Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Ox App Suite MEDIUM 6.0
CVE-2021-33493

The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Spring Cloud Netflix HIGH 8.8
CVE-2021-22053EPSS 13%

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within th…

Fix: 2.2.10+
Fix from $1,950 2021-11-19
Cron Utils CRITICAL 9.8
CVE-2021-41269

cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A te…

Fix: 9.1.6+
Fix from $2,300 2021-11-15
Tl Wr840n Firmware CRITICAL 9.8
CVE-2021-41653EPSS 76%

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a cr…

Mitigation only
Fix from $2,300 2021-11-13
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2021-33816

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a…

No fix yet
Fix from $2,300 2021-11-10
3d Viewer HIGH 7.8
CVE-2021-43208

3D Viewer Remote Code Execution Vulnerability

Fix: 7.2107.7012.0+
Fix from $1,950 2021-11-10
365 Apps HIGH 7.8
CVE-2021-42296

Microsoft Word Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-11-10
Malware Protection Engine HIGH 7.8
CVE-2021-42298EPSS 5%

Microsoft Defender Remote Code Execution Vulnerability

Fix: 1.1.18700.3+
Fix from $1,950 2021-11-10
Thymeleaf CRITICAL 9.8
CVE-2021-43466

In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.

No fix yet
Fix from $2,300 2021-11-09
Loco Translate MEDIUM 6.5
CVE-2021-24721

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .ph…

Fix: 2.5.4+
Fix from $1,600 2021-11-08
Similar Posts HIGH 7.2
CVE-2021-24537

The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened environment (ie with DISALLO…

Fix: after 3.1.5
Fix from $1,950 2021-11-08
Tensorflow HIGH 7.8
CVE-2021-41228

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is vulnerable to a code injectio…

Fix: 2.4.4 / 2.5.2+
Fix from $1,950 2021-11-05
Obsidian Dataview HIGH 7.8
CVE-2021-42057

Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft …

Fix: after 0.4.11
Fix from $1,950 2021-11-04
Mybb HIGH 7.2
CVE-2021-43281

MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module doe…

Fix: 1.8.29+
Fix from $1,950 2021-11-04
Forticlient MEDIUM 5.0
CVE-2021-42754

An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authen…

Fix: after 6.4.5
Fix from $1,600 2021-11-02
Youphptube HIGH 7.2
CVE-2021-25877

AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag…

Fix: after 10.0
Fix from $1,950 2021-11-01
Uyuni HIGH 8.8
CVE-2021-40348

Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename use…

Patch available
Fix from $1,950 2021-11-01
Unicode HIGH 8.3
CVE-2021-42694

An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce sour…

Fix: 14.0.0+
Fix from $1,950 2021-11-01
Fedora HIGH 8.3
CVE-2021-42574EPSS 12%

An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via …

Fix: 14.0.0+
Fix from $1,950 2021-11-01
Emui HIGH 7.5
CVE-2021-36985

There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the…

Mitigation only
Fix from $1,950 2021-10-28
Enterprise HIGH 7.2
CVE-2021-41619

An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The…

Fix: 2021.1.2+
Fix from $1,950 2021-10-27
Tracer Concierge HIGH 8.8
CVE-2021-38450

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended c…

Fix: 4.4 / 5.5+
Fix from $1,950 2021-10-27
Playable CRITICAL 9.8
CVE-2020-23037

Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web script…

No fix yet
Fix from $2,300 2021-10-22
Glasswire CRITICAL 9.8
CVE-2021-22961

A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in t…

Mitigation only
Fix from $2,300 2021-10-18
Cognos Analytics HIGH 8.8
CVE-2021-29679

IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled inp…

Patch available
Fix from $1,950 2021-10-15
365 Apps HIGH 7.8
CVE-2021-40485

Microsoft Excel Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-10-13
Sharepoint Enterprise Server HIGH 8.1
CVE-2021-40487EPSS 48%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-10-13
Netweaver Application Server Abap CRITICAL 9.8
CVE-2021-40499

Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD,…

Mitigation only
Fix from $2,300 2021-10-12
Editorskit HIGH 8.8
CVE-2021-24546

The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Vis…

Fix: 1.31.6+
Fix from $1,950 2021-10-11
Cmsuno CRITICAL 9.8
CVE-2021-40889

CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents…

No fix yet
Fix from $2,300 2021-10-11