Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Fta CRITICAL 9.8
CVE-2021-27730

Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_4…

Fix: after 9_12_432
Fix from $2,300 2021-03-02
Agcombo Vd625 Firmware CRITICAL 9.8
CVE-2021-27132EPSS 16%

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition head…

Mitigation only
Fix from $2,300 2021-02-27
Fedora CRITICAL 9.8
CVE-2021-3197EPSS 72%

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Jira Server For Slack HIGH 8.8
CVE-2021-26068

An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via …

Fix: 2.0.15+
Fix from $1,950 2021-02-22
Alfresco Enterprise Content Management HIGH 8.8
CVE-2020-12873

An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a w…

Fix: 6.2.1+
Fix from $1,950 2021-02-19
Less Openui5 HIGH 7.8
CVE-2021-21316

less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming reso…

Fix: 0.10.0+
Fix from $1,950 2021-02-16
Mbconnect24 HIGH 7.5
CVE-2020-35564

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malici…

Fix: after 2.6.2
Fix from $1,950 2021-02-16
Citsmart CRITICAL 9.8
CVE-2020-35775EPSS 13%

CITSmart before 9.1.2.23 allows LDAP Injection.

Fix: 9.1.2.23+
Fix from $2,300 2021-02-15
Wrc 1467ghbk A Firmware MEDIUM 6.1
CVE-2021-20644

ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.

Mitigation only
Fix from $1,600 2021-02-12
Is User Valid HIGH 7.5
CVE-2021-23335

All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.

No fix yet
Fix from $1,950 2021-02-11
Scimono CRITICAL 9.1
CVE-2021-21479EPSS 10%

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the sys…

Fix: 0.0.19+
Fix from $2,300 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21137EPSS 6%

Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome MEDIUM 6.5
CVE-2021-21141EPSS 5%

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy v…

Fix: 88.0.705.74 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Carrierwave HIGH 8.8
CVE-2021-21305EPSS 13%

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions…

Fix: 1.3.2 / 2.1.1+
Fix from $1,950 2021-02-08
Helm MEDIUM 6.8
CVE-2021-21303

Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-co…

Fix: 3.5.2+
Fix from $1,600 2021-02-05
Angular Expressions HIGH 8.8
CVE-2021-21277

angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2…

Fix: 1.1.2+
Fix from $1,950 2021-02-01
Nim CRITICAL 9.8
CVE-2020-15690

In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.

Fix: 1.2.6+
Fix from $2,300 2021-01-30
Rsshub CRITICAL 9.8
CVE-2021-21278

RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk …

Fix: 2021-01-25+
Fix from $2,300 2021-01-26
Laravel MEDIUM 5.3
CVE-2021-21263

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit…

Fix: 6.20.11 / 7.30.2+
Fix from $1,600 2021-01-19
Onedev CRITICAL 9.8
CVE-2021-21242EPSS 74%

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code exe…

Fix: 4.0.3+
Fix from $2,300 2021-01-15
Onedev HIGH 8.8
CVE-2021-21247

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAj…

Fix: 4.0.3+
Fix from $1,950 2021-01-15
Onedev HIGH 8.8
CVE-2021-21248

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. I…

Fix: 4.0.3+
Fix from $1,950 2021-01-15
Onedev HIGH 8.8
CVE-2021-21249

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote …

Fix: 4.0.3+
Fix from $1,950 2021-01-15
Onedev CRITICAL 9.8
CVE-2021-21243EPSS 54%

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted da…

Fix: 4.0.3+
Fix from $2,300 2021-01-15
Onedev CRITICAL 9.8
CVE-2021-21244

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injectio…

Fix: 4.0.3+
Fix from $2,300 2021-01-15
Debian Linux HIGH 8.8
CVE-2021-21261

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` ser…

Fix: 1.8.5 / 1.10.0+
Fix from $1,950 2021-01-14
Redcarpet MEDIUM 5.4
CVE-2020-26298

Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-…

Fix: 3.5.1+
Fix from $1,600 2021-01-11
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-5019

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B…

Fix: 10.1.7+
Fix from $1,600 2021-01-08
Vital Signs Monitor Vc150 Firmware MEDIUM 5.3
CVE-2020-27260

Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow phys…

Fix: 1.7.15+
Fix from $1,600 2021-01-08
Pwntools CRITICAL 9.8
CVE-2020-28468

This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template …

Fix: 4.3.1+
Fix from $2,300 2021-01-08