Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 7.8 CVE-2017-1000052 Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypa… Plug 1.0.4 / 1.1.7+ Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-7459 ntopng before 3.0 allows HTTP Response Splitting. Ntopng after 2.4 Fix from $1,9502017-06-26 HIGH 8.8 CVE-2017-9133 An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in… Backhaul Radios after 2.2.1 Fix from $1,9502017-05-21 HIGH 8.8 CVE-2017-9135 An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, t… Backhaul Radios after 2.2.3 Fix from $1,9502017-05-21 HIGH 8.8 CVE-2017-6031 A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripti… Atvise Scada after 2.5.10 Fix from $1,9502017-05-06 MEDIUM 6.5 CVE-2017-8458 Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indic… Brave Patch available Fix from $1,6002017-05-03 HIGH 8.8 CVE-2017-2140 Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory. Tablacus Explorer after 17.3.30 Fix from $1,9502017-04-28 HIGH 7.4 CVE-2017-3547 Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported vers… Peoplesoft Enterprise Peopletools Patch available Fix from $1,9502017-04-24 CRITICAL 9.8 CVE-2016-1155 HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or … Android Mitigation only Fix from $2,3002017-04-13 HIGH 7.5 CVE-2017-7703 In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was … Wireshark Patch available Fix from $1,9502017-04-12 CRITICAL 9.8 CVE-2017-7239 Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of ser… Ninka after 1.3.0 Fix from $2,3002017-04-10 CRITICAL 9.8 CVE-2015-7264 The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks. Proxygen after 0.32.0 Fix from $2,3002017-04-10 HIGH 7.5 CVE-2015-8258EPSS 9% AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script … Axis Communications Firmware after 5.80.3 Fix from $1,9502017-04-10 HIGH 8.8 CVE-2017-6971EPSS 16% AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, … Ossim after 5.3.6 Fix from $1,9502017-03-22 HIGH 8.8 CVE-2017-5585 OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based co… Documentum Content Server No fix yet Fix from $1,9502017-02-22 HIGH 7.5 CVE-2017-5630EPSS 13% PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al… Pear No fix yet Fix from $1,9502017-02-01 HIGH 8.8 CVE-2015-2180 The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in … Webmail after 1.1 Fix from $1,9502017-01-30 CRITICAL 9.8 CVE-2016-4010EPSS 93% Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serializ… Magento after 2.0.5 Fix from $2,3002017-01-23 MEDIUM 5.4 CVE-2016-5013 In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. Moodle after 2.7.14 Fix from $1,6002017-01-20 CRITICAL 9.8 CVE-2016-10131 system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from f… Codeigniter after 3.1.2 Fix from $2,3002017-01-12 MEDIUM 6.5 CVE-2016-6473 A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2… iOS Mitigation only Fix from $1,6002016-12-14 CRITICAL 9.9 CVE-2016-9832 PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbit… Ace Advanced Business Application Programming No fix yet Fix from $2,3002016-12-10 HIGH 8.8 CVE-2016-5685 Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection. Idrac7 Firmware after 2.30.30.30 Fix from $1,9502016-11-29 HIGH 8.8 CVE-2016-6754 A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote a… Android after 6.0.1 Fix from $1,9502016-11-25 HIGH 7.5 CVE-2016-7125EPSS 6% ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows r… PHP after 5.6.24 Fix from $1,9502016-09-12 MEDIUM 6.1 CVE-2016-5701 setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to condu… phpMyAdmin Patch available Fix from $1,6002016-07-03 HIGH 7.3 CVE-2015-8800 Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers … Symantec Critical System Protection Mitigation only Fix from $1,9502016-06-08 HIGH 8.2 CVE-2016-2204 The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted… Messaging Gateway after 10.6.0 Fix from $1,9502016-04-22 MEDIUM 6.5 CVE-2016-0881 EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection… Documentum Xcp Mitigation only Fix from $1,6002016-02-12 MEDIUM 6.5 CVE-2015-7309EPSS 39% The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbit… Bolt after 2.2.0 Fix from $1,6002015-09-22