Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2014-5287EPSS 8%
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI…
Loadmaster
after 7.1-16
HIGH 7.5
CVE-2019-20213
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnc…
Dir 859 Firmware
after 3.12b04
CRITICAL 9.8
CVE-2013-7070
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharac…
Monitorix
3.3.1+
HIGH 7.5
CVE-2019-17558 KEVEPSS 99%
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provi…
Solr
7.7.3 / 8.4.0+
MEDIUM 5.4
CVE-2013-4318
File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory.
Feature
No fix yet
MEDIUM 5.4
CVE-2019-19389
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
Ktor
1.2.6+
MEDIUM 6.1
CVE-2019-6034
a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in …
A Blog Cms
2.8.64 / 2.9.6+
MEDIUM 5.9
CVE-2019-11045EPSS 9%
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them…
PHP
5.19.0+
HIGH 8.8
CVE-2019-8792
An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. …
Shazam
Mitigation only
HIGH 7.5
CVE-2019-17123
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstra…
Mail
No fix yet
MEDIUM 5.4
CVE-2019-1490
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Serv…
Skype For Business
Patch available
CRITICAL 9.8
CVE-2013-2095
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection
Openshift Origin Controller
No fix yet
MEDIUM 6.5
CVE-2019-16771
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary …
Armeria
0.97.0+
CRITICAL 9.8
CVE-2013-4486
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
Zanata
after 3.1.2
CRITICAL 9.8
CVE-2011-2717
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metach…
Dhcp6c
after 2011-07-25
CRITICAL 9.8
CVE-2019-19330
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa),…
Ubuntu Linux
2.0.10+
MEDIUM 5.3
CVE-2019-16254
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input i…
Ruby
after 2.6.4
MEDIUM 5.3
CVE-2011-3624
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Ser…
Ruby
Mitigation only
CRITICAL 9.8
CVE-2014-3700
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
Edeploy
after 1.6.0
HIGH 7.8
CVE-2010-4654
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
Debian Linux
0.16.3+
CRITICAL 9.8
CVE-2019-8135
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Sym…
Magento
2.2.10 / 2.3.2+
HIGH 7.5
CVE-2010-3668
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.
TYPO3
4.1.14 / 4.2.13+
CRITICAL 9.8
CVE-2005-3056
TWiki allows arbitrary shell command execution via the Include function
Twiki
Patch available
MEDIUM 5.3
CVE-2019-18657
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
Clickhouse
19.13.5.44+
HIGH 7.2
CVE-2011-2538
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to exec…
Telepresence Video Communication Server
Mitigation only
MEDIUM 5.4
CVE-2019-4396
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of…
Cloud Orchestrator
after 2.5.0.9
MEDIUM 5.4
CVE-2019-4461
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. Th…
Cloud Orchestrator
after 2.5.0.9
MEDIUM 6.1
CVE-2019-18348
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker co…
Python
3.5.10 / 3.6.11+
HIGH 7.5
CVE-2019-17513
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers l…
Ratpack
1.7.5+
CRITICAL 9.8
CVE-2019-9535
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by provi…
Iterm2
after 3.3.5