Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Plug HIGH 7.8
CVE-2017-1000052

Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypa…

Fix: 1.0.4 / 1.1.7+
Fix from $1,950 2017-07-17
Ntopng HIGH 7.5
CVE-2017-7459

ntopng before 3.0 allows HTTP Response Splitting.

Fix: after 2.4
Fix from $1,950 2017-06-26
Backhaul Radios HIGH 8.8
CVE-2017-9133

An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in…

Fix: after 2.2.1
Fix from $1,950 2017-05-21
Backhaul Radios HIGH 8.8
CVE-2017-9135

An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, t…

Fix: after 2.2.3
Fix from $1,950 2017-05-21
Atvise Scada HIGH 8.8
CVE-2017-6031

A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripti…

Fix: after 2.5.10
Fix from $1,950 2017-05-06
Brave MEDIUM 6.5
CVE-2017-8458

Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indic…

Patch available
Fix from $1,600 2017-05-03
Tablacus Explorer HIGH 8.8
CVE-2017-2140

Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory.

Fix: after 17.3.30
Fix from $1,950 2017-04-28
Peoplesoft Enterprise Peopletools HIGH 7.4
CVE-2017-3547

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported vers…

Patch available
Fix from $1,950 2017-04-24
Android CRITICAL 9.8
CVE-2016-1155

HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or …

Mitigation only
Fix from $2,300 2017-04-13
Wireshark HIGH 7.5
CVE-2017-7703

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was …

Patch available
Fix from $1,950 2017-04-12
Ninka CRITICAL 9.8
CVE-2017-7239

Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of ser…

Fix: after 1.3.0
Fix from $2,300 2017-04-10
Proxygen CRITICAL 9.8
CVE-2015-7264

The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.

Fix: after 0.32.0
Fix from $2,300 2017-04-10
Axis Communications Firmware HIGH 7.5
CVE-2015-8258EPSS 9%

AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script …

Fix: after 5.80.3
Fix from $1,950 2017-04-10
Ossim HIGH 8.8
CVE-2017-6971EPSS 16%

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, …

Fix: after 5.3.6
Fix from $1,950 2017-03-22
Documentum Content Server HIGH 8.8
CVE-2017-5585

OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based co…

No fix yet
Fix from $1,950 2017-02-22
Pear HIGH 7.5
CVE-2017-5630EPSS 13%

PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al…

No fix yet
Fix from $1,950 2017-02-01
Webmail HIGH 8.8
CVE-2015-2180

The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in …

Fix: after 1.1
Fix from $1,950 2017-01-30
Magento CRITICAL 9.8
CVE-2016-4010EPSS 93%

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serializ…

Fix: after 2.0.5
Fix from $2,300 2017-01-23
Moodle MEDIUM 5.4
CVE-2016-5013

In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.

Fix: after 2.7.14
Fix from $1,600 2017-01-20
Codeigniter CRITICAL 9.8
CVE-2016-10131

system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from f…

Fix: after 3.1.2
Fix from $2,300 2017-01-12
iOS MEDIUM 6.5
CVE-2016-6473

A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2…

Mitigation only
Fix from $1,600 2016-12-14
Ace Advanced Business Application Programming CRITICAL 9.9
CVE-2016-9832

PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbit…

No fix yet
Fix from $2,300 2016-12-10
Idrac7 Firmware HIGH 8.8
CVE-2016-5685

Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.

Fix: after 2.30.30.30
Fix from $1,950 2016-11-29
Android HIGH 8.8
CVE-2016-6754

A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote a…

Fix: after 6.0.1
Fix from $1,950 2016-11-25
PHP HIGH 7.5
CVE-2016-7125EPSS 6%

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows r…

Fix: after 5.6.24
Fix from $1,950 2016-09-12
phpMyAdmin MEDIUM 6.1
CVE-2016-5701

setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to condu…

Patch available
Fix from $1,600 2016-07-03
Symantec Critical System Protection HIGH 7.3
CVE-2015-8800

Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers …

Mitigation only
Fix from $1,950 2016-06-08
Messaging Gateway HIGH 8.2
CVE-2016-2204

The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted…

Fix: after 10.6.0
Fix from $1,950 2016-04-22
Documentum Xcp MEDIUM 6.5
CVE-2016-0881

EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection…

Mitigation only
Fix from $1,600 2016-02-12
Bolt MEDIUM 6.5
CVE-2015-7309EPSS 39%

The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbit…

Fix: after 2.2.0
Fix from $1,600 2015-09-22