Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 7.8 CVE-2019-4558 A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4… Spectrum Scale after 5.0.3.2 Fix from $1,9502019-10-09 MEDIUM 6.1 CVE-2019-15259 A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response s… Unified Contact Center Express 11.6+ Fix from $1,6002019-10-02 HIGH 7.5 CVE-2019-17068 PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content. Putty 0.73+ Fix from $1,9502019-10-01 MEDIUM 6.1 CVE-2019-16532 An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections. Yzmcms No fix yet Fix from $1,6002019-09-26 HIGH 8.1 CVE-2019-11277 Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authentic… Cf Deployment 1.7.11 / 2.3.0+ Fix from $1,9502019-09-23 CRITICAL 9.8 CVE-2017-18634 The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. Newspaper 6.7.2+ Fix from $2,3002019-09-16 MEDIUM 6.1 CVE-2019-5314 Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able t… Arubaos 6.4.4.20 / 6.5.4.11+ Fix from $1,6002019-09-13 CRITICAL 9.8 CVE-2019-10074 An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This … Ofbiz after 16.11.05 Fix from $2,3002019-09-11 CRITICAL 9.8 CVE-2017-18605 The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. Gravitate Qa Tracker after 1.2.1 Fix from $2,3002019-09-10 HIGH 7.5 CVE-2017-18604 The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. Sitebuilder Dynamic Components after 1.0 Fix from $1,9502019-09-10 HIGH 8.8 CVE-2019-12463 An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/gr… Librenms 1.53+ Fix from $1,9502019-09-09 CRITICAL 9.8 CVE-2019-10665 An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes… Librenms after 1.47 Fix from $2,3002019-09-09 HIGH 8.8 CVE-2019-1939 A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affec… Webex Teams 3.0.12427.0+ Fix from $1,9502019-09-05 MEDIUM 6.1 CVE-2014-10386 The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. Live Chat 4.1.0+ Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2014-10391 The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. Wp Support Plus Responsive Ticket System 4.1+ Fix from $1,6002019-08-22 MEDIUM 6.1 CVE-2014-10394 The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header. Rich Counter 1.2.0+ Fix from $1,6002019-08-22 CRITICAL 9.8 CVE-2017-18583 The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection. Post Pay Counter 2.731+ Fix from $2,3002019-08-22 CRITICAL 9.8 CVE-2019-11581 KEVEPSS 85% There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. A… Jira Server 7.6.14 / 7.13.5+ Fix from $2,3002019-08-09 HIGH 8.8 CVE-2019-5404 A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. 3par Storeserv Management Console 3.5.0.1+ Fix from $1,9502019-08-09 HIGH 8.8 CVE-2016-10801 cPanel before 58.0.4 has improper session handling for shared users (SEC-139). Cpanel 11.54.0.26 / 56.0.27+ Fix from $1,9502019-08-07 MEDIUM 6.5 CVE-2019-7889 An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magen… Magento 1.9.4.2 / 1.14.4.2+ Fix from $1,6002019-08-02 HIGH 7.2 CVE-2017-18386 cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313). Cpanel 62.0.35 / 64.0.42+ Fix from $1,9502019-08-02 HIGH 7.2 CVE-2017-18387 cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314). Cpanel 62.0.35 / 64.0.42+ Fix from $1,9502019-08-02 MEDIUM 6.3 CVE-2017-18389 cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318). Cpanel 64.0.42 / 66.0.34+ Fix from $1,6002019-08-02 HIGH 8.1 CVE-2016-10845 cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78). Cpanel 11.48.5.2 / 11.50.4.3+ Fix from $1,9502019-08-01 HIGH 8.1 CVE-2016-10847 cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80). Cpanel 11.48.5.2 / 11.50.4.3+ Fix from $1,9502019-08-01 HIGH 7.3 CVE-2018-20914 In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). Cpanel 70.0.23+ Fix from $1,9502019-08-01 MEDIUM 5.3 CVE-2018-20885 cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). Cpanel 74.0.0+ Fix from $1,6002019-08-01 MEDIUM 6.1 CVE-2019-1020006 invenio-app before 1.1.1 allows host header injection. Invenio App 1.1.1+ Fix from $1,6002019-07-29 HIGH 8.3 CVE-2019-9811 As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser fea… Firefox 60.8 / 68.0+ Fix from $1,9502019-07-23