Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Node.extend CRITICAL 9.8
CVE-2018-16491

A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.proto…

Fix: 1.1.7 / 2.0.1+
Fix from $2,300 2019-02-01
Extend CRITICAL 9.8
CVE-2018-16492

A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.pro…

Fix: 2.0.2 / 3.0.2+
Fix from $2,300 2019-02-01
Defaults Deep CRITICAL 9.8
CVE-2018-16486

A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.

Fix: after 0.2.4
Fix from $2,300 2019-02-01
Just Extend CRITICAL 9.8
CVE-2018-16489

A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functio…

Fix: 4.0.0+
Fix from $2,300 2019-02-01
Pypiserver MEDIUM 6.1
CVE-2019-6802

CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.

Fix: after 1.2.5
Fix from $1,600 2019-01-25
Django MEDIUM 6.5
CVE-2019-3498

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Down…

Fix: 1.11.18 / 2.0.10+
Fix from $1,600 2019-01-09
Kirby MEDIUM 6.1
CVE-2018-16627

panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

No fix yet
Fix from $1,600 2018-12-20
Esigate CRITICAL 9.8
CVE-2018-1000854

esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (…

Fix: after 5.2
Fix from $2,300 2018-12-20
Icinga Web 2 HIGH 7.5
CVE-2018-18250

Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation ite…

Fix: 2.6.2+
Fix from $1,950 2018-12-17
Terminology HIGH 7.8
CVE-2018-20167

Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn…

Fix: 1.3.1+
Fix from $1,950 2018-12-17
Connections MEDIUM 5.4
CVE-2018-1896

IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-…

Patch available
Fix from $1,600 2018-12-07
Virtualmin MEDIUM 6.1
CVE-2018-18207

Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.

No fix yet
Fix from $1,600 2018-10-10
Fuel Cms CRITICAL 9.8
CVE-2018-16763EPSS 83%

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Cod…

Fix: after 1.4.2
Fix from $2,300 2018-09-09
Campaign MEDIUM 5.4
CVE-2017-1115

IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec…

Patch available
Fix from $1,600 2018-09-07
E42 80 Firmware MEDIUM 6.8
CVE-2018-9062

In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.

Fix: 0zcn48ww / 2wcn40ww+
Fix from $1,600 2018-07-19
Rational Quality Manager MEDIUM 5.4
CVE-2018-1549

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could explo…

Fix: after 6.0.5
Fix from $1,600 2018-07-10
Acrobat Dc CRITICAL 9.8
CVE-2018-4995EPSS 7%

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST inject…

Fix: after 18.011.20038
Fix from $2,300 2018-07-09
Nx Os HIGH 8.8
CVE-2018-0313

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the managem…

Mitigation only
Fix from $1,950 2018-06-21
Enterprise Linux Desktop HIGH 8.8
CVE-2017-7846

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in th…

Fix: 52.5.2+
Fix from $1,950 2018-06-11
Enterprise Linux MEDIUM 5.3
CVE-2017-7848

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.

Fix: 52.5.2+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7788

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content S…

Fix: 55.0+
Fix from $2,300 2018-06-11
Apple Tv MEDIUM 5.5
CVE-2018-4235

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watch…

Fix: 4.3.1 / 10.13.5+
Fix from $1,600 2018-06-08
Shout MEDIUM 6.1
CVE-2017-16043

Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the…

Fix: 0.50.0+
Fix from $1,600 2018-06-04
Factorytalk Activation HIGH 7.8
CVE-2017-6015

Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may …

Fix: after 4.00.02
Fix from $1,950 2018-05-11
Debian Linux HIGH 8.8
CVE-2017-18266

The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER enviro…

Fix: 1.1.3+
Fix from $1,950 2018-05-10
Mdm9206 Firmware CRITICAL 9.8
CVE-2016-10498

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205,…

Mitigation only
Fix from $2,300 2018-04-18
Open Web Analytics CRITICAL 9.8
CVE-2014-2294

Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_even…

Fix: 1.5.7+
Fix from $2,300 2018-04-17
Debian Linux CRITICAL 9.8
CVE-2017-0372EPSS 11%

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

Fix: after 1.23.15
Fix from $2,300 2018-04-13
Tivoli Directory Server HIGH 7.8
CVE-2015-1975

The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 3…

Mitigation only
Fix from $1,950 2018-04-03
Mac Os X HIGH 8.8
CVE-2018-4106

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" co…

Fix: 10.13.4+
Fix from $1,950 2018-04-03