Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.8 CVE-2021-27730 Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_4… Fta after 9_12_432 Fix from $2,3002021-03-02 CRITICAL 9.8 CVE-2021-27132EPSS 16% SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition head… Agcombo Vd625 Firmware Mitigation only Fix from $2,3002021-02-27 CRITICAL 9.8 CVE-2021-3197EPSS 72% An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an… Fedora 2015.8.10 / 2015.8.13+ Fix from $2,3002021-02-27 HIGH 8.8 CVE-2021-26068 An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via … Jira Server For Slack 2.0.15+ Fix from $1,9502021-02-22 HIGH 8.8 CVE-2020-12873 An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a w… Alfresco Enterprise Content Management 6.2.1+ Fix from $1,9502021-02-19 HIGH 7.8 CVE-2021-21316 less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming reso… Less Openui5 0.10.0+ Fix from $1,9502021-02-16 HIGH 7.5 CVE-2020-35564 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malici… Mbconnect24 after 2.6.2 Fix from $1,9502021-02-16 CRITICAL 9.8 CVE-2020-35775EPSS 13% CITSmart before 9.1.2.23 allows LDAP Injection. Citsmart 9.1.2.23+ Fix from $2,3002021-02-15 MEDIUM 6.1 CVE-2021-20644 ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page. Wrc 1467ghbk A Firmware Mitigation only Fix from $1,6002021-02-12 HIGH 7.5 CVE-2021-23335 All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure. Is User Valid No fix yet Fix from $1,9502021-02-11 CRITICAL 9.1 CVE-2021-21479EPSS 10% In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the sys… Scimono 0.0.19+ Fix from $2,3002021-02-09 MEDIUM 6.5 CVE-2021-21137EPSS 6% Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information… Chrome 88.0.705.50 / 88.0.4324.96+ Fix from $1,6002021-02-09 MEDIUM 6.5 CVE-2021-21141EPSS 5% Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy v… Chrome 88.0.705.74 / 88.0.4324.96+ Fix from $1,6002021-02-09 HIGH 8.8 CVE-2021-21305EPSS 13% CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions… Carrierwave 1.3.2 / 2.1.1+ Fix from $1,9502021-02-08 MEDIUM 6.8 CVE-2021-21303 Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-co… Helm 3.5.2+ Fix from $1,6002021-02-05 HIGH 8.8 CVE-2021-21277 angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2… Angular Expressions 1.1.2+ Fix from $1,9502021-02-01 CRITICAL 9.8 CVE-2020-15690 In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character. Nim 1.2.6+ Fix from $2,3002021-01-30 CRITICAL 9.8 CVE-2021-21278 RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk … Rsshub 2021-01-25+ Fix from $2,3002021-01-26 MEDIUM 5.3 CVE-2021-21263 Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit… Laravel 6.20.11 / 7.30.2+ Fix from $1,6002021-01-19 CRITICAL 9.8 CVE-2021-21242EPSS 74% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code exe… Onedev 4.0.3+ Fix from $2,3002021-01-15 HIGH 8.8 CVE-2021-21247 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAj… Onedev 4.0.3+ Fix from $1,9502021-01-15 HIGH 8.8 CVE-2021-21248 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. I… Onedev 4.0.3+ Fix from $1,9502021-01-15 HIGH 8.8 CVE-2021-21249 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote … Onedev 4.0.3+ Fix from $1,9502021-01-15 CRITICAL 9.8 CVE-2021-21243EPSS 54% OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted da… Onedev 4.0.3+ Fix from $2,3002021-01-15 CRITICAL 9.8 CVE-2021-21244 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injectio… Onedev 4.0.3+ Fix from $2,3002021-01-15 HIGH 8.8 CVE-2021-21261 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` ser… Debian Linux 1.8.5 / 1.10.0+ Fix from $1,9502021-01-14 MEDIUM 5.4 CVE-2020-26298 Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-… Redcarpet 3.5.1+ Fix from $1,6002021-01-11 MEDIUM 6.5 CVE-2020-5019 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. B… Spectrum Protect Plus 10.1.7+ Fix from $1,6002021-01-08 MEDIUM 5.3 CVE-2020-27260 Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow phys… Vital Signs Monitor Vc150 Firmware 1.7.15+ Fix from $1,6002021-01-08 CRITICAL 9.8 CVE-2020-28468 This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template … Pwntools 4.3.1+ Fix from $2,3002021-01-08