Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-18900
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.
Mattermost Server
3.10.3 / 4.0.4+
HIGH 7.5
CVE-2018-21258
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.
Mattermost Server
5.1.0+
HIGH 8.8
CVE-2020-13445
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not r…
Liferay Portal
Patch available
MEDIUM 6.1
CVE-2019-16385
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an exa…
Thinfinity Virtualui
after 2.5.17.2
MEDIUM 6.8
CVE-2020-11078
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body,…
Fedora
0.18.0+
MEDIUM 5.3
CVE-2020-5574
HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advance…
Movable Type
after 7.2.1
HIGH 8.8
CVE-2020-11060EPSS 11%
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited…
Glpi
9.4.6+
MEDIUM 6.7
CVE-2020-6245
SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can b…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2020-12790
In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template In…
Seomatic
3.2.49+
MEDIUM 6.3
CVE-2020-11056
In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which…
Sprout Forms
3.9.0+
MEDIUM 6.5
CVE-2020-12108
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
Debian Linux
2.1.31+
MEDIUM 6.1
CVE-2020-5336
RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vul…
Archer
6.7.0.1+
HIGH 7.5
CVE-2019-13285
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
Endpoint Protector
No fix yet
CRITICAL 9.8
CVE-2020-1961
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, e…
Syncope
2.0.15 / 2.1.6+
HIGH 7.5
CVE-2019-12425
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
Ofbiz
Mitigation only
HIGH 7.7
CVE-2017-18860
Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110T…
Fs752tp Firmware
after 6.6.2.6
HIGH 8.8
CVE-2017-18855
NETGEAR WNR854T devices before 1.5.2 are affected by command execution.
Wnr854t Firmware
1.5.2+
MEDIUM 6.7
CVE-2017-18856
NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection.
Readynas Os Firmware
6.6.1+
MEDIUM 6.7
CVE-2017-18854
NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection.
Readynas Os Firmware
after 6.6.1
HIGH 8.8
CVE-2018-21208
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, …
D6100 Firmware
1.0.0.50 / 1.0.0.57+
HIGH 7.1
CVE-2017-18863
Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP3…
Wn604 Firmware
2.0.11 / 3.3.3+
MEDIUM 6.8
CVE-2018-21227
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R6400v2 before 1.0.2.34, R670…
D7800 Firmware
1.0.0.62 / 1.0.1.30+
MEDIUM 6.8
CVE-2018-21228
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, EX6100v2 before 1.0.1.50, EX6…
D7800 Firmware
1.0.0.110 / 1.0.1.16+
HIGH 8.8
CVE-2017-18735
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, PR2000 before 1.0.0.18…
Jr6150 Firmware
1.0.0.18 / 1.0.1.10+
HIGH 8.8
CVE-2017-18736
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10,…
Jr6150 Firmware
1.0.1.10 / 1.1.0.48+
HIGH 8.8
CVE-2017-18737
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1…
Jnr1010 Firmware
1.0.0.18 / 1.0.1.10+
HIGH 8.8
CVE-2017-18734
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1…
Jnr1010 Firmware
1.0.0.18 / 1.0.1.10+
CRITICAL 9.8
CVE-2020-7489
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Mach…
Ecostruxure Machine Expert
Patch available
MEDIUM 6.8
CVE-2017-18754
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.…
Wndr3700 Firmware
1.0.0.58 / 1.0.2.88+
HIGH 8.8
CVE-2018-21123
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, …
Wc7500 Firmware
6.5.3.9+