Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 5.4 CVE-2021-22232 HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE GitLab 13.11.6 / 13.12.6+ Fix from $1,6002021-07-06 MEDIUM 6.1 CVE-2021-20101 Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to recei… Machform 16+ Fix from $1,6002021-06-29 HIGH 8.8 CVE-2021-23400 The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns … Nodemailer 6.6.1+ Fix from $1,9502021-06-29 HIGH 8.8 CVE-2021-20574 IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially cra… Security Identity Manager Adapter Patch available Fix from $1,9502021-06-28 MEDIUM 5.4 CVE-2021-29676 IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-cra… Security Verify 10.9.66+ Fix from $1,6002021-06-25 MEDIUM 5.3 CVE-2021-29955 A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have … Firefox 78.9 / 87.0+ Fix from $1,6002021-06-24 HIGH 8.8 CVE-2021-24002 When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed a… Firefox 78.10 / 88.0+ Fix from $1,9502021-06-24 HIGH 7.5 CVE-2021-29084 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report managemen… Diskstation Manager 3.1-23033 / 6.2.3-25426-3+ Fix from $1,9502021-06-23 HIGH 7.5 CVE-2021-29085 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component… Diskstation Manager 3.1-23033 / 6.2.3-25426-3+ Fix from $1,9502021-06-23 MEDIUM 6.5 CVE-2021-0551 In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. Th… Android Mitigation only Fix from $1,6002021-06-22 HIGH 7.3 CVE-2021-0553 In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local esc… Android Mitigation only Fix from $1,9502021-06-22 HIGH 7.8 CVE-2021-0567 In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of… Android Mitigation only Fix from $1,9502021-06-22 CRITICAL 9.1 CVE-2021-20736 NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the databa… Growi 4.2.20+ Fix from $2,3002021-06-22 CRITICAL 9.8 CVE-2018-25016 Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection. Greenbone Security Assistant 5.0.0 / 7.0.3+ Fix from $2,3002021-06-21 HIGH 7.5 CVE-2021-29702 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnorma… Db2 after 11.5.5.0 Fix from $1,9502021-06-16 MEDIUM 6.5 CVE-2021-28979 SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability usin… Safenet Keysecure after 8.12.0 Fix from $1,6002021-06-16 HIGH 7.8 CVE-2021-25682 It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel. Apport 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+ Fix from $1,9502021-06-11 HIGH 7.5 CVE-2021-33668 Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confid… Infrabox 1.2.1+ Fix from $1,9502021-06-09 MEDIUM 6.5 CVE-2021-30540 Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafte… Chrome 91.0.4472.77+ Fix from $1,6002021-06-07 MEDIUM 6.5 CVE-2021-31249EPSS 18% A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validatio… Bf 430 Firmware No fix yet Fix from $1,6002021-06-04 HIGH 8.8 CVE-2021-30506 Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a we… Chrome 90.0.4430.212+ Fix from $1,9502021-06-04 CRITICAL 9.1 CVE-2021-32647 Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication Remote Code Execution (RCE).… Emissary Patch available Fix from $2,3002021-06-01 CRITICAL 9.4 CVE-2021-32642 radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-edu… Fedora 1.9.0+ Fix from $2,3002021-05-28 HIGH 7.0 CVE-2020-27212 STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP lev… Stm32cubel4 Firmware after 1.16.0 Fix from $1,9502021-05-21 MEDIUM 6.1 CVE-2021-29414 STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control. Stm32cubel4 Firmware after 1.17.0 Fix from $1,6002021-05-21 HIGH 7.8 CVE-2021-32622 Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the loca… Matrix React Sdk 3.21.0+ Fix from $1,9502021-05-17 MEDIUM 6.5 CVE-2021-3524 A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection … Ceph 14.2.21+ Fix from $1,6002021-05-17 MEDIUM 5.4 CVE-2021-30214EPSS 24% Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter. Knowage No fix yet Fix from $1,6002021-05-12 MEDIUM 5.3 CVE-2020-26142 An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversa… OpenBSD Mitigation only Fix from $1,6002021-05-11 HIGH 7.1 CVE-2021-27614 SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to i… Business One Hana Chef Cookbook Mitigation only Fix from $1,9502021-05-11