Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.8 CVE-2018-16491 A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.proto… Node.extend 1.1.7 / 2.0.1+ Fix from $2,3002019-02-01 CRITICAL 9.8 CVE-2018-16492 A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.pro… Extend 2.0.2 / 3.0.2+ Fix from $2,3002019-02-01 CRITICAL 9.8 CVE-2018-16486 A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype. Defaults Deep after 0.2.4 Fix from $2,3002019-02-01 CRITICAL 9.8 CVE-2018-16489 A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functio… Just Extend 4.0.0+ Fix from $2,3002019-02-01 MEDIUM 6.1 CVE-2019-6802 CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI. Pypiserver after 1.2.5 Fix from $1,6002019-01-25 MEDIUM 6.5 CVE-2019-3498 In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Down… Django 1.11.18 / 2.0.10+ Fix from $1,6002019-01-09 MEDIUM 6.1 CVE-2018-16627 panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. Kirby No fix yet Fix from $1,6002018-12-20 CRITICAL 9.8 CVE-2018-1000854 esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (… Esigate after 5.2 Fix from $2,3002018-12-20 HIGH 7.5 CVE-2018-18250 Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation ite… Icinga Web 2 2.6.2+ Fix from $1,9502018-12-17 HIGH 7.8 CVE-2018-20167 Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn… Terminology 1.3.1+ Fix from $1,9502018-12-17 MEDIUM 5.4 CVE-2018-1896 IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-… Connections Patch available Fix from $1,6002018-12-07 MEDIUM 6.1 CVE-2018-18207 Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter. Virtualmin No fix yet Fix from $1,6002018-10-10 CRITICAL 9.8 CVE-2018-16763EPSS 83% FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Cod… Fuel Cms after 1.4.2 Fix from $2,3002018-09-09 MEDIUM 5.4 CVE-2017-1115 IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be exec… Campaign Patch available Fix from $1,6002018-09-07 MEDIUM 6.8 CVE-2018-9062 In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code. E42 80 Firmware 0zcn48ww / 2wcn40ww+ Fix from $1,6002018-07-19 MEDIUM 5.4 CVE-2018-1549 IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could explo… Rational Quality Manager after 6.0.5 Fix from $1,6002018-07-10 CRITICAL 9.8 CVE-2018-4995EPSS 7% Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST inject… Acrobat Dc after 18.011.20038 Fix from $2,3002018-07-09 HIGH 8.8 CVE-2018-0313 A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the managem… Nx Os Mitigation only Fix from $1,9502018-06-21 HIGH 8.8 CVE-2017-7846 It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in th… Enterprise Linux Desktop 52.5.2+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2017-7848 RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2. Enterprise Linux 52.5.2+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-7788 When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content S… Firefox 55.0+ Fix from $2,3002018-06-11 MEDIUM 5.5 CVE-2018-4235 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watch… Apple Tv 4.3.1 / 10.13.5+ Fix from $1,6002018-06-08 MEDIUM 6.1 CVE-2017-16043 Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the… Shout 0.50.0+ Fix from $1,6002018-06-04 HIGH 7.8 CVE-2017-6015 Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may … Factorytalk Activation after 4.00.02 Fix from $1,9502018-05-11 HIGH 8.8 CVE-2017-18266 The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER enviro… Debian Linux 1.1.3+ Fix from $1,9502018-05-10 CRITICAL 9.8 CVE-2016-10498 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205,… Mdm9206 Firmware Mitigation only Fix from $2,3002018-04-18 CRITICAL 9.8 CVE-2014-2294 Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_even… Open Web Analytics 1.5.7+ Fix from $2,3002018-04-17 CRITICAL 9.8 CVE-2017-0372EPSS 11% Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities. Debian Linux after 1.23.15 Fix from $2,3002018-04-13 HIGH 7.8 CVE-2015-1975 The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 3… Tivoli Directory Server Mitigation only Fix from $1,9502018-04-03 HIGH 8.8 CVE-2018-4106 An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" co… Mac Os X 10.13.4+ Fix from $1,9502018-04-03