Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Sopas Engineering Tool HIGH 7.5
CVE-2021-32499

SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable.

Fix: 4.8.0+
Fix from $1,950 2021-12-17
Atomix HIGH 8.1
CVE-2020-35213

An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.

No fix yet
Fix from $1,950 2021-12-16
Jfinal Cms HIGH 7.5
CVE-2021-37262

JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.

Patch available
Fix from $1,950 2021-12-16
Vault Cli CRITICAL 9.1
CVE-2021-43837EPSS 5%

vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli fea…

Fix: 3.0.0+
Fix from $2,300 2021-12-16
Tuleap HIGH 7.2
CVE-2021-41276

Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanit…

Fix: 13.1-5 / 13.2-3+
Fix from $1,950 2021-12-15
Tuleap HIGH 7.2
CVE-2021-43782

Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a follow up to GHSA-887w-pv2r-x8pm…

Fix: 13.1-6 / 13.2-4+
Fix from $1,950 2021-12-15
Fedora HIGH 7.1
CVE-2021-43818

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted scri…

Fix: 4.6.5+
Fix from $1,950 2021-12-13
Unitrends Backup HIGH 8.8
CVE-2021-43038

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL tr…

Fix: 10.5.5+
Fix from $1,950 2021-12-06
Planning Analytics HIGH 7.8
CVE-2021-38873

IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by im…

Patch available
Fix from $1,950 2021-11-24
Cloudlink HIGH 7.2
CVE-2021-36313

Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially explo…

Fix: 7.1.1+
Fix from $1,950 2021-11-23
Emui HIGH 7.5
CVE-2021-37033

There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

No fix yet
Fix from $1,950 2021-11-23
X1008p Firmware MEDIUM 6.1
CVE-2021-36322

Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may pote…

Fix: 3.0.1.8+
Fix from $1,600 2021-11-20
Zoom Client For Meetings MEDIUM 5.3
CVE-2021-34419

In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a use…

Fix: 5.1.0+
Fix from $1,600 2021-11-11
Traffic Control CRITICAL 9.8
CVE-2021-43350

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP…

Fix: 5.1.4 / 6.0.1+
Fix from $2,300 2021-11-11
Talkyard HIGH 8.8
CVE-2021-25980

In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-r…

Fix: after 0.2021.02-wip-879ef3fe1
Fix from $1,950 2021-11-11
Youtrack CRITICAL 9.8
CVE-2021-43185

JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

Fix: 2021.3.23639+
Fix from $2,300 2021-11-09
Neoan3 Template CRITICAL 9.8
CVE-2021-41170

neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template eng…

Fix: 1.1.1+
Fix from $2,300 2021-11-08
Pandora Fms MEDIUM 6.7
CVE-2021-36697

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file cont…

Fix: after 755
Fix from $1,600 2021-11-03
Planning Poker CRITICAL 9.8
CVE-2021-41232

Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerab…

Fix: 1.16.3+
Fix from $2,300 2021-11-02
Storm CRITICAL 9.8
CVE-2021-38294EPSS 84%

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Tao Assessment Platform HIGH 8.0
CVE-2020-23050

TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user a…

No fix yet
Fix from $1,950 2021-10-22
Discourse CRITICAL 9.8
CVE-2021-41163EPSS 20%

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.…

Fix: 2.7.9+
Fix from $2,300 2021-10-20
Huntflow Enterprise HIGH 7.5
CVE-2021-37933

An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logi…

Fix: 3.10.6+
Fix from $1,950 2021-10-14
Remote Service Manager MEDIUM 5.3
CVE-2021-20802

HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.

Mitigation only
Fix from $1,600 2021-10-13
Mxview CRITICAL 9.8
CVE-2021-38458

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite crit…

Fix: after 3.2.2
Fix from $2,300 2021-10-12
Hygeia HIGH 8.8
CVE-2021-41128

Hygeia is an application for collecting and processing personal and case data in connection with communicable diseases. In affected versions all CSV …

Fix: 1.30.4+
Fix from $1,950 2021-10-06
Axis Os HIGH 8.8
CVE-2021-31988

A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed…

Fix: 6.50.5.5 / 8.40.4.3+
Fix from $1,950 2021-10-05
Filerun HIGH 7.2
CVE-2021-35504

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.

Fix: after 2021.03.26
Fix from $1,950 2021-10-05
Filerun HIGH 7.2
CVE-2021-35505

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.

Fix: after 2021.03.26
Fix from $1,950 2021-10-05
Aviatorscript CRITICAL 9.8
CVE-2021-41862

AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).

No fix yet
Fix from $2,300 2021-10-02