Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.8 CVE-2017-18900 An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report. Mattermost Server 3.10.3 / 4.0.4+ Fix from $2,3002020-06-19 HIGH 7.5 CVE-2018-21258 An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command. Mattermost Server 5.1.0+ Fix from $1,9502020-06-19 HIGH 8.8 CVE-2020-13445 In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not r… Liferay Portal Patch available Fix from $1,9502020-06-10 MEDIUM 6.1 CVE-2019-16385 Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an exa… Thinfinity Virtualui after 2.5.17.2 Fix from $1,6002020-06-04 MEDIUM 6.8 CVE-2020-11078 In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body,… Fedora 0.18.0+ Fix from $1,6002020-05-20 MEDIUM 5.3 CVE-2020-5574 HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advance… Movable Type after 7.2.1 Fix from $1,6002020-05-14 HIGH 8.8 CVE-2020-11060EPSS 11% In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited… Glpi 9.4.6+ Fix from $1,9502020-05-12 MEDIUM 6.7 CVE-2020-6245 SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can b… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-05-12 HIGH 7.5 CVE-2020-12790 In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template In… Seomatic 3.2.49+ Fix from $1,9502020-05-11 MEDIUM 6.3 CVE-2020-11056 In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which… Sprout Forms 3.9.0+ Fix from $1,6002020-05-07 MEDIUM 6.5 CVE-2020-12108 /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. Debian Linux 2.1.31+ Fix from $1,6002020-05-06 MEDIUM 6.1 CVE-2020-5336 RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vul… Archer 6.7.0.1+ Fix from $1,6002020-05-04 HIGH 7.5 CVE-2019-13285 CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection. Endpoint Protector No fix yet Fix from $1,9502020-05-04 CRITICAL 9.8 CVE-2020-1961 Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e… Syncope 2.0.15 / 2.1.6+ Fix from $2,3002020-05-04 HIGH 7.5 CVE-2019-12425 Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host Ofbiz Mitigation only Fix from $1,9502020-04-30 HIGH 7.7 CVE-2017-18860 Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110T… Fs752tp Firmware after 6.6.2.6 Fix from $1,9502020-04-29 HIGH 8.8 CVE-2017-18855 NETGEAR WNR854T devices before 1.5.2 are affected by command execution. Wnr854t Firmware 1.5.2+ Fix from $1,9502020-04-29 MEDIUM 6.7 CVE-2017-18856 NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection. Readynas Os Firmware 6.6.1+ Fix from $1,6002020-04-29 MEDIUM 6.7 CVE-2017-18854 NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection. Readynas Os Firmware after 6.6.1 Fix from $1,6002020-04-29 HIGH 8.8 CVE-2018-21208 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, … D6100 Firmware 1.0.0.50 / 1.0.0.57+ Fix from $1,9502020-04-28 HIGH 7.1 CVE-2017-18863 Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP3… Wn604 Firmware 2.0.11 / 3.3.3+ Fix from $1,9502020-04-28 MEDIUM 6.8 CVE-2018-21227 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R6400v2 before 1.0.2.34, R670… D7800 Firmware 1.0.0.62 / 1.0.1.30+ Fix from $1,6002020-04-24 MEDIUM 6.8 CVE-2018-21228 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, EX6100v2 before 1.0.1.50, EX6… D7800 Firmware 1.0.0.110 / 1.0.1.16+ Fix from $1,6002020-04-24 HIGH 8.8 CVE-2017-18735 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, PR2000 before 1.0.0.18… Jr6150 Firmware 1.0.0.18 / 1.0.1.10+ Fix from $1,9502020-04-23 HIGH 8.8 CVE-2017-18736 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10,… Jr6150 Firmware 1.0.1.10 / 1.1.0.48+ Fix from $1,9502020-04-23 HIGH 8.8 CVE-2017-18737 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1… Jnr1010 Firmware 1.0.0.18 / 1.0.1.10+ Fix from $1,9502020-04-23 HIGH 8.8 CVE-2017-18734 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1… Jnr1010 Firmware 1.0.0.18 / 1.0.1.10+ Fix from $1,9502020-04-23 CRITICAL 9.8 CVE-2020-7489 A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Mach… Ecostruxure Machine Expert Patch available Fix from $2,3002020-04-22 MEDIUM 6.8 CVE-2017-18754 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.… Wndr3700 Firmware 1.0.0.58 / 1.0.2.88+ Fix from $1,6002020-04-22 HIGH 8.8 CVE-2018-21123 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, … Wc7500 Firmware 6.5.3.9+ Fix from $1,9502020-04-22