Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 6.0 CVE-2021-29795 IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of hypervisor calls from a part… Powervm Hypervisor Patch available Fix from $1,6002021-09-21 CRITICAL 9.8 CVE-2021-41392 static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed … Boostnote after 0.22.0 Fix from $2,3002021-09-17 HIGH 8.0 CVE-2021-41390 In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection. Enterprise Content Management No fix yet Fix from $1,9502021-09-17 HIGH 8.8 CVE-2021-41314EPSS 14% Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentica… Gc108p Firmware 1.0.3.2 / 1.0.5.3+ Fix from $1,9502021-09-16 HIGH 8.8 CVE-2021-39213 GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable… Glpi 9.5.6+ Fix from $1,9502021-09-15 HIGH 7.8 CVE-2021-30777 An injection issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Upd… Mac Os X 11.5+ Fix from $1,9502021-09-08 HIGH 8.2 CVE-2021-40143 Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may d… Nexus Repository Manager 3 3.34.0+ Fix from $1,9502021-09-07 HIGH 7.5 CVE-2021-39187 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes… Parse Server 4.10.3+ Fix from $1,9502021-09-02 MEDIUM 6.1 CVE-2021-39175 HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the … Hedgedoc 1.9.0+ Fix from $1,6002021-08-30 HIGH 8.8 CVE-2020-18875 Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocit… Dotcms 5.1.0+ Fix from $1,9502021-08-18 CRITICAL 9.6 CVE-2021-32827 MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim… Mockserver Patch available Fix from $2,3002021-08-16 CRITICAL 9.8 CVE-2021-20509 IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the sys… Maximo Asset Management 7.6.1.2+ Fix from $2,3002021-08-12 HIGH 7.5 CVE-2021-38371 The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending. Exim after 4.94.2 Fix from $1,9502021-08-10 HIGH 7.5 CVE-2020-23148 The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive inform… Rconfig No fix yet Fix from $1,9502021-08-09 HIGH 8.1 CVE-2021-38290 A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset… Fuel Cms after 1.5.0 Fix from $1,9502021-08-09 MEDIUM 6.1 CVE-2021-37541 In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. Hub 2021.1.13402+ Fix from $1,6002021-08-06 MEDIUM 5.5 CVE-2020-24821 A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation … Libelfin No fix yet Fix from $1,6002021-08-04 MEDIUM 5.5 CVE-2020-24822 A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault… Libelfin No fix yet Fix from $1,6002021-08-04 MEDIUM 5.5 CVE-2020-24823 A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault vi… Libelfin No fix yet Fix from $1,6002021-08-04 MEDIUM 5.5 CVE-2020-24825 A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fa… Libelfin No fix yet Fix from $1,6002021-08-04 MEDIUM 5.5 CVE-2020-24826 A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation f… Libelfin No fix yet Fix from $1,6002021-08-04 HIGH 8.1 CVE-2021-38084 An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the PO… Courier Mail Server 1.1.5+ Fix from $1,9502021-08-03 HIGH 7.2 CVE-2021-35450 A Server Side Template Injection in the Entando Admin Console 6.3.9 and before allows a user with privileges to execute FreeMarker template with comm… Admin Console after 6.3.9 Fix from $1,9502021-08-02 HIGH 7.3 CVE-2021-33195 Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may c… Go 1.15.13 / 1.16.5+ Fix from $1,9502021-08-02 HIGH 7.5 CVE-2021-32558EPSS 9% An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Aster… Debian Linux 13.38.3 / 16.19.1+ Fix from $1,9502021-07-30 CRITICAL 9.8 CVE-2021-3169 An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have acce… Jumpserver 2.4.5 / 2.5.4+ Fix from $2,3002021-07-23 HIGH 8.8 CVE-2021-32756 ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module o… Manageiq Mitigation only Fix from $1,9502021-07-21 HIGH 8.1 CVE-2020-5323 Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection v… Emc Openmanage Enterprise 1.10.00 / 3.2+ Fix from $1,9502021-07-19 HIGH 8.0 CVE-2021-0594 In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote … Android Mitigation only Fix from $1,9502021-07-14 MEDIUM 5.3 CVE-2021-36381 In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_err… Transaction Management after 2021-07-12 Fix from $1,6002021-07-12