Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 6.1 CVE-2020-26293 HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before versi… Htmlsanitizer 5.0.372+ Fix from $1,6002021-01-04 CRITICAL 9.9 CVE-2020-10208 Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B … Ak45x Firmware No fix yet Fix from $2,3002020-12-30 HIGH 8.8 CVE-2020-16268 The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair o… Client Mitigation only Fix from $1,9502020-12-29 CRITICAL 10.0 CVE-2020-26282 BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Prox… Browserup Proxy 2.1.2+ Fix from $2,3002020-12-24 MEDIUM 6.1 CVE-2020-35669 An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, … Http after 0.12.2 Fix from $1,6002020-12-24 HIGH 7.8 CVE-2020-35608 A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted … Azure Sphere No fix yet Fix from $1,9502020-12-22 HIGH 8.8 CVE-2020-27687 ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-… Thingsboard 3.2+ Fix from $1,9502020-12-18 HIGH 7.8 CVE-2020-8177 curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file wh… Curl after 7.70.0 Fix from $1,9502020-12-14 HIGH 8.8 CVE-2020-25967 The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability. Fastadmin No fix yet Fix from $1,9502020-12-10 MEDIUM 6.4 CVE-2020-26260 BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit… Bookstack 0.30.5+ Fix from $1,6002020-12-09 HIGH 7.5 CVE-2020-29655 An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaste… Rt Ac88u Firmware 3.1.0.108+ Fix from $1,9502020-12-09 MEDIUM 5.4 CVE-2020-14193 Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF… Automation For Jira 7.1.15+ Fix from $1,6002020-11-30 HIGH 8.1 CVE-2020-26238 Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.… Cron Utils 9.1.3+ Fix from $1,9502020-11-25 CRITICAL 9.8 CVE-2020-13942EPSS 68% It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack ve… Unomi 1.5.2+ Fix from $2,3002020-11-24 MEDIUM 6.1 CVE-2020-26081 Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-sit… Iot Field Network Director 4.6.1+ Fix from $1,6002020-11-18 MEDIUM 6.1 CVE-2020-26884 RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vuln… Archer after 6.8.0.3 Fix from $1,6002020-11-18 MEDIUM 6.1 CVE-2020-27627 JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection. Teamcity 2020.1.2+ Fix from $1,6002020-11-16 HIGH 8.8 CVE-2020-26222 Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java, .NET, Elm and Go. In Depen… Dependabot 0.125.1+ Fix from $1,9502020-11-13 HIGH 7.0 CVE-2020-15238 Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argume… Debian Linux 2.1.4+ Fix from $1,9502020-10-27 HIGH 7.2 CVE-2020-15244 In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to… Magento 20.0.4+ Fix from $1,9502020-10-21 HIGH 7.6 CVE-2020-7749 This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}})… Osm Static Maps Patch available Fix from $1,9502020-10-20 HIGH 7.3 CVE-2020-15255 In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treat… Time Tracker 1.19.23.5325+ Fix from $1,9502020-10-16 HIGH 8.8 CVE-2020-15252 In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet … Xwiki 11.10.6 / 12.5+ Fix from $1,9502020-10-16 MEDIUM 5.3 CVE-2020-25768 Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end … Contao 4.4.52 / 4.9.6+ Fix from $1,6002020-10-07 CRITICAL 9.8 CVE-2020-15227EPSS 34% Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters… Debian Linux 2.0.19 / 2.1.13+ Fix from $2,3002020-10-01 MEDIUM 6.5 CVE-2020-26137 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characte… Urllib3 1.25.9+ Fix from $1,6002020-09-30 CRITICAL 9.8 CVE-2020-21523 A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the… Halo No fix yet Fix from $2,3002020-09-30 HIGH 7.2 CVE-2020-26116EPSS 6% http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker contro… Python 3.5.10 / 3.6.12+ Fix from $1,9502020-09-27 MEDIUM 5.5 CVE-2020-25596 An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves va… Fedora after 4.14.0 Fix from $1,6002020-09-23 HIGH 8.4 CVE-2020-16875EPSS 47% <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who s… Exchange Server Patch available Fix from $1,9502020-09-11