Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Warnsystem MEDIUM 6.5
CVE-2021-29502

WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to access sensible informations…

Fix: 1.3.18+
Fix from $1,600 2021-05-10
Dav Cogs MEDIUM 6.5
CVE-2021-29501

Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users to expose sensitive informatio…

Fix: 1.0.1+
Fix from $1,600 2021-05-10
Serv U HIGH 7.5
CVE-2021-3154

An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: thi…

Fix: 15.2.2+
Fix from $1,950 2021-05-04
Unomi HIGH 7.5
CVE-2021-31164

Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

Fix: 1.5.5+
Fix from $1,950 2021-05-04
P30 Firmware HIGH 7.5
CVE-2021-22331

There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit…

Fix: 10.1.0.165 / 11.0.0.118+
Fix from $1,950 2021-04-28
Debian Linux MEDIUM 5.9
CVE-2019-25031

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HT…

Fix: 1.9.5+
Fix from $1,600 2021-04-27
Junos CRITICAL 9.3
CVE-2021-0268

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buff…

Mitigation only
Fix from $2,300 2021-04-22
Administrator HIGH 8.0
CVE-2021-28829

The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO A…

Fix: after 5.10.2
Fix from $1,950 2021-04-20
Dio HIGH 7.5
CVE-2021-31402

The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.

Fix: 5.0.0+
Fix from $1,950 2021-04-15
Mdaemon HIGH 8.8
CVE-2021-27182

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an…

Fix: 20.0.4+
Fix from $1,950 2021-04-14
Desktop HIGH 8.8
CVE-2021-22879

Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to exec…

Fix: 3.1.3+
Fix from $1,950 2021-04-14
Debian Linux MEDIUM 5.3
CVE-2020-36308

Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading ti…

Fix: 4.0.7 / 4.1.1+
Fix from $1,600 2021-04-06
Stripe HIGH 7.8
CVE-2021-21420

vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted so…

Fix: 1.7.3+
Fix from $1,950 2021-04-01
Nim HIGH 8.8
CVE-2021-21372

Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in differ…

Fix: 1.2.10 / 1.4.4+
Fix from $1,950 2021-03-26
FreeBSD MEDIUM 5.3
CVE-2020-7464

In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and 11.3-RELEASE before p14, a pr…

Mitigation only
Fix from $1,600 2021-03-26
Fedora MEDIUM 6.1
CVE-2021-21333

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.27.0+
Fix from $1,600 2021-03-26
Passhport MEDIUM 6.5
CVE-2021-3027

app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of specia…

Fix: after 2.5
Fix from $1,600 2021-03-26
Openam HIGH 7.5
CVE-2021-29156EPSS 76%

ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-ch…

Fix: 13.5.1+
Fix from $1,950 2021-03-25
Ios Xe HIGH 7.3
CVE-2021-1432

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlyi…

Mitigation only
Fix from $1,950 2021-03-24
Debian Linux MEDIUM 5.3
CVE-2021-28963

Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.

Fix: 3.2.1+
Fix from $1,600 2021-03-22
Data Center MEDIUM 5.3
CVE-2021-26069

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project k…

Fix: 8.5.11 / 8.13.3+
Fix from $1,600 2021-03-22
Redash MEDIUM 5.3
CVE-2020-36144

Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template sinc…

Mitigation only
Fix from $1,600 2021-03-18
Contact Form 7 Database Addon HIGH 7.8
CVE-2021-24144

Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers injec…

Fix: 1.2.5.6+
Fix from $1,950 2021-03-18
Spectrum Scale MEDIUM 5.5
CVE-2020-4851

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and develo…

Fix: 5.0.5.5 / 5.1.0.2+
Fix from $1,600 2021-03-16
Wireshark HIGH 8.8
CVE-2021-22191

Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture f…

Fix: after 3.4.3
Fix from $1,950 2021-03-15
Experience Manager HIGH 7.2
CVE-2020-14987

An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because th…

Fix: after 14.2.2
Fix from $1,950 2021-03-11
Debian Linux HIGH 8.2
CVE-2021-21381

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before versi…

Fix: 1.10.2+
Fix from $1,950 2021-03-11
Idrac8 Firmware MEDIUM 6.1
CVE-2021-21510

Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit th…

Fix: 2.75.100.75+
Fix from $1,600 2021-03-08
Glpi MEDIUM 6.1
CVE-2021-21313

GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In G…

Fix: 9.5.4+
Fix from $1,600 2021-03-03
Pug CRITICAL 9.0
CVE-2021-21353

Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty…

Fix: 2.0.3 / 3.0.1+
Fix from $2,300 2021-03-03