Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 6.5 CVE-2021-29502 WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to access sensible informations… Warnsystem 1.3.18+ Fix from $1,6002021-05-10 MEDIUM 6.5 CVE-2021-29501 Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users to expose sensitive informatio… Dav Cogs 1.0.1+ Fix from $1,6002021-05-10 HIGH 7.5 CVE-2021-3154 An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: thi… Serv U 15.2.2+ Fix from $1,9502021-05-04 HIGH 7.5 CVE-2021-31164 Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. Unomi 1.5.5+ Fix from $1,9502021-05-04 HIGH 7.5 CVE-2021-22331 There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit… P30 Firmware 10.1.0.165 / 11.0.0.118+ Fix from $1,9502021-04-28 MEDIUM 5.9 CVE-2019-25031 Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HT… Debian Linux 1.9.5+ Fix from $1,6002021-04-27 CRITICAL 9.3 CVE-2021-0268 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buff… Junos Mitigation only Fix from $2,3002021-04-22 HIGH 8.0 CVE-2021-28829 The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO A… Administrator after 5.10.2 Fix from $1,9502021-04-20 HIGH 7.5 CVE-2021-31402 The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. Dio 5.0.0+ Fix from $1,9502021-04-15 HIGH 8.8 CVE-2021-27182 An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an… Mdaemon 20.0.4+ Fix from $1,9502021-04-14 HIGH 8.8 CVE-2021-22879 Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to exec… Desktop 3.1.3+ Fix from $1,9502021-04-14 MEDIUM 5.3 CVE-2020-36308 Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading ti… Debian Linux 4.0.7 / 4.1.1+ Fix from $1,6002021-04-06 HIGH 7.8 CVE-2021-21420 vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted so… Stripe 1.7.3+ Fix from $1,9502021-04-01 HIGH 8.8 CVE-2021-21372 Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in differ… Nim 1.2.10 / 1.4.4+ Fix from $1,9502021-03-26 MEDIUM 5.3 CVE-2020-7464 In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and 11.3-RELEASE before p14, a pr… FreeBSD Mitigation only Fix from $1,6002021-03-26 MEDIUM 6.1 CVE-2021-21333 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging… Fedora 1.27.0+ Fix from $1,6002021-03-26 MEDIUM 6.5 CVE-2021-3027 app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of specia… Passhport after 2.5 Fix from $1,6002021-03-26 HIGH 7.5 CVE-2021-29156EPSS 76% ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-ch… Openam 13.5.1+ Fix from $1,9502021-03-25 HIGH 7.3 CVE-2021-1432 A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlyi… Ios Xe Mitigation only Fix from $1,9502021-03-24 MEDIUM 5.3 CVE-2021-28963 Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters. Debian Linux 3.2.1+ Fix from $1,6002021-03-22 MEDIUM 5.3 CVE-2021-26069 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project k… Data Center 8.5.11 / 8.13.3+ Fix from $1,6002021-03-22 MEDIUM 5.3 CVE-2020-36144 Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template sinc… Redash Mitigation only Fix from $1,6002021-03-18 HIGH 7.8 CVE-2021-24144 Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers injec… Contact Form 7 Database Addon 1.2.5.6+ Fix from $1,9502021-03-18 MEDIUM 5.5 CVE-2020-4851 IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and develo… Spectrum Scale 5.0.5.5 / 5.1.0.2+ Fix from $1,6002021-03-16 HIGH 8.8 CVE-2021-22191 Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture f… Wireshark after 3.4.3 Fix from $1,9502021-03-15 HIGH 7.2 CVE-2020-14987 An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because th… Experience Manager after 14.2.2 Fix from $1,9502021-03-11 HIGH 8.2 CVE-2021-21381 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before versi… Debian Linux 1.10.2+ Fix from $1,9502021-03-11 MEDIUM 6.1 CVE-2021-21510 Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit th… Idrac8 Firmware 2.75.100.75+ Fix from $1,6002021-03-08 MEDIUM 6.1 CVE-2021-21313 GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In G… Glpi 9.5.4+ Fix from $1,6002021-03-03 CRITICAL 9.0 CVE-2021-21353 Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty… Pug 2.0.3 / 3.0.1+ Fix from $2,3002021-03-03