Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 8.8 CVE-2014-5287EPSS 8% A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI… Loadmaster after 7.1-16 Fix from $1,9502020-01-08 HIGH 7.5 CVE-2019-20213 D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnc… Dir 859 Firmware after 3.12b04 Fix from $1,9502020-01-02 CRITICAL 9.8 CVE-2013-7070 The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharac… Monitorix 3.3.1+ Fix from $2,3002019-12-31 HIGH 7.5 CVE-2019-17558 KEVEPSS 99% Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi… Solr 7.7.3 / 8.4.0+ Fix from $1,9502019-12-30 MEDIUM 5.4 CVE-2013-4318 File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory. Feature No fix yet Fix from $1,6002019-12-26 MEDIUM 5.4 CVE-2019-19389 JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. Ktor 1.2.6+ Fix from $1,6002019-12-26 MEDIUM 6.1 CVE-2019-6034 a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in … A Blog Cms 2.8.64 / 2.9.6+ Fix from $1,6002019-12-26 MEDIUM 5.9 CVE-2019-11045EPSS 9% In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them… PHP 5.19.0+ Fix from $1,6002019-12-23 HIGH 8.8 CVE-2019-8792 An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. … Shazam Mitigation only Fix from $1,9502019-12-18 HIGH 7.5 CVE-2019-17123 The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstra… Mail No fix yet Fix from $1,9502019-12-13 MEDIUM 5.4 CVE-2019-1490 A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Serv… Skype For Business Patch available Fix from $1,6002019-12-10 CRITICAL 9.8 CVE-2013-2095 rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection Openshift Origin Controller No fix yet Fix from $2,3002019-12-10 MEDIUM 6.5 CVE-2019-16771 Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary … Armeria 0.97.0+ Fix from $1,6002019-12-06 CRITICAL 9.8 CVE-2013-4486 Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging Zanata after 3.1.2 Fix from $2,3002019-12-03 CRITICAL 9.8 CVE-2011-2717 The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metach… Dhcp6c after 2011-07-25 Fix from $2,3002019-11-27 CRITICAL 9.8 CVE-2019-19330 The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa),… Ubuntu Linux 2.0.10+ Fix from $2,3002019-11-27 MEDIUM 5.3 CVE-2019-16254 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input i… Ruby after 2.6.4 Fix from $1,6002019-11-26 MEDIUM 5.3 CVE-2011-3624 Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Ser… Ruby Mitigation only Fix from $1,6002019-11-26 CRITICAL 9.8 CVE-2014-3700 eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data Edeploy after 1.6.0 Fix from $2,3002019-11-21 HIGH 7.8 CVE-2010-4654 poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. Debian Linux 0.16.3+ Fix from $1,9502019-11-13 CRITICAL 9.8 CVE-2019-8135 A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Sym… Magento 2.2.10 / 2.3.2+ Fix from $2,3002019-11-06 HIGH 7.5 CVE-2010-3668 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl. TYPO3 4.1.14 / 4.2.13+ Fix from $1,9502019-11-04 CRITICAL 9.8 CVE-2005-3056 TWiki allows arbitrary shell command execution via the Include function Twiki Patch available Fix from $2,3002019-11-01 MEDIUM 5.3 CVE-2019-18657 ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function. Clickhouse 19.13.5.44+ Fix from $1,6002019-10-31 HIGH 7.2 CVE-2011-2538 Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to exec… Telepresence Video Communication Server Mitigation only Fix from $1,9502019-10-29 MEDIUM 5.4 CVE-2019-4396 IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of… Cloud Orchestrator after 2.5.0.9 Fix from $1,6002019-10-25 MEDIUM 5.4 CVE-2019-4461 IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. Th… Cloud Orchestrator after 2.5.0.9 Fix from $1,6002019-10-25 MEDIUM 6.1 CVE-2019-18348 An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker co… Python 3.5.10 / 3.6.11+ Fix from $1,6002019-10-23 HIGH 7.5 CVE-2019-17513 An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers l… Ratpack 1.7.5+ Fix from $1,9502019-10-18 CRITICAL 9.8 CVE-2019-9535 A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by provi… Iterm2 after 3.3.5 Fix from $2,3002019-10-09