Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Deno Standard Modules CRITICAL 9.8
CVE-2021-42139

Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.

Fix: 0.107.0+
Fix from $2,300 2021-10-11
Myucms HIGH 8.8
CVE-2020-21650

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() meth…

No fix yet
Fix from $1,950 2021-10-06
Myucms CRITICAL 9.8
CVE-2020-21651

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() metho…

No fix yet
Fix from $2,300 2021-10-06
Myucms CRITICAL 9.8
CVE-2020-21652

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() me…

No fix yet
Fix from $2,300 2021-10-06
Android HIGH 7.9
CVE-2021-25470

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

Mitigation only
Fix from $1,950 2021-10-06
Slo Generator HIGH 7.8
CVE-2021-22557

SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera…

Fix: 2.0.1+
Fix from $1,950 2021-10-04
Cobbler CRITICAL 9.8
CVE-2021-40323EPSS 87%

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

Fix: after 3.3.0
Fix from $2,300 2021-10-04
Wuzhicms HIGH 8.8
CVE-2020-20124

Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.

No fix yet
Fix from $1,950 2021-09-28
Unifi Talk HIGH 8.8
CVE-2021-22952

A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequen…

Fix: after 1.12.3
Fix from $1,950 2021-09-23
Ansible Automation Platform HIGH 7.1
CVE-2021-3583

A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i…

Fix: 2.9.23 / 3.7.0+
Fix from $1,950 2021-09-22
Maianaffiliate HIGH 7.2
CVE-2021-39402

MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate m…

No fix yet
Fix from $1,950 2021-09-20
Jira Data Center HIGH 7.2
CVE-2021-39128

Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators acc…

Fix: 8.13.12 / 8.19.1+
Fix from $1,950 2021-09-16
Cloud Connector MEDIUM 6.8
CVE-2021-33693

SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potenti…

Patch available
Fix from $1,600 2021-09-15
Playsms CRITICAL 9.8
CVE-2021-40373

playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that …

Fix: 1.4.5+
Fix from $2,300 2021-09-10
Zstack HIGH 8.1
CVE-2021-32836

ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserializat…

Fix: 3.10.12 / 4.1.6+
Fix from $1,950 2021-09-09
Keti CRITICAL 9.9
CVE-2021-32834

Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy…

No fix yet
Fix from $2,300 2021-09-09
Phpmywind HIGH 7.2
CVE-2021-39503

PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker ca…

No fix yet
Fix from $1,950 2021-09-07
Jira Service Desk HIGH 7.2
CVE-2021-39115

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arb…

Fix: 4.13.9 / 4.18.0+
Fix from $1,950 2021-09-01
Total.js HIGH 7.2
CVE-2021-32831

Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django …

Fix: 3.4.9+
Fix from $1,950 2021-08-30
Api Connect CRITICAL 9.8
CVE-2021-29772

IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.

Fix: after 5.0.8.11
Fix from $2,300 2021-08-26
Zzcms HIGH 7.2
CVE-2020-19822

A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" an…

No fix yet
Fix from $1,950 2021-08-26
Binderhub CRITICAL 9.8
CVE-2021-39159

BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In a…

Fix: 0.2.0-n653+
Fix from $2,300 2021-08-25
Nbgitpuller HIGH 8.8
CVE-2021-39160

nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted li…

Fix: 0.10.2+
Fix from $1,950 2021-08-25
Opensysusers CRITICAL 9.8
CVE-2021-40084

opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execut…

Fix: after 0.6
Fix from $2,300 2021-08-25
Debian Linux HIGH 8.5
CVE-2021-39144 KEVEPSS 98%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Imcat HIGH 8.8
CVE-2020-22120

A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitr…

Patch available
Fix from $1,950 2021-08-18
Empirecms CRITICAL 9.8
CVE-2020-22937

A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to th…

No fix yet
Fix from $2,300 2021-08-17
Smart Camera C2e Firmware MEDIUM 6.8
CVE-2021-3615

A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card…

Fix: 01.03.29.16+
Fix from $1,600 2021-08-17
Rest Api CRITICAL 9.9
CVE-2021-32829

ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networki…

Fix: 3.8.21 / 3.10.8+
Fix from $2,300 2021-08-17
Hbs MEDIUM 5.3
CVE-2021-32822

The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnera…

No fix yet
Fix from $1,600 2021-08-16