Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Htmlsanitizer MEDIUM 6.1
CVE-2020-26293

HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before versi…

Fix: 5.0.372+
Fix from $1,600 2021-01-04
Ak45x Firmware CRITICAL 9.9
CVE-2020-10208

Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B …

No fix yet
Fix from $2,300 2020-12-30
Client HIGH 8.8
CVE-2020-16268

The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair o…

Mitigation only
Fix from $1,950 2020-12-29
Browserup Proxy CRITICAL 10.0
CVE-2020-26282

BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Prox…

Fix: 2.1.2+
Fix from $2,300 2020-12-24
Http MEDIUM 6.1
CVE-2020-35669

An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, …

Fix: after 0.12.2
Fix from $1,600 2020-12-24
Azure Sphere HIGH 7.8
CVE-2020-35608

A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted …

No fix yet
Fix from $1,950 2020-12-22
Thingsboard HIGH 8.8
CVE-2020-27687

ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-…

Fix: 3.2+
Fix from $1,950 2020-12-18
Curl HIGH 7.8
CVE-2020-8177

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file wh…

Fix: after 7.70.0
Fix from $1,950 2020-12-14
Fastadmin HIGH 8.8
CVE-2020-25967

The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.

No fix yet
Fix from $1,950 2020-12-10
Bookstack MEDIUM 6.4
CVE-2020-26260

BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit…

Fix: 0.30.5+
Fix from $1,600 2020-12-09
Rt Ac88u Firmware HIGH 7.5
CVE-2020-29655

An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaste…

Fix: 3.1.0.108+
Fix from $1,950 2020-12-09
Automation For Jira MEDIUM 5.4
CVE-2020-14193

Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF…

Fix: 7.1.15+
Fix from $1,600 2020-11-30
Cron Utils HIGH 8.1
CVE-2020-26238

Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.…

Fix: 9.1.3+
Fix from $1,950 2020-11-25
Unomi CRITICAL 9.8
CVE-2020-13942EPSS 68%

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve…

Fix: 1.5.2+
Fix from $2,300 2020-11-24
Iot Field Network Director MEDIUM 6.1
CVE-2020-26081

Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-sit…

Fix: 4.6.1+
Fix from $1,600 2020-11-18
Archer MEDIUM 6.1
CVE-2020-26884

RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vuln…

Fix: after 6.8.0.3
Fix from $1,600 2020-11-18
Teamcity MEDIUM 6.1
CVE-2020-27627

JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.

Fix: 2020.1.2+
Fix from $1,600 2020-11-16
Dependabot HIGH 8.8
CVE-2020-26222

Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java, .NET, Elm and Go. In Depen…

Fix: 0.125.1+
Fix from $1,950 2020-11-13
Debian Linux HIGH 7.0
CVE-2020-15238

Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argume…

Fix: 2.1.4+
Fix from $1,950 2020-10-27
Magento HIGH 7.2
CVE-2020-15244

In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to…

Fix: 20.0.4+
Fix from $1,950 2020-10-21
Osm Static Maps HIGH 7.6
CVE-2020-7749

This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}})…

Patch available
Fix from $1,950 2020-10-20
Time Tracker HIGH 7.3
CVE-2020-15255

In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treat…

Fix: 1.19.23.5325+
Fix from $1,950 2020-10-16
Xwiki HIGH 8.8
CVE-2020-15252

In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet …

Fix: 11.10.6 / 12.5+
Fix from $1,950 2020-10-16
Contao MEDIUM 5.3
CVE-2020-25768

Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end …

Fix: 4.4.52 / 4.9.6+
Fix from $1,600 2020-10-07
Debian Linux CRITICAL 9.8
CVE-2020-15227EPSS 34%

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…

Fix: 2.0.19 / 2.1.13+
Fix from $2,300 2020-10-01
Urllib3 MEDIUM 6.5
CVE-2020-26137

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characte…

Fix: 1.25.9+
Fix from $1,600 2020-09-30
Halo CRITICAL 9.8
CVE-2020-21523

A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the…

No fix yet
Fix from $2,300 2020-09-30
Python HIGH 7.2
CVE-2020-26116EPSS 6%

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker contro…

Fix: 3.5.10 / 3.6.12+
Fix from $1,950 2020-09-27
Fedora MEDIUM 5.5
CVE-2020-25596

An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves va…

Fix: after 4.14.0
Fix from $1,600 2020-09-23
Exchange Server HIGH 8.4
CVE-2020-16875EPSS 47%

<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who s…

Patch available
Fix from $1,950 2020-09-11