Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Loadmaster HIGH 8.8
CVE-2014-5287EPSS 8%

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI…

Fix: after 7.1-16
Fix from $1,950 2020-01-08
Dir 859 Firmware HIGH 7.5
CVE-2019-20213

D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnc…

Fix: after 3.12b04
Fix from $1,950 2020-01-02
Monitorix CRITICAL 9.8
CVE-2013-7070

The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharac…

Fix: 3.3.1+
Fix from $2,300 2019-12-31
Solr HIGH 7.5
CVE-2019-17558 KEVEPSS 99%

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi…

Fix: 7.7.3 / 8.4.0+
Fix from $1,950 2019-12-30
Feature MEDIUM 5.4
CVE-2013-4318

File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory.

No fix yet
Fix from $1,600 2019-12-26
Ktor MEDIUM 5.4
CVE-2019-19389

JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.

Fix: 1.2.6+
Fix from $1,600 2019-12-26
A Blog Cms MEDIUM 6.1
CVE-2019-6034

a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in …

Fix: 2.8.64 / 2.9.6+
Fix from $1,600 2019-12-26
PHP MEDIUM 5.9
CVE-2019-11045EPSS 9%

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them…

Fix: 5.19.0+
Fix from $1,600 2019-12-23
Shazam HIGH 8.8
CVE-2019-8792

An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. …

Mitigation only
Fix from $1,950 2019-12-18
Mail HIGH 7.5
CVE-2019-17123

The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstra…

No fix yet
Fix from $1,950 2019-12-13
Skype For Business MEDIUM 5.4
CVE-2019-1490

A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Serv…

Patch available
Fix from $1,600 2019-12-10
Openshift Origin Controller CRITICAL 9.8
CVE-2013-2095

rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection

No fix yet
Fix from $2,300 2019-12-10
Armeria MEDIUM 6.5
CVE-2019-16771

Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary …

Fix: 0.97.0+
Fix from $1,600 2019-12-06
Zanata CRITICAL 9.8
CVE-2013-4486

Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging

Fix: after 3.1.2
Fix from $2,300 2019-12-03
Dhcp6c CRITICAL 9.8
CVE-2011-2717

The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metach…

Fix: after 2011-07-25
Fix from $2,300 2019-11-27
Ubuntu Linux CRITICAL 9.8
CVE-2019-19330

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa),…

Fix: 2.0.10+
Fix from $2,300 2019-11-27
Ruby MEDIUM 5.3
CVE-2019-16254

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input i…

Fix: after 2.6.4
Fix from $1,600 2019-11-26
Ruby MEDIUM 5.3
CVE-2011-3624

Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Ser…

Mitigation only
Fix from $1,600 2019-11-26
Edeploy CRITICAL 9.8
CVE-2014-3700

eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data

Fix: after 1.6.0
Fix from $2,300 2019-11-21
Debian Linux HIGH 7.8
CVE-2010-4654

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

Fix: 0.16.3+
Fix from $1,950 2019-11-13
Magento CRITICAL 9.8
CVE-2019-8135

A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Sym…

Fix: 2.2.10 / 2.3.2+
Fix from $2,300 2019-11-06
TYPO3 HIGH 7.5
CVE-2010-3668

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.

Fix: 4.1.14 / 4.2.13+
Fix from $1,950 2019-11-04
Twiki CRITICAL 9.8
CVE-2005-3056

TWiki allows arbitrary shell command execution via the Include function

Patch available
Fix from $2,300 2019-11-01
Clickhouse MEDIUM 5.3
CVE-2019-18657

ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.

Fix: 19.13.5.44+
Fix from $1,600 2019-10-31
Telepresence Video Communication Server HIGH 7.2
CVE-2011-2538

Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to exec…

Mitigation only
Fix from $1,950 2019-10-29
Cloud Orchestrator MEDIUM 5.4
CVE-2019-4396

IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of…

Fix: after 2.5.0.9
Fix from $1,600 2019-10-25
Cloud Orchestrator MEDIUM 5.4
CVE-2019-4461

IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. Th…

Fix: after 2.5.0.9
Fix from $1,600 2019-10-25
Python MEDIUM 6.1
CVE-2019-18348

An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker co…

Fix: 3.5.10 / 3.6.11+
Fix from $1,600 2019-10-23
Ratpack HIGH 7.5
CVE-2019-17513

An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers l…

Fix: 1.7.5+
Fix from $1,950 2019-10-18
Iterm2 CRITICAL 9.8
CVE-2019-9535

A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by provi…

Fix: after 3.3.5
Fix from $2,300 2019-10-09