Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.8 CVE-2018-21051 An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trus… Android Mitigation only Fix from $2,3002020-04-08 CRITICAL 9.8 CVE-2017-18652 An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic librari… Android Mitigation only Fix from $2,3002020-04-07 HIGH 7.5 CVE-2020-11593 An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data … Cipace 9.1+ Fix from $1,9502020-04-06 MEDIUM 5.3 CVE-2020-10960 In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user … Mediawiki 1.34.1+ Fix from $1,6002020-04-03 MEDIUM 6.5 CVE-2020-1958 When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali… Druid Mitigation only Fix from $1,6002020-04-01 MEDIUM 6.1 CVE-2020-3884 An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbi… Mac Os X 10.15.4+ Fix from $1,6002020-04-01 MEDIUM 6.1 CVE-2020-11441 phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on a… phpMyAdmin No fix yet Fix from $1,6002020-03-31 HIGH 8.8 CVE-2020-6982 In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution. Win Pak after 4.7.2 Fix from $1,9502020-03-24 CRITICAL 9.8 CVE-2020-7475 A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in… Ecostruxure Control Expert 3.10 / 3.20+ Fix from $2,3002020-03-23 CRITICAL 9.8 CVE-2013-7487 On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to e… Dvr04b Firmware No fix yet Fix from $2,3002020-03-21 MEDIUM 6.1 CVE-2019-18860EPSS 6% Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. Debian Linux 4.9+ Fix from $1,6002020-03-20 MEDIUM 6.1 CVE-2019-12416 we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrat… Deltaspike after 1.9.2 Fix from $1,6002020-03-19 HIGH 8.8 CVE-2020-8468 KEVEPSS 6% Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulne… Apex One Patch available Fix from $1,9502020-03-18 HIGH 7.2 CVE-2019-11073EPSS 6% A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sa… Prtg Network Monitor 19.4.54.1506+ Fix from $1,9502020-03-16 MEDIUM 6.5 CVE-2020-6858 Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a res… Styx after 0.7.10 Fix from $1,6002020-03-12 HIGH 8.6 CVE-2020-5259 In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inje… Dojox 1.11.10 / 1.12.8+ Fix from $1,9502020-03-10 HIGH 7.5 CVE-2019-19614 An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the … Raquest Mitigation only Fix from $1,9502020-03-09 CRITICAL 9.8 CVE-2020-9757EPSS 73% The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers co… Craft Cms 3.3.0+ Fix from $2,3002020-03-04 MEDIUM 6.5 CVE-2020-5249 In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header, an attacker can use a carria… Puma after 4.3.2 Fix from $1,6002020-03-02 HIGH 7.5 CVE-2020-5247 In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newli… Puma after 4.3.2 Fix from $1,9502020-02-28 MEDIUM 5.4 CVE-2020-9382 An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page … Widgets after 1.4.0 Fix from $1,6002020-02-24 HIGH 8.8 CVE-2020-5245 Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service a… Dropwizard Validation 1.3.19 / 2.0.2+ Fix from $1,9502020-02-24 CRITICAL 9.8 CVE-2014-4678EPSS 5% The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi… Ansible 1.6.4+ Fix from $2,3002020-02-20 MEDIUM 6.3 CVE-2019-10792 bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.protot… Bodymen 1.1.1+ Fix from $1,6002020-02-18 MEDIUM 6.3 CVE-2019-10793 dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of Object.prototy… Dot Object 2.1.3+ Fix from $1,6002020-02-18 MEDIUM 6.3 CVE-2019-10794 All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Objec… Component Flatten Patch available Fix from $1,6002020-02-18 MEDIUM 6.3 CVE-2019-10795 undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of Object.prototyp… Undefsafe 2.0.3+ Fix from $1,6002020-02-18 CRITICAL 9.8 CVE-2014-4966 Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which … Ansible 1.6.7+ Fix from $2,3002020-02-18 CRITICAL 9.8 CVE-2014-4967 Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib… Ansible 1.6.7+ Fix from $2,3002020-02-18 CRITICAL 9.1 CVE-2014-7236EPSS 56% Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenable… Twiki after 5.1.4 Fix from $2,3002020-02-17