Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Prestashop CRITICAL 9.8
CVE-2022-21686

PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig c…

Fix: after 1.7.8.3
Fix from $2,300 2022-01-26
Jpress HIGH 8.8
CVE-2021-46114

jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which atta…

Mitigation only
Fix from $1,950 2022-01-26
Jpress HIGH 7.2
CVE-2021-46118

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a functio…

No fix yet
Fix from $1,950 2022-01-26
Jpress HIGH 7.2
CVE-2021-46117

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through …

No fix yet
Fix from $1,950 2022-01-26
Nginx Controller Api Management MEDIUM 5.4
CVE-2022-23008

On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed AP…

Fix: 3.19.1+
Fix from $1,600 2022-01-25
Shenyu CRITICAL 9.8
CVE-2021-45029EPSS 6%

Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Mitigation only
Fix from $2,300 2022-01-25
Mustache HIGH 8.8
CVE-2022-0323

Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

Fix: 2.14.1+
Fix from $1,950 2022-01-21
Deep Security Agent HIGH 7.8
CVE-2022-23120EPSS 6%

A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an att…

Fix: 20.0.0-3445+
Fix from $1,950 2022-01-20
B2236 Firmware CRITICAL 9.8
CVE-2021-44734EPSS 6%

Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the …

No fix yet
Fix from $2,300 2022-01-20
Code42 HIGH 8.8
CVE-2021-43269

In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) fil…

Fix: 8.8.0+
Fix from $1,950 2022-01-20
October HIGH 8.8
CVE-2021-32649

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…

Fix: 1.0.473 / 1.1.6+
Fix from $1,950 2022-01-14
October HIGH 8.8
CVE-2021-32650

October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an att…

Patch available
Fix from $1,950 2022-01-14
Commcell HIGH 8.8
CVE-2021-34994EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…

Mitigation only
Fix from $1,950 2022-01-13
Jpress HIGH 8.8
CVE-2021-45806

jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.

Mitigation only
Fix from $1,950 2022-01-13
Lens HIGH 7.8
CVE-2021-23154

In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed…

Fix: after 5.3.3
Fix from $1,950 2022-01-10
Bixby Routines HIGH 7.1
CVE-2022-22286

A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers t…

Fix: 2.6.30.5 / 3.1.21.8+
Fix from $1,950 2022-01-10
Reminder HIGH 7.1
CVE-2022-22285

A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to…

Fix: 12.2.05.0 / 12.3.02.1000+
Fix from $1,950 2022-01-10
Harmonyos CRITICAL 9.8
CVE-2021-39979

HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.

Fix: 2.0+
Fix from $2,300 2022-01-03
Thinkcmf CRITICAL 9.8
CVE-2020-20601EPSS 8%

An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

No fix yet
Fix from $2,300 2021-12-22
Laravel Filemanager HIGH 8.8
CVE-2021-23814

This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type wh…

Mitigation only
Fix from $1,950 2021-12-17
Vault Cli CRITICAL 9.1
CVE-2021-43837EPSS 5%

vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli fea…

Fix: 3.0.0+
Fix from $2,300 2021-12-16
Sharepoint Enterprise Server HIGH 8.8
CVE-2021-42309

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-12-15
Abap Platform CRITICAL 9.8
CVE-2021-44231

Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t…

Mitigation only
Fix from $2,300 2021-12-14
Sockeye HIGH 7.8
CVE-2021-43811

Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data c…

Fix: 2.3.24+
Fix from $1,950 2021-12-08
Endpoint Manager Cloud Services Appliance CRITICAL 9.8
CVE-2021-44529 KEVEPSS 99%

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited…

Fix: after 4.5
Fix from $2,300 2021-12-08
Harmonyos HIGH 7.5
CVE-2021-37097

There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.

Fix: 2.0+
Fix from $1,950 2021-12-08
Harmonyos CRITICAL 9.1
CVE-2021-37079

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary fi…

Fix: 2.0+
Fix from $2,300 2021-12-07
Mq Appliance MEDIUM 6.7
CVE-2021-38967

IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.

Patch available
Fix from $1,600 2021-11-30
Oh My Zsh HIGH 8.8
CVE-2021-3725

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt…

Fix: 11-11-2021+
Fix from $1,950 2021-11-30
Symbio 700 HIGH 7.6
CVE-2021-38448

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended c…

Fix: 1.00.0023 / 1.10.0010+
Fix from $1,950 2021-11-22