potential…

Fix: 5.00.20.00+
Fix from $1,950 2022-01-25
Websphere Application Server HIGH 8.8
CVE-2021-39031

IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By usi…

Fix: after 22.0.0.1
Fix from $1,950 2022-01-25
Owncloud Desktop Client HIGH 7.8
CVE-2021-44537

ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.

Fix: 2.9.2+
Fix from $1,950 2022-01-15
Unifi Network Controller CRITICAL 9.8
CVE-2021-44530

An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious…

Fix: after 6.5.53
Fix from $2,300 2022-01-14
October HIGH 8.8
CVE-2021-32649

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…

Fix: 1.0.473 / 1.1.6+
Fix from $1,950 2022-01-14
October HIGH 8.8
CVE-2021-32650

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…

Patch available
Fix from $1,950 2022-01-14
Caldera HIGH 8.8
CVE-2021-42561EPSS 20%

An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. Th…

Fix: after 2.8.1
Fix from $1,950 2022-01-12
Debian Linux HIGH 8.8
CVE-2021-29454

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.…

Fix: 3.1.42 / 4.0.2+
Fix from $1,950 2022-01-10
The Plus Addons For Elementor HIGH 7.5
CVE-2021-24948

The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action…

Fix: 5.0.7+
Fix from $1,950 2022-01-10
WordPress HIGH 7.2
CVE-2022-21663

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Adm…

Fix: 5.8.3+
Fix from $1,950 2022-01-06
Oroplatform HIGH 8.8
CVE-2021-43852

OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties …

Fix: 4.1.14 / 4.2.8+
Fix from $1,950 2022-01-04
Userfrosting HIGH 8.8
CVE-2021-25994

In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauth…

Fix: 4.6.3+
Fix from $1,950 2022-01-03
Safari Montage MEDIUM 6.1
CVE-2021-45818

SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.

No fix yet
Fix from $1,600 2021-12-30
Log4j MEDIUM 6.6
CVE-2021-44832EPSS 98%

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) at…

Fix: 2.3.2 / 2.12.4+
Fix from $1,600 2021-12-28
R6400 Firmware MEDIUM 6.8
CVE-2021-45655

NETGEAR R6400 devices before 1.0.1.70 are affected by server-side injection.

Fix: 1.0.1.70+
Fix from $1,600 2021-12-26
D6200 Firmware HIGH 7.8
CVE-2021-45656

Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R60…

Fix: 1.0.0.48 / 1.0.0.66+
Fix from $1,950 2021-12-26
D6200 Firmware HIGH 7.8
CVE-2021-45657

Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R60…

Fix: 1.0.0.48 / 1.0.0.66+
Fix from $1,950 2021-12-26
D7800 Firmware CRITICAL 9.8
CVE-2021-45658

Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6…

Fix: 1.0.0.66 / 1.0.0.110+
Fix from $2,300 2021-12-26
Rbk40 Firmware HIGH 7.8
CVE-2021-45659

Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK2…

Fix: 2.5.1.16+
Fix from $1,950 2021-12-26
Rbk40 Firmware HIGH 7.8
CVE-2021-45660

Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK2…

Fix: 2.5.1.16+
Fix from $1,950 2021-12-26
Rbk40 Firmware HIGH 7.8
CVE-2021-45661

Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK2…

Fix: 2.5.1.16+
Fix from $1,950 2021-12-26
Engineers Online Portal HIGH 8.8
CVE-2021-43437

In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the a…

Mitigation only
Fix from $1,950 2021-12-20