Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Spectrum Scale HIGH 7.8
CVE-2019-4558

A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4…

Fix: after 5.0.3.2
Fix from $1,950 2019-10-09
Unified Contact Center Express MEDIUM 6.1
CVE-2019-15259

A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response s…

Fix: 11.6+
Fix from $1,600 2019-10-02
Putty HIGH 7.5
CVE-2019-17068

PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.

Fix: 0.73+
Fix from $1,950 2019-10-01
Yzmcms MEDIUM 6.1
CVE-2019-16532

An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.

No fix yet
Fix from $1,600 2019-09-26
Cf Deployment HIGH 8.1
CVE-2019-11277

Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authentic…

Fix: 1.7.11 / 2.3.0+
Fix from $1,950 2019-09-23
Newspaper CRITICAL 9.8
CVE-2017-18634

The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

Fix: 6.7.2+
Fix from $2,300 2019-09-16
Arubaos MEDIUM 6.1
CVE-2019-5314

Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able t…

Fix: 6.4.4.20 / 6.5.4.11+
Fix from $1,600 2019-09-13
Ofbiz CRITICAL 9.8
CVE-2019-10074

An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This …

Fix: after 16.11.05
Fix from $2,300 2019-09-11
Gravitate Qa Tracker CRITICAL 9.8
CVE-2017-18605

The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.

Fix: after 1.2.1
Fix from $2,300 2019-09-10
Sitebuilder Dynamic Components HIGH 7.5
CVE-2017-18604

The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.

Fix: after 1.0
Fix from $1,950 2019-09-10
Librenms HIGH 8.8
CVE-2019-12463

An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/gr…

Fix: 1.53+
Fix from $1,950 2019-09-09
Librenms CRITICAL 9.8
CVE-2019-10665

An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes…

Fix: after 1.47
Fix from $2,300 2019-09-09
Webex Teams HIGH 8.8
CVE-2019-1939

A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affec…

Fix: 3.0.12427.0+
Fix from $1,950 2019-09-05
Live Chat MEDIUM 6.1
CVE-2014-10386

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

Fix: 4.1.0+
Fix from $1,600 2019-08-22
Wp Support Plus Responsive Ticket System MEDIUM 6.1
CVE-2014-10391

The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.

Fix: 4.1+
Fix from $1,600 2019-08-22
Rich Counter MEDIUM 6.1
CVE-2014-10394

The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.

Fix: 1.2.0+
Fix from $1,600 2019-08-22
Post Pay Counter CRITICAL 9.8
CVE-2017-18583

The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.

Fix: 2.731+
Fix from $2,300 2019-08-22
Jira Server CRITICAL 9.8
CVE-2019-11581 KEVEPSS 85%

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. A…

Fix: 7.6.14 / 7.13.5+
Fix from $2,300 2019-08-09
3par Storeserv Management Console HIGH 8.8
CVE-2019-5404

A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

Fix: 3.5.0.1+
Fix from $1,950 2019-08-09
Cpanel HIGH 8.8
CVE-2016-10801

cPanel before 58.0.4 has improper session handling for shared users (SEC-139).

Fix: 11.54.0.26 / 56.0.27+
Fix from $1,950 2019-08-07
Magento MEDIUM 6.5
CVE-2019-7889

An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magen…

Fix: 1.9.4.2 / 1.14.4.2+
Fix from $1,600 2019-08-02
Cpanel HIGH 7.2
CVE-2017-18386

cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).

Fix: 62.0.35 / 64.0.42+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.2
CVE-2017-18387

cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).

Fix: 62.0.35 / 64.0.42+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 6.3
CVE-2017-18389

cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).

Fix: 64.0.42 / 66.0.34+
Fix from $1,600 2019-08-02
Cpanel HIGH 8.1
CVE-2016-10845

cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,950 2019-08-01
Cpanel HIGH 8.1
CVE-2016-10847

cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).

Fix: 11.48.5.2 / 11.50.4.3+
Fix from $1,950 2019-08-01
Cpanel HIGH 7.3
CVE-2018-20914

In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).

Fix: 70.0.23+
Fix from $1,950 2019-08-01
Cpanel MEDIUM 5.3
CVE-2018-20885

cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).

Fix: 74.0.0+
Fix from $1,600 2019-08-01
Invenio App MEDIUM 6.1
CVE-2019-1020006

invenio-app before 1.1.1 allows host header injection.

Fix: 1.1.1+
Fix from $1,600 2019-07-29
Firefox HIGH 8.3
CVE-2019-9811

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser fea…

Fix: 60.8 / 68.0+
Fix from $1,950 2019-07-23