Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Intellij Idea HIGH 7.7
CVE-2022-29814

In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible

Fix: 2022.1+
Fix from $1,950 2022-04-28
Intellij Idea MEDIUM 6.7
CVE-2022-29815

In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible

Fix: 2022.1+
Fix from $1,600 2022-04-28
Intellij Idea HIGH 7.7
CVE-2022-29819

In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible

Fix: 2022.1+
Fix from $1,950 2022-04-28
Pycharm HIGH 7.7
CVE-2022-29821

In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

Fix: 2022.1+
Fix from $1,950 2022-04-28
Redis HIGH 7.8
CVE-2022-24735

Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Re…

Fix: 6.2.7+
Fix from $1,950 2022-04-27
Codegen CRITICAL 9.8
CVE-2022-24881

Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote…

Fix: 1.0.0+
Fix from $2,300 2022-04-26
Ejs CRITICAL 9.8
CVE-2022-29078EPSS 33%

The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionN…

Patch available
Fix from $2,300 2022-04-25
Ad Injection HIGH 7.2
CVE-2022-0661EPSS 40%

The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privil…

Fix: after 1.2.0.19
Fix from $1,950 2022-04-18
Jai Ext CRITICAL 10.0
CVE-2022-24816 KEVEPSS 99%

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via networ…

Fix: 1.1.22+
Fix from $2,300 2022-04-13
Accessibility HIGH 7.8
CVE-2022-27837

A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to …

Fix: 12.5.3.2 / 13.0.1.1+
Fix from $1,950 2022-04-11
Identity Manager CRITICAL 9.8
CVE-2022-22954 KEVEPSS 100%

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act…

Fix: after 8.2
Fix from $2,300 2022-04-11
Bolt Cms HIGH 8.8
CVE-2021-40219

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side t…

Fix: after 4.2.0
Fix from $1,950 2022-04-11
Itop HIGH 8.8
CVE-2022-24780EPSS 5%

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the…

Fix: 2.7.6+
Fix from $1,950 2022-04-05
Simple Machines Forum HIGH 7.2
CVE-2022-26982EPSS 9%

SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because…

Fix: after 2.1.1
Fix from $1,950 2022-04-05
Confluence Data Center HIGH 8.8
CVE-2021-39114

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arb…

Fix: 6.13.23 / 7.4.11+
Fix from $1,950 2022-04-05
Spring Cloud Function CRITICAL 9.8
CVE-2022-22963 KEVEPSS 100%

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide …

Fix: after 3.2.2
Fix from $2,300 2022-04-01
Spring Framework CRITICAL 9.8
CVE-2022-22965 KEVEPSS 100%

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit …

Fix: 2.1.0 / 5.2.20+
Fix from $2,300 2022-04-01
Controllogix 5580 Firmware HIGH 7.2
CVE-2022-1159

Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation runn…

Mitigation only
Fix from $1,950 2022-04-01
GitLab HIGH 7.5
CVE-2021-39908

In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4…

Fix: 14.2.6 / 14.3.4+
Fix from $1,950 2022-04-01
Bbs HIGH 7.2
CVE-2021-43097

A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrar…

No fix yet
Fix from $1,950 2022-03-28
Genian Nac CRITICAL 10.0
CVE-2021-26622

An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote…

Fix: after 5.0.42.0827
Fix from $2,300 2022-03-25
Chamilo MEDIUM 6.8
CVE-2021-38745

Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a craft…

Patch available
Fix from $1,600 2022-03-21
Dwsurvey CRITICAL 9.8
CVE-2021-39383

DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.

No fix yet
Fix from $2,300 2022-03-20
Taocms CRITICAL 9.8
CVE-2022-25578

taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.

Mitigation only
Fix from $2,300 2022-03-18
Rt430 Firmware HIGH 8.8
CVE-2020-25197

A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A0…

Fix: 08a06+
Fix from $1,950 2022-03-18
Frams\' Fast File Exchange CRITICAL 9.8
CVE-2020-15591

fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).

Fix: 20160919_2+
Fix from $2,300 2022-03-17
Accesslog CRITICAL 9.8
CVE-2022-25760

All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization.…

No fix yet
Fix from $2,300 2022-03-17
Cri O HIGH 8.8
CVE-2022-0811EPSS 19%

A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster th…

Fix: 1.19.6 / 1.20.7+
Fix from $1,950 2022-03-16
Cuppacms CRITICAL 9.8
CVE-2022-25498

CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

No fix yet
Fix from $2,300 2022-03-15
Sqlpad HIGH 7.2
CVE-2022-0944EPSS 9%

Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.

Fix: 6.10.1+
Fix from $1,950 2022-03-15