Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
GitLab MEDIUM 5.4
CVE-2021-22232

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

Fix: 13.11.6 / 13.12.6+
Fix from $1,600 2021-07-06
Machform MEDIUM 6.1
CVE-2021-20101

Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to recei…

Fix: 16+
Fix from $1,600 2021-06-29
Nodemailer HIGH 8.8
CVE-2021-23400

The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns …

Fix: 6.6.1+
Fix from $1,950 2021-06-29
Security Identity Manager Adapter HIGH 8.8
CVE-2021-20574

IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially cra…

Patch available
Fix from $1,950 2021-06-28
Security Verify MEDIUM 5.4
CVE-2021-29676

IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-cra…

Fix: 10.9.66+
Fix from $1,600 2021-06-25
Firefox MEDIUM 5.3
CVE-2021-29955

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have …

Fix: 78.9 / 87.0+
Fix from $1,600 2021-06-24
Firefox HIGH 8.8
CVE-2021-24002

When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed a…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Diskstation Manager HIGH 7.5
CVE-2021-29084

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report managemen…

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $1,950 2021-06-23
Diskstation Manager HIGH 7.5
CVE-2021-29085

Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component…

Fix: 3.1-23033 / 6.2.3-25426-3+
Fix from $1,950 2021-06-23
Android MEDIUM 6.5
CVE-2021-0551

In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. Th…

Mitigation only
Fix from $1,600 2021-06-22
Android HIGH 7.3
CVE-2021-0553

In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local esc…

Mitigation only
Fix from $1,950 2021-06-22
Android HIGH 7.8
CVE-2021-0567

In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2021-06-22
Growi CRITICAL 9.1
CVE-2021-20736

NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the databa…

Fix: 4.2.20+
Fix from $2,300 2021-06-22
Greenbone Security Assistant CRITICAL 9.8
CVE-2018-25016

Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.

Fix: 5.0.0 / 7.0.3+
Fix from $2,300 2021-06-21
Db2 HIGH 7.5
CVE-2021-29702

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnorma…

Fix: after 11.5.5.0
Fix from $1,950 2021-06-16
Safenet Keysecure MEDIUM 6.5
CVE-2021-28979

SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability usin…

Fix: after 8.12.0
Fix from $1,600 2021-06-16
Apport HIGH 7.8
CVE-2021-25682

It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

Fix: 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
Fix from $1,950 2021-06-11
Infrabox HIGH 7.5
CVE-2021-33668

Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confid…

Fix: 1.2.1+
Fix from $1,950 2021-06-09
Chrome MEDIUM 6.5
CVE-2021-30540

Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafte…

Fix: 91.0.4472.77+
Fix from $1,600 2021-06-07
Bf 430 Firmware MEDIUM 6.5
CVE-2021-31249EPSS 18%

A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validatio…

No fix yet
Fix from $1,600 2021-06-04
Chrome HIGH 8.8
CVE-2021-30506

Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a we…

Fix: 90.0.4430.212+
Fix from $1,950 2021-06-04
Emissary CRITICAL 9.1
CVE-2021-32647

Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication Remote Code Execution (RCE).…

Patch available
Fix from $2,300 2021-06-01
Fedora CRITICAL 9.4
CVE-2021-32642

radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-edu…

Fix: 1.9.0+
Fix from $2,300 2021-05-28
Stm32cubel4 Firmware HIGH 7.0
CVE-2020-27212

STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP lev…

Fix: after 1.16.0
Fix from $1,950 2021-05-21
Stm32cubel4 Firmware MEDIUM 6.1
CVE-2021-29414

STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.

Fix: after 1.17.0
Fix from $1,600 2021-05-21
Matrix React Sdk HIGH 7.8
CVE-2021-32622

Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the loca…

Fix: 3.21.0+
Fix from $1,950 2021-05-17
Ceph MEDIUM 6.5
CVE-2021-3524

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection …

Fix: 14.2.21+
Fix from $1,600 2021-05-17
Knowage MEDIUM 5.4
CVE-2021-30214EPSS 24%

Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.

No fix yet
Fix from $1,600 2021-05-12
OpenBSD MEDIUM 5.3
CVE-2020-26142

An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversa…

Mitigation only
Fix from $1,600 2021-05-11
Business One Hana Chef Cookbook HIGH 7.1
CVE-2021-27614

SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to i…

Mitigation only
Fix from $1,950 2021-05-11