Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Mattermost Server CRITICAL 9.8
CVE-2017-18900

An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.

Fix: 3.10.3 / 4.0.4+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 7.5
CVE-2018-21258

An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.

Fix: 5.1.0+
Fix from $1,950 2020-06-19
Liferay Portal HIGH 8.8
CVE-2020-13445

In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not r…

Patch available
Fix from $1,950 2020-06-10
Thinfinity Virtualui MEDIUM 6.1
CVE-2019-16385

Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an exa…

Fix: after 2.5.17.2
Fix from $1,600 2020-06-04
Fedora MEDIUM 6.8
CVE-2020-11078

In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body,…

Fix: 0.18.0+
Fix from $1,600 2020-05-20
Movable Type MEDIUM 5.3
CVE-2020-5574

HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advance…

Fix: after 7.2.1
Fix from $1,600 2020-05-14
Glpi HIGH 8.8
CVE-2020-11060EPSS 11%

In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited…

Fix: 9.4.6+
Fix from $1,950 2020-05-12
Businessobjects Business Intelligence Platform MEDIUM 6.7
CVE-2020-6245

SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can b…

Mitigation only
Fix from $1,600 2020-05-12
Seomatic HIGH 7.5
CVE-2020-12790

In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template In…

Fix: 3.2.49+
Fix from $1,950 2020-05-11
Sprout Forms MEDIUM 6.3
CVE-2020-11056

In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which…

Fix: 3.9.0+
Fix from $1,600 2020-05-07
Debian Linux MEDIUM 6.5
CVE-2020-12108

/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.

Fix: 2.1.31+
Fix from $1,600 2020-05-06
Archer MEDIUM 6.1
CVE-2020-5336

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vul…

Fix: 6.7.0.1+
Fix from $1,600 2020-05-04
Endpoint Protector HIGH 7.5
CVE-2019-13285

CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

No fix yet
Fix from $1,950 2020-05-04
Syncope CRITICAL 9.8
CVE-2020-1961

Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e…

Fix: 2.0.15 / 2.1.6+
Fix from $2,300 2020-05-04
Ofbiz HIGH 7.5
CVE-2019-12425

Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

Mitigation only
Fix from $1,950 2020-04-30
Fs752tp Firmware HIGH 7.7
CVE-2017-18860

Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110T…

Fix: after 6.6.2.6
Fix from $1,950 2020-04-29
Wnr854t Firmware HIGH 8.8
CVE-2017-18855

NETGEAR WNR854T devices before 1.5.2 are affected by command execution.

Fix: 1.5.2+
Fix from $1,950 2020-04-29
Readynas Os Firmware MEDIUM 6.7
CVE-2017-18856

NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection.

Fix: 6.6.1+
Fix from $1,600 2020-04-29
Readynas Os Firmware MEDIUM 6.7
CVE-2017-18854

NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection.

Fix: after 6.6.1
Fix from $1,600 2020-04-29
D6100 Firmware HIGH 8.8
CVE-2018-21208

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, …

Fix: 1.0.0.50 / 1.0.0.57+
Fix from $1,950 2020-04-28
Wn604 Firmware HIGH 7.1
CVE-2017-18863

Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP3…

Fix: 2.0.11 / 3.3.3+
Fix from $1,950 2020-04-28
D7800 Firmware MEDIUM 6.8
CVE-2018-21227

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R6400v2 before 1.0.2.34, R670…

Fix: 1.0.0.62 / 1.0.1.30+
Fix from $1,600 2020-04-24
D7800 Firmware MEDIUM 6.8
CVE-2018-21228

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, EX6100v2 before 1.0.1.50, EX6…

Fix: 1.0.0.110 / 1.0.1.16+
Fix from $1,600 2020-04-24
Jr6150 Firmware HIGH 8.8
CVE-2017-18735

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, PR2000 before 1.0.0.18…

Fix: 1.0.0.18 / 1.0.1.10+
Fix from $1,950 2020-04-23
Jr6150 Firmware HIGH 8.8
CVE-2017-18736

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10,…

Fix: 1.0.1.10 / 1.1.0.48+
Fix from $1,950 2020-04-23
Jnr1010 Firmware HIGH 8.8
CVE-2017-18737

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1…

Fix: 1.0.0.18 / 1.0.1.10+
Fix from $1,950 2020-04-23
Jnr1010 Firmware HIGH 8.8
CVE-2017-18734

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1…

Fix: 1.0.0.18 / 1.0.1.10+
Fix from $1,950 2020-04-23
Ecostruxure Machine Expert CRITICAL 9.8
CVE-2020-7489

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Mach…

Patch available
Fix from $2,300 2020-04-22
Wndr3700 Firmware MEDIUM 6.8
CVE-2017-18754

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.…

Fix: 1.0.0.58 / 1.0.2.88+
Fix from $1,600 2020-04-22
Wc7500 Firmware HIGH 8.8
CVE-2018-21123

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, …

Fix: 6.5.3.9+
Fix from $1,950 2020-04-22