Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Voipmonitor CRITICAL 9.8
CVE-2021-30461EPSS 37%

A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR v…

Fix: 24.61+
Fix from $2,300 2021-05-29
Debian Linux HIGH 8.8
CVE-2021-29505EPSS 77%

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attack…

Fix: 1.4.17+
Fix from $1,950 2021-05-28
Xwiki HIGH 8.8
CVE-2021-32621

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 12.6.7 and 12.10.3, a u…

Fix: 12.6.7 / 12.10.3+
Fix from $1,950 2021-05-28
Connect Secure HIGH 8.8
CVE-2021-22894 KEVEPSS 41%

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th…

Mitigation only
Fix from $1,950 2021-05-27
Connect Secure HIGH 7.2
CVE-2021-22900 KEVEPSS 14%

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to pe…

Fix: after 9.1
Fix from $1,950 2021-05-27
Fusion HIGH 8.8
CVE-2020-28905EPSS 26%

Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.

Fix: after 4.1.8
Fix from $1,950 2021-05-24
Qibosoft HIGH 7.2
CVE-2021-27811

A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exp…

No fix yet
Fix from $1,950 2021-05-21
Rabbitmq Server HIGH 7.8
CVE-2021-22117

RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient loc…

Fix: 3.8.16+
Fix from $1,950 2021-05-18
Moodle MEDIUM 6.1
CVE-2019-14827

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustach…

Fix: after 3.7.1
Fix from $1,600 2021-05-17
Express Handlebars MEDIUM 6.8
CVE-2021-32817

express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express rend…

Fix: after 5.3.2
Fix from $1,600 2021-05-14
Express Handlebars HIGH 8.6
CVE-2021-32820EPSS 18%

Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the…

Fix: after 5.3.2
Fix from $1,950 2021-05-14
Exchange Server HIGH 7.8
CVE-2021-31198

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-05-11
Sharepoint Enterprise Server HIGH 8.8
CVE-2021-31181EPSS 30%

Microsoft SharePoint Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-05-11
Netweaver Application Server Abap MEDIUM 6.7
CVE-2021-27611

SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when…

Mitigation only
Fix from $1,600 2021-05-11
Warnsystem MEDIUM 6.5
CVE-2021-29502

WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to access sensible informations…

Fix: 1.3.18+
Fix from $1,600 2021-05-10
Kennnyshiwa Cogs HIGH 8.8
CVE-2021-29493

Kennnyshiwa-cogs contains cogs for Red Discordbot. An RCE exploit has been found in the Tickets module of kennnyshiwa-cogs. This exploit allows disco…

Fix: 2021-05-05+
Fix from $1,950 2021-05-06
Language Tools HIGH 7.8
CVE-2021-21415

Prisma VS Code a VSCode extension for Prisma schema files. This is a Remote Code Execution Vulnerability that affects all versions of the Prisma VS C…

Fix: 2.20.0+
Fix from $1,950 2021-04-29
Debian Linux HIGH 8.8
CVE-2021-29472

Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitize…

Fix: 1.10.22 / 2.0.13+
Fix from $1,950 2021-04-27
Hedgedoc CRITICAL 10.0
CVE-2021-29475

HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file sys…

Fix: 1.5.0+
Fix from $2,300 2021-04-26
Debian Linux HIGH 7.8
CVE-2021-22204 KEVEPSS 100%

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malici…

Fix: 12.24+
Fix from $1,950 2021-04-23
GitLab CRITICAL 10.0
CVE-2021-22205 KEVEPSS 100%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were pass…

Fix: 13.8.8 / 13.9.6+
Fix from $2,300 2021-04-23
Discord Recon CRITICAL 9.8
CVE-2021-29465

Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability in which a remote attacker is …

Fix: 0.0.4+
Fix from $2,300 2021-04-22
Discord Recon HIGH 8.8
CVE-2021-29461

Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in Discord Recon Server prior to…

Mitigation only
Fix from $1,950 2021-04-20
Grav HIGH 7.2
CVE-2021-29440EPSS 31%

Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or…

Fix: 1.7.11+
Fix from $1,950 2021-04-13
Intelligent Power Manager CRITICAL 10.0
CVE-2021-23281

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanit…

Fix: 1.69+
Fix from $2,300 2021-04-13
Commerce CRITICAL 9.9
CVE-2021-27602

SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are transl…

Mitigation only
Fix from $2,300 2021-04-13
Intelligent Power Manager CRITICAL 10.0
CVE-2021-23277

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize c…

Fix: 1.68 / 1.69+
Fix from $2,300 2021-04-13
Discord Recon HIGH 8.8
CVE-2021-21433

Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution in version 0.0.1 would allow…

Fix: 0.0.2+
Fix from $1,950 2021-04-09
Prime License Manager HIGH 8.8
CVE-2021-1362

A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Ci…

Fix: 11.5 / 12.5+
Fix from $1,950 2021-04-08
Wp Super Cache HIGH 7.2
CVE-2021-24209EPSS 24%

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure a…

Fix: 1.7.2+
Fix from $1,950 2021-04-05