Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Firefox MEDIUM 5.3
CVE-2019-11718

Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page with…

Fix: 68.0+
Fix from $1,600 2019-07-23
Wide HIGH 7.5
CVE-2019-13915

b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and ru…

Fix: 1.6.0+
Fix from $1,950 2019-07-18
Gateway HIGH 7.5
CVE-2019-0319

The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attac…

No fix yet
Fix from $1,950 2019-07-10
Field Test MEDIUM 5.3
CVE-2019-13146

The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to…

No fix yet
Fix from $1,600 2019-07-09
K400r Firmware MEDIUM 6.5
CVE-2016-10761

Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

Mitigation only
Fix from $1,600 2019-06-29
Fehelper CRITICAL 9.8
CVE-2019-12966

FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} i…

Fix: after 2019-06-19
Fix from $2,300 2019-06-26
Debian Linux HIGH 7.5
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. T…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 7.5
CVE-2019-8323

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 7.5
CVE-2019-8325

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence in…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Advanced Business Application Programming Platform Kernel CRITICAL 9.8
CVE-2019-0304

FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.…

Mitigation only
Fix from $2,300 2019-06-12
Fedora MEDIUM 6.1
CVE-2019-12387

In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CR…

Fix: 19.2.1+
Fix from $1,600 2019-06-10
Rancher HIGH 8.8
CVE-2019-12303

In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd…

Fix: after 2.2.3
Fix from $1,950 2019-06-06
Spamtitan HIGH 7.5
CVE-2019-6800

In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which…

Fix: after 7.03
Fix from $1,950 2019-06-05
Exponent Cms CRITICAL 9.8
CVE-2016-8900

Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change…

Patch available
Fix from $2,300 2019-05-24
Exponent Cms CRITICAL 9.8
CVE-2016-8899

Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change…

Patch available
Fix from $2,300 2019-05-23
B2evolution CRITICAL 9.8
CVE-2016-8901

b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.

Patch available
Fix from $2,300 2019-05-23
Oculus Browser MEDIUM 6.1
CVE-2019-3562

A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This af…

Fix: after 5.7.11
Fix from $1,600 2019-04-29
Agile Plm CRITICAL 9.8
CVE-2019-2725 KEVEPSS 100%

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected …

Fix: 5.2.36 / 6.0.16+
Fix from $2,300 2019-04-26
Openshift Service Mesh HIGH 8.3
CVE-2019-9900

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers c…

Fix: after 1.9.0
Fix from $1,950 2019-04-25
Origin HIGH 7.8
CVE-2019-11354EPSS 23%

The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be…

No fix yet
Fix from $1,950 2019-04-19
Cloud Private MEDIUM 5.4
CVE-2018-1943

IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visi…

Patch available
Fix from $1,600 2019-04-08
Axiom MEDIUM 6.1
CVE-2015-5462

AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.

Fix: after 9.5.3
Fix from $1,600 2019-04-03
Mac Os X MEDIUM 5.9
CVE-2018-4153

An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.

Fix: 10.14+
Fix from $1,600 2019-04-03
Ofcms HIGH 8.8
CVE-2019-9614

An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.ut…

Fix: 1.1.3+
Fix from $1,950 2019-03-06
Papercut Mf CRITICAL 9.8
CVE-2019-8948

PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.

Fix: 18.3.6+
Fix from $2,300 2019-02-20
Bigfix Compliance MEDIUM 5.4
CVE-2017-1202

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, wh…

Fix: after 1.9.91
Fix from $1,600 2019-02-05
Laquis Scada HIGH 8.8
CVE-2018-18992

LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote co…

Fix: 4.1.0.4150+
Fix from $1,950 2019-02-05
Laquis Scada CRITICAL 9.8
CVE-2018-18996

LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to …

Fix: 4.1.0.4150+
Fix from $2,300 2019-02-05
Zoneminder MEDIUM 6.5
CVE-2019-7351

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject …

Fix: after 1.32.3
Fix from $1,600 2019-02-04
Mpath HIGH 7.5
CVE-2018-16490

A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

Fix: 0.5.1+
Fix from $1,950 2019-02-01