Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Powervm Hypervisor MEDIUM 6.0
CVE-2021-29795

IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of hypervisor calls from a part…

Patch available
Fix from $1,600 2021-09-21
Boostnote CRITICAL 9.8
CVE-2021-41392

static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed …

Fix: after 0.22.0
Fix from $2,300 2021-09-17
Enterprise Content Management HIGH 8.0
CVE-2021-41390

In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.

No fix yet
Fix from $1,950 2021-09-17
Gc108p Firmware HIGH 8.8
CVE-2021-41314EPSS 14%

Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentica…

Fix: 1.0.3.2 / 1.0.5.3+
Fix from $1,950 2021-09-16
Glpi HIGH 8.8
CVE-2021-39213

GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable…

Fix: 9.5.6+
Fix from $1,950 2021-09-15
Mac Os X HIGH 7.8
CVE-2021-30777

An injection issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Upd…

Fix: 11.5+
Fix from $1,950 2021-09-08
Nexus Repository Manager 3 HIGH 8.2
CVE-2021-40143

Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may d…

Fix: 3.34.0+
Fix from $1,950 2021-09-07
Parse Server HIGH 7.5
CVE-2021-39187

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes…

Fix: 4.10.3+
Fix from $1,950 2021-09-02
Hedgedoc MEDIUM 6.1
CVE-2021-39175

HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the …

Fix: 1.9.0+
Fix from $1,600 2021-08-30
Dotcms HIGH 8.8
CVE-2020-18875

Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocit…

Fix: 5.1.0+
Fix from $1,950 2021-08-18
Mockserver CRITICAL 9.6
CVE-2021-32827

MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim…

Patch available
Fix from $2,300 2021-08-16
Maximo Asset Management CRITICAL 9.8
CVE-2021-20509

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys…

Fix: 7.6.1.2+
Fix from $2,300 2021-08-12
Exim HIGH 7.5
CVE-2021-38371

The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.

Fix: after 4.94.2
Fix from $1,950 2021-08-10
Rconfig HIGH 7.5
CVE-2020-23148

The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive inform…

No fix yet
Fix from $1,950 2021-08-09
Fuel Cms HIGH 8.1
CVE-2021-38290

A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset…

Fix: after 1.5.0
Fix from $1,950 2021-08-09
Hub MEDIUM 6.1
CVE-2021-37541

In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

Fix: 2021.1.13402+
Fix from $1,600 2021-08-06
Libelfin MEDIUM 5.5
CVE-2020-24821

A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation …

No fix yet
Fix from $1,600 2021-08-04
Libelfin MEDIUM 5.5
CVE-2020-24822

A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault…

No fix yet
Fix from $1,600 2021-08-04
Libelfin MEDIUM 5.5
CVE-2020-24823

A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault vi…

No fix yet
Fix from $1,600 2021-08-04
Libelfin MEDIUM 5.5
CVE-2020-24825

A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fa…

No fix yet
Fix from $1,600 2021-08-04
Libelfin MEDIUM 5.5
CVE-2020-24826

A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation f…

No fix yet
Fix from $1,600 2021-08-04
Courier Mail Server HIGH 8.1
CVE-2021-38084

An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the PO…

Fix: 1.1.5+
Fix from $1,950 2021-08-03
Admin Console HIGH 7.2
CVE-2021-35450

A Server Side Template Injection in the Entando Admin Console 6.3.9 and before allows a user with privileges to execute FreeMarker template with comm…

Fix: after 6.3.9
Fix from $1,950 2021-08-02
Go HIGH 7.3
CVE-2021-33195

Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may c…

Fix: 1.15.13 / 1.16.5+
Fix from $1,950 2021-08-02
Debian Linux HIGH 7.5
CVE-2021-32558EPSS 9%

An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Aster…

Fix: 13.38.3 / 16.19.1+
Fix from $1,950 2021-07-30
Jumpserver CRITICAL 9.8
CVE-2021-3169

An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have acce…

Fix: 2.4.5 / 2.5.4+
Fix from $2,300 2021-07-23
Manageiq HIGH 8.8
CVE-2021-32756

ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module o…

Mitigation only
Fix from $1,950 2021-07-21
Emc Openmanage Enterprise HIGH 8.1
CVE-2020-5323

Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection v…

Fix: 1.10.00 / 3.2+
Fix from $1,950 2021-07-19
Android HIGH 8.0
CVE-2021-0594

In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote …

Mitigation only
Fix from $1,950 2021-07-14
Transaction Management MEDIUM 5.3
CVE-2021-36381

In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_err…

Fix: after 2021-07-12
Fix from $1,600 2021-07-12