Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Allura MEDIUM 6.1
CVE-2018-1319

In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted…

Fix: after 1.8.0
Fix from $1,600 2018-03-15
Email Encryption Gateway CRITICAL 9.8
CVE-2018-6220EPSS 10%

An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to…

Patch available
Fix from $2,300 2018-03-15
Webarchive Agent HIGH 8.1
CVE-2018-1000130EPSS 73%

A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on th…

Mitigation only
Fix from $1,950 2018-03-14
Elasticsearch CRITICAL 9.8
CVE-2015-5377EPSS 14%

Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI app…

Fix: 1.6.1+
Fix from $2,300 2018-03-06
Knox Enterprise Mobility Management MEDIUM 5.9
CVE-2017-10963

In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker c…

Mitigation only
Fix from $1,600 2018-02-20
Opencall Media Platform HIGH 8.8
CVE-2017-5799EPSS 15%

A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (…

Fix: 3.4.2 / 4.4.7+
Fix from $1,950 2018-02-15
Myrepos HIGH 7.5
CVE-2018-7032

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attack…

Fix: after 1.20171231
Fix from $1,950 2018-02-14
Webpam Proe MEDIUM 6.1
CVE-2018-6603

Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript cod…

Mitigation only
Fix from $1,600 2018-02-07
Secure Mail Gateway CRITICAL 9.8
CVE-2018-6289EPSS 7%

Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.

No fix yet
Fix from $2,300 2018-02-06
Debian Linux HIGH 7.5
CVE-2018-6519

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for…

Fix: 1.10.4 / 2.3.5+
Fix from $1,950 2018-02-02
Wondercms HIGH 7.5
CVE-2017-14523EPSS 8%

WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that e…

No fix yet
Fix from $1,950 2018-01-26
Silverstripe MEDIUM 5.5
CVE-2017-18049

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and …

Fix: after 3.6.2
Fix from $1,600 2018-01-23
Smart Protection Server CRITICAL 9.8
CVE-2017-14094EPSS 19%

A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command executio…

Fix: after 3.2
Fix from $2,300 2018-01-19
Android HIGH 7.8
CVE-2014-7952

The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveragi…

No fix yet
Fix from $1,950 2018-01-12
Ofbiz CRITICAL 9.8
CVE-2017-15714

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code …

No fix yet
Fix from $2,300 2018-01-04
Rocket.chat CRITICAL 9.8
CVE-2017-1000493

Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

Fix: after 0.59
Fix from $2,300 2018-01-03
Cms Made Simple CRITICAL 9.8
CVE-2017-1000453

CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execu…

Fix: 2.2+
Fix from $2,300 2018-01-02
Cms Made Simple HIGH 7.8
CVE-2017-1000454

CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and l…

Fix: 2.2+
Fix from $1,950 2018-01-02
Linux Kernel MEDIUM 5.5
CVE-2016-3695

The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause …

Patch available
Fix from $1,600 2017-12-29
Smartcare HIGH 8.8
CVE-2017-15313

Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious CSV expression to the affecte…

Mitigation only
Fix from $1,950 2017-12-22
Diskstation Manager MEDIUM 6.5
CVE-2017-16766

An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows loc…

Fix: 6.0.3-8754-6 / 6.1.4-15217+
Fix from $1,600 2017-12-22
Ruby CRITICAL 9.8
CVE-2017-17790EPSS 6%

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by…

Fix: after 2.4.2
Fix from $2,300 2017-12-20
Global HIGH 8.8
CVE-2017-17531

gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow…

Mitigation only
Fix from $1,950 2017-12-14
Kiwi HIGH 8.8
CVE-2017-17532

examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable,…

Mitigation only
Fix from $1,950 2017-12-14
Tkabber HIGH 8.8
CVE-2017-17533

default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow re…

Mitigation only
Fix from $1,950 2017-12-14
Mensis HIGH 8.8
CVE-2017-17534

uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow…

Mitigation only
Fix from $1,950 2017-12-14
Gjots2 HIGH 8.8
CVE-2017-17535

lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which mig…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17511

KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attac…

Mitigation only
Fix from $1,950 2017-12-14
Tex Live HIGH 8.8
CVE-2017-17513

TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow rem…

Fix: after 20170524
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17514

boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote …

Mitigation only
Fix from $1,950 2017-12-14