Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Android CRITICAL 9.8
CVE-2018-21051

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trus…

Mitigation only
Fix from $2,300 2020-04-08
Android CRITICAL 9.8
CVE-2017-18652

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic librari…

Mitigation only
Fix from $2,300 2020-04-07
Cipace HIGH 7.5
CVE-2020-11593

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data …

Fix: 9.1+
Fix from $1,950 2020-04-06
Mediawiki MEDIUM 5.3
CVE-2020-10960

In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user …

Fix: 1.34.1+
Fix from $1,600 2020-04-03
Druid MEDIUM 6.5
CVE-2020-1958

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…

Mitigation only
Fix from $1,600 2020-04-01
Mac Os X MEDIUM 6.1
CVE-2020-3884

An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbi…

Fix: 10.15.4+
Fix from $1,600 2020-04-01
phpMyAdmin MEDIUM 6.1
CVE-2020-11441

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on a…

No fix yet
Fix from $1,600 2020-03-31
Win Pak HIGH 8.8
CVE-2020-6982

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.

Fix: after 4.7.2
Fix from $1,950 2020-03-24
Ecostruxure Control Expert CRITICAL 9.8
CVE-2020-7475

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in…

Fix: 3.10 / 3.20+
Fix from $2,300 2020-03-23
Dvr04b Firmware CRITICAL 9.8
CVE-2013-7487

On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to e…

No fix yet
Fix from $2,300 2020-03-21
Debian Linux MEDIUM 6.1
CVE-2019-18860EPSS 6%

Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.

Fix: 4.9+
Fix from $1,600 2020-03-20
Deltaspike MEDIUM 6.1
CVE-2019-12416

we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrat…

Fix: after 1.9.2
Fix from $1,600 2020-03-19
Apex One HIGH 8.8
CVE-2020-8468 KEVEPSS 6%

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulne…

Patch available
Fix from $1,950 2020-03-18
Prtg Network Monitor HIGH 7.2
CVE-2019-11073EPSS 6%

A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sa…

Fix: 19.4.54.1506+
Fix from $1,950 2020-03-16
Styx MEDIUM 6.5
CVE-2020-6858

Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a res…

Fix: after 0.7.10
Fix from $1,600 2020-03-12
Dojox HIGH 8.6
CVE-2020-5259

In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inje…

Fix: 1.11.10 / 1.12.8+
Fix from $1,950 2020-03-10
Raquest HIGH 7.5
CVE-2019-19614

An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the …

Mitigation only
Fix from $1,950 2020-03-09
Craft Cms CRITICAL 9.8
CVE-2020-9757EPSS 73%

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers co…

Fix: 3.3.0+
Fix from $2,300 2020-03-04
Puma MEDIUM 6.5
CVE-2020-5249

In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header, an attacker can use a carria…

Fix: after 4.3.2
Fix from $1,600 2020-03-02
Puma HIGH 7.5
CVE-2020-5247

In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newli…

Fix: after 4.3.2
Fix from $1,950 2020-02-28
Widgets MEDIUM 5.4
CVE-2020-9382

An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page …

Fix: after 1.4.0
Fix from $1,600 2020-02-24
Dropwizard Validation HIGH 8.8
CVE-2020-5245

Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service a…

Fix: 1.3.19 / 2.0.2+
Fix from $1,950 2020-02-24
Ansible CRITICAL 9.8
CVE-2014-4678EPSS 5%

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…

Fix: 1.6.4+
Fix from $2,300 2020-02-20
Bodymen MEDIUM 6.3
CVE-2019-10792

bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.protot…

Fix: 1.1.1+
Fix from $1,600 2020-02-18
Dot Object MEDIUM 6.3
CVE-2019-10793

dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of Object.prototy…

Fix: 2.1.3+
Fix from $1,600 2020-02-18
Component Flatten MEDIUM 6.3
CVE-2019-10794

All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Objec…

Patch available
Fix from $1,600 2020-02-18
Undefsafe MEDIUM 6.3
CVE-2019-10795

undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of Object.prototyp…

Fix: 2.0.3+
Fix from $1,600 2020-02-18
Ansible CRITICAL 9.8
CVE-2014-4966

Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which …

Fix: 1.6.7+
Fix from $2,300 2020-02-18
Ansible CRITICAL 9.8
CVE-2014-4967

Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib…

Fix: 1.6.7+
Fix from $2,300 2020-02-18
Twiki CRITICAL 9.1
CVE-2014-7236EPSS 56%

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenable…

Fix: after 5.1.4
Fix from $2,300 2020-02-17