Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Xwiki MEDIUM 6.6
CVE-2020-15171

In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servle…

Fix: 11.10.5 / 12.2.1+
Fix from $1,600 2020-09-10
Scratch Login CRITICAL 10.0
CVE-2020-15164

in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repea…

Fix: 1.1+
Fix from $2,300 2020-08-28
Neprofile HIGH 8.8
CVE-2020-12855

A Host header injection vulnerability has been discovered in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can poison this header resul…

No fix yet
Fix from $1,950 2020-08-26
Micollab HIGH 8.1
CVE-2020-13863

The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to …

Fix: 9.1.3+
Fix from $1,950 2020-08-26
Minetime HIGH 8.8
CVE-2020-24364

MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meeting invite.

Fix: after 1.8.5
Fix from $1,950 2020-08-24
Red Discord Bot HIGH 8.5
CVE-2020-15147

Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users wit…

Fix: after 3.3.11
Fix from $1,950 2020-08-21
Red Discord Bot CRITICAL 9.6
CVE-2020-15140

In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically…

Fix: 3.3.11+
Fix from $2,300 2020-08-21
Syliusresourcebundle HIGH 8.8
CVE-2020-15146

In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expres…

Fix: after 1.6.3
Fix from $1,950 2020-08-20
Syliusresourcebundle HIGH 8.8
CVE-2020-15143

In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expre…

Fix: after 1.6.3
Fix from $1,950 2020-08-20
Nim MEDIUM 6.5
CVE-2020-15693

In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls…

Fix: after 1.2.6
Fix from $1,600 2020-08-14
Zalo Desktop HIGH 8.6
CVE-2020-16087

An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Windows machine running the Zalo…

No fix yet
Fix from $1,950 2020-08-13
Vbulletin CRITICAL 9.8
CVE-2020-17496 KEVEPSS 88%

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.…

Fix: after 5.6.2
Fix from $2,300 2020-08-12
Chartkick MEDIUM 6.1
CVE-2020-16254

The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).

Fix: after 3.3.2
Fix from $1,600 2020-08-05
Voice Over Internet Protocol Gateways Firmware HIGH 7.5
CVE-2017-18923

beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.

Fix: 3.0.16+
Fix from $1,950 2020-07-29
Uvicorn MEDIUM 5.3
CVE-2020-7695

Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit th…

Fix: 0.11.7+
Fix from $1,600 2020-07-27
Fedora HIGH 7.4
CVE-2020-15953

LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. Whe…

Fix: after 1.9.4
Fix from $1,950 2020-07-27
Fiber MEDIUM 5.4
CVE-2020-15111

In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore v…

Fix: 1.12.6+
Fix from $1,600 2020-07-20
Debian Linux MEDIUM 5.9
CVE-2020-14928

evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds…

Fix: after 3.36.3
Fix from $1,600 2020-07-17
Iview CRITICAL 9.8
CVE-2020-14505EPSS 7%

Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Su…

Fix: after 5.6
Fix from $2,300 2020-07-15
Traccar MEDIUM 6.5
CVE-2020-5246

Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By …

Fix: 4.9+
Fix from $1,600 2020-07-14
Dir 610 Firmware HIGH 7.5
CVE-2020-9376EPSS 17%

D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only aff…

Patch available
Fix from $1,950 2020-07-09
Camel HIGH 7.5
CVE-2020-11994

Server-Side Template Injection and arbitrary file disclosure on Camel templating components

Fix: after 8.5.0
Fix from $1,950 2020-07-08
Code42 HIGH 7.2
CVE-2020-12736

Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a loca…

Fix: after 7.0.4
Fix from $1,950 2020-07-07
Ceph Storage MEDIUM 6.5
CVE-2020-10753

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS …

Fix: 14.2.21+
Fix from $1,600 2020-06-26
Traceroute CRITICAL 9.8
CVE-2018-21268

The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because th…

Fix: after 1.0.0
Fix from $2,300 2020-06-25
Jira CRITICAL 9.8
CVE-2019-20409

The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote…

Fix: 8.8.0+
Fix from $2,300 2020-06-23
Debian Linux MEDIUM 5.9
CVE-2020-14954

Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS"…

Fix: 1.14.4 / 20200619+
Fix from $1,600 2020-06-21
GitLab MEDIUM 6.1
CVE-2020-13262

Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT req…

Fix: 12.9.8 / 12.10.7+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2016-11068

An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.

Fix: 3.2.0+
Fix from $1,600 2020-06-19
Archiva MEDIUM 5.3
CVE-2020-9495EPSS 8%

Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP…

Fix: 2.2.5+
Fix from $1,600 2020-06-19