Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.8 CVE-2013-4144 There is an object injection vulnerability in swfupload plugin for wordpress. Swfupload No fix yet Fix from $2,3002022-06-30 MEDIUM 6.1 CVE-2022-31108 Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex … Mermaid 9.1.3+ Fix from $1,6002022-06-28 HIGH 8.8 CVE-2022-31086 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,9502022-06-27 HIGH 7.8 CVE-2022-31087 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,9502022-06-27 MEDIUM 5.3 CVE-2022-31088 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,6002022-06-27 CRITICAL 9.8 CVE-2022-25167 Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L… Flume 1.10.0+ Fix from $2,3002022-06-14 HIGH 8.8 CVE-2020-36531 A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device M… Sevone Network Performance Management after 5.7.2.22 Fix from $1,9502022-06-07 HIGH 7.5 CVE-2022-29631 Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRe… Jodd Http 6.2.1+ Fix from $1,9502022-06-06 CRITICAL 9.8 CVE-2020-28246 A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email tem… Form.io Mitigation only Fix from $2,3002022-06-02 MEDIUM 6.1 CVE-2022-30991 HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 Cyber Protect 15+ Fix from $1,6002022-05-18 MEDIUM 5.4 CVE-2022-23068 ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name f… Tooljet after 1.10.2 Fix from $1,6002022-05-18 MEDIUM 6.6 CVE-2022-22975 An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would inv… Pinniped 0.17.0+ Fix from $1,6002022-05-11 HIGH 7.2 CVE-2022-29171 Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserv… Sourcegraph 3.38.0+ Fix from $1,9502022-05-06 HIGH 8.8 CVE-2022-29166 matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing… Matrix Irc Bridge 0.33.2+ Fix from $1,9502022-05-05 HIGH 8.8 CVE-2022-23064 In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password … Snipe It after 5.3.7 Fix from $1,9502022-05-02 HIGH 7.5 CVE-2022-27924 KEVEPSS 85% Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. Thes… Zimbra Collaboration Suite Mitigation only Fix from $1,9502022-04-21 HIGH 7.2 CVE-2022-20693 A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a… Ios Xe Mitigation only Fix from $1,9502022-04-15 HIGH 7.5 CVE-2022-28345 The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking spa… Signal 5.34+ Fix from $1,9502022-04-15 MEDIUM 6.8 CVE-2022-24832 GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly esc… Gocd 22.1.0+ Fix from $1,6002022-04-11 CRITICAL 9.8 CVE-2022-24838EPSS 33% Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and … Calendar 3.2.2+ Fix from $2,3002022-04-11 MEDIUM 5.3 CVE-2021-22055 The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious … Photon Os 2022-02-16+ Fix from $1,6002022-04-11 CRITICAL 9.8 CVE-2022-1287 A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classe… School Club Application System Mitigation only Fix from $2,3002022-04-09 MEDIUM 5.4 CVE-2022-1074 A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection</h1> in the WiFi settings of … Flex 1085 Firmware Mitigation only Fix from $1,6002022-03-29 CRITICAL 9.8 CVE-2022-25420 NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary … Goo Blog No fix yet Fix from $2,3002022-03-29 CRITICAL 9.8 CVE-2022-26205 Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability … Marky Mitigation only Fix from $2,3002022-03-27 HIGH 7.8 CVE-2022-20001 fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-re… Fedora after 3.3.1 Fix from $1,9502022-03-14 MEDIUM 6.1 CVE-2022-22344 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST… Spectrum Copy Data Management 2.2.15.0+ Fix from $1,6002022-03-14 CRITICAL 10.0 CVE-2022-24760EPSS 49% Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Ser… Parse Server 4.10.7+ Fix from $2,3002022-03-12 HIGH 8.8 CVE-2021-41282EPSS 87% diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the fire… Pfsense No fix yet Fix from $1,9502022-03-01 MEDIUM 5.3 CVE-2022-23701 A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior… Integrated Lights Out 2.60+ Fix from $1,6002022-02-24