Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Fedora MEDIUM 5.4
CVE-2021-32809

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](htt…

Fix: 4.16.2 / 21.1.4+
Fix from $1,600 2021-08-12
Contao HIGH 7.2
CVE-2021-37626

Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files …

Fix: 4.4.56 / 4.9.18+
Fix from $1,950 2021-08-11
Java Spring Cloud Stream Template HIGH 7.8
CVE-2021-37694

@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection …

Fix: 0.7.0+
Fix from $1,950 2021-08-11
Better Macro CRITICAL 9.8
CVE-2021-38196

An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitr…

Fix: after 2021-07-22
Fix from $2,300 2021-08-08
Akaunting CRITICAL 9.1
CVE-2021-36800

Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/…

Fix: 2.1.13+
Fix from $2,300 2021-08-04
Pi Hole HIGH 8.8
CVE-2021-32706EPSS 60%

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface ve…

Fix: 5.5.1+
Fix from $1,950 2021-08-04
Openplc V3 Firmware HIGH 8.8
CVE-2021-31630EPSS 27%

Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/har…

No fix yet
Fix from $1,950 2021-08-03
Speed Booster Pack HIGH 7.2
CVE-2021-24430

The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_qu…

Fix: 4.2.0+
Fix from $1,950 2021-08-02
Data Center HIGH 8.8
CVE-2017-18113

The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system admi…

Fix: 8.18.1+
Fix from $1,950 2021-08-02
Bridge CRITICAL 9.8
CVE-2020-18172

A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.

No fix yet
Fix from $2,300 2021-07-26
Bludit HIGH 7.8
CVE-2021-25808

A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.

No fix yet
Fix from $1,950 2021-07-23
Firepower Device Manager On Box HIGH 8.8
CVE-2021-1518

A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbi…

Fix: 6.4.0 / 6.7.0.2+
Fix from $1,950 2021-07-22
Manageiq HIGH 8.8
CVE-2021-32756

ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module o…

Mitigation only
Fix from $1,950 2021-07-21
Fedora HIGH 8.1
CVE-2021-32749

fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0…

Fix: 0.10.7 / 0.11.3+
Fix from $1,950 2021-07-16
Netweaver Application Server Abap MEDIUM 6.5
CVE-2021-33678

A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75…

No fix yet
Fix from $1,600 2021-07-14
Total4 CRITICAL 9.8
CVE-2021-23390

The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

Fix: 0.0.43+
Fix from $2,300 2021-07-12
Total.js CRITICAL 9.8
CVE-2021-23389

The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

Fix: 3.4.9+
Fix from $2,300 2021-07-12
Adaptive Security Device Manager HIGH 8.1
CVE-2021-1585EPSS 20%

A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary co…

Fix: 7.18.1.152+
Fix from $1,950 2021-07-08
Monstra Cms HIGH 8.8
CVE-2020-23219

Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" …

No fix yet
Fix from $1,950 2021-07-01
Narou CRITICAL 9.8
CVE-2021-35514

Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.

Fix: 3.8.0+
Fix from $2,300 2021-06-28
Phpwcms CRITICAL 9.8
CVE-2020-21784

phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

No fix yet
Fix from $2,300 2021-06-24
Phpcms HIGH 8.8
CVE-2020-22201

phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.

No fix yet
Fix from $1,950 2021-06-16
Android MEDIUM 5.5
CVE-2021-25415

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writ…

Mitigation only
Fix from $1,600 2021-06-11
Android MEDIUM 6.5
CVE-2021-25416

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel…

Mitigation only
Fix from $1,600 2021-06-11
Android MEDIUM 5.5
CVE-2021-25393

Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system ui…

No fix yet
Fix from $1,600 2021-06-11
365 Apps HIGH 7.3
CVE-2021-31949

Microsoft Outlook Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-06-08
Reg Keygen Git Hash CRITICAL 9.8
CVE-2021-32673

reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin throu…

Fix: after 0.10.15
Fix from $2,300 2021-06-08
Emui HIGH 7.5
CVE-2021-22336

There is an Improper Control of Generation of Code vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause denial…

Mitigation only
Fix from $1,950 2021-06-03
Ips Community Suite HIGH 8.8
CVE-2021-32924EPSS 20%

Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages…

Fix: 4.6.0+
Fix from $1,950 2021-06-01
Wp Super Cache HIGH 7.2
CVE-2021-24312

The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of …

Fix: 1.7.3+
Fix from $1,950 2021-06-01