Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 6.1 CVE-2018-1319 In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted… Allura after 1.8.0 Fix from $1,6002018-03-15 CRITICAL 9.8 CVE-2018-6220EPSS 10% An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to… Email Encryption Gateway Patch available Fix from $2,3002018-03-15 HIGH 8.1 CVE-2018-1000130EPSS 73% A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on th… Webarchive Agent Mitigation only Fix from $1,9502018-03-14 CRITICAL 9.8 CVE-2015-5377EPSS 14% Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI app… Elasticsearch 1.6.1+ Fix from $2,3002018-03-06 MEDIUM 5.9 CVE-2017-10963 In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker c… Knox Enterprise Mobility Management Mitigation only Fix from $1,6002018-02-20 HIGH 8.8 CVE-2017-5799EPSS 15% A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (… Opencall Media Platform 3.4.2 / 4.4.7+ Fix from $1,9502018-02-15 HIGH 7.5 CVE-2018-7032 webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attack… Myrepos after 1.20171231 Fix from $1,9502018-02-14 MEDIUM 6.1 CVE-2018-6603 Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript cod… Webpam Proe Mitigation only Fix from $1,6002018-02-07 CRITICAL 9.8 CVE-2018-6289EPSS 7% Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1. Secure Mail Gateway No fix yet Fix from $2,3002018-02-06 HIGH 7.5 CVE-2018-6519 The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for… Debian Linux 1.10.4 / 2.3.5+ Fix from $1,9502018-02-02 HIGH 7.5 CVE-2017-14523EPSS 8% WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that e… Wondercms No fix yet Fix from $1,9502018-01-26 MEDIUM 5.5 CVE-2017-18049 In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and … Silverstripe after 3.6.2 Fix from $1,6002018-01-23 CRITICAL 9.8 CVE-2017-14094EPSS 19% A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command executio… Smart Protection Server after 3.2 Fix from $2,3002018-01-19 HIGH 7.8 CVE-2014-7952 The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveragi… Android No fix yet Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2017-15714 The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code … Ofbiz No fix yet Fix from $2,3002018-01-04 CRITICAL 9.8 CVE-2017-1000493 Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover Rocket.chat after 0.59 Fix from $2,3002018-01-03 CRITICAL 9.8 CVE-2017-1000453 CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execu… Cms Made Simple 2.2+ Fix from $2,3002018-01-02 HIGH 7.8 CVE-2017-1000454 CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and l… Cms Made Simple 2.2+ Fix from $1,9502018-01-02 MEDIUM 5.5 CVE-2016-3695 The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause … Linux Kernel Patch available Fix from $1,6002017-12-29 HIGH 8.8 CVE-2017-15313 Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious CSV expression to the affecte… Smartcare Mitigation only Fix from $1,9502017-12-22 MEDIUM 6.5 CVE-2017-16766 An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows loc… Diskstation Manager 6.0.3-8754-6 / 6.1.4-15217+ Fix from $1,6002017-12-22 CRITICAL 9.8 CVE-2017-17790EPSS 6% The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by… Ruby after 2.4.2 Fix from $2,3002017-12-20 HIGH 8.8 CVE-2017-17531 gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow… Global Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17532 examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable,… Kiwi Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17533 default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow re… Tkabber Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17534 uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow… Mensis Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17535 lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which mig… Gjots2 Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17511 KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attac… Debian Linux Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17513 TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow rem… Tex Live after 20170524 Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17514 boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote … Debian Linux Mitigation only Fix from $1,9502017-12-14