Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 7.5 CVE-2021-32499 SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable. Sopas Engineering Tool 4.8.0+ Fix from $1,9502021-12-17 HIGH 8.1 CVE-2020-35213 An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node. Atomix No fix yet Fix from $1,9502021-12-16 HIGH 7.5 CVE-2021-37262 JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service. Jfinal Cms Patch available Fix from $1,9502021-12-16 CRITICAL 9.1 CVE-2021-43837EPSS 5% vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli fea… Vault Cli 3.0.0+ Fix from $2,3002021-12-16 HIGH 7.2 CVE-2021-41276 Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanit… Tuleap 13.1-5 / 13.2-3+ Fix from $1,9502021-12-15 HIGH 7.2 CVE-2021-43782 Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a follow up to GHSA-887w-pv2r-x8pm… Tuleap 13.1-6 / 13.2-4+ Fix from $1,9502021-12-15 HIGH 7.1 CVE-2021-43818 lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted scri… Fedora 4.6.5+ Fix from $1,9502021-12-13 HIGH 8.8 CVE-2021-43038 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL tr… Unitrends Backup 10.5.5+ Fix from $1,9502021-12-06 HIGH 7.8 CVE-2021-38873 IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by im… Planning Analytics Patch available Fix from $1,9502021-11-24 HIGH 7.2 CVE-2021-36313 Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged attacker, may potentially explo… Cloudlink 7.1.1+ Fix from $1,9502021-11-23 HIGH 7.5 CVE-2021-37033 There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. Emui No fix yet Fix from $1,9502021-11-23 MEDIUM 6.1 CVE-2021-36322 Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may pote… X1008p Firmware 3.0.1.8+ Fix from $1,6002021-11-20 MEDIUM 5.3 CVE-2021-34419 In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a use… Zoom Client For Meetings 5.1.0+ Fix from $1,6002021-11-11 CRITICAL 9.8 CVE-2021-43350 An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP… Traffic Control 5.1.4 / 6.0.1+ Fix from $2,3002021-11-11 HIGH 8.8 CVE-2021-25980 In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-r… Talkyard after 0.2021.02-wip-879ef3fe1 Fix from $1,9502021-11-11 CRITICAL 9.8 CVE-2021-43185 JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. Youtrack 2021.3.23639+ Fix from $2,3002021-11-09 CRITICAL 9.8 CVE-2021-41170 neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template eng… Neoan3 Template 1.1.1+ Fix from $2,3002021-11-08 MEDIUM 6.7 CVE-2021-36697 With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file cont… Pandora Fms after 755 Fix from $1,6002021-11-03 CRITICAL 9.8 CVE-2021-41232 Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerab… Planning Poker 1.16.3+ Fix from $2,3002021-11-02 CRITICAL 9.8 CVE-2021-38294EPSS 84% A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4… Storm 1.2.4 / 2.1.1+ Fix from $2,3002021-10-25 HIGH 8.0 CVE-2020-23050 TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user a… Tao Assessment Platform No fix yet Fix from $1,9502021-10-22 CRITICAL 9.8 CVE-2021-41163EPSS 20% Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.… Discourse 2.7.9+ Fix from $2,3002021-10-20 HIGH 7.5 CVE-2021-37933 An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logi… Huntflow Enterprise 3.10.6+ Fix from $1,9502021-10-14 MEDIUM 5.3 CVE-2021-20802 HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product. Remote Service Manager Mitigation only Fix from $1,6002021-10-13 CRITICAL 9.8 CVE-2021-38458 A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite crit… Mxview after 3.2.2 Fix from $2,3002021-10-12 HIGH 8.8 CVE-2021-41128 Hygeia is an application for collecting and processing personal and case data in connection with communicable diseases. In affected versions all CSV … Hygeia 1.30.4+ Fix from $1,9502021-10-06 HIGH 8.8 CVE-2021-31988 A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed… Axis Os 6.50.5.5 / 8.40.4.3+ Fix from $1,9502021-10-05 HIGH 7.2 CVE-2021-35504 Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary. Filerun after 2021.03.26 Fix from $1,9502021-10-05 HIGH 7.2 CVE-2021-35505 Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary. Filerun after 2021.03.26 Fix from $1,9502021-10-05 CRITICAL 9.8 CVE-2021-41862 AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL). Aviatorscript No fix yet Fix from $2,3002021-10-02