Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Debian Linux HIGH 7.2
CVE-2021-23358

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template fu…

Fix: 1.12.1 / 1.13.0-2+
Fix from $1,950 2021-03-29
Reason Dr60 Firmware HIGH 8.8
CVE-2021-27438

The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Re…

Fix: 02a04.1+
Fix from $1,950 2021-03-25
Activemq CRITICAL 9.9
CVE-2021-21345EPSS 72%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
MariaDB HIGH 7.2
CVE-2021-27928EPSS 38%

A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percon…

Fix: 10.2.37 / 10.3.28+
Fix from $1,950 2021-03-19
Expressionengine HIGH 8.8
CVE-2021-27230

ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to wri…

Fix: 5.4.2 / 6.0.3+
Fix from $1,950 2021-03-15
Linux Kernel MEDIUM 6.7
CVE-2021-3411

A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linki…

Fix: 5.10+
Fix from $1,600 2021-03-09
Manufacturing Integration And Intelligence HIGH 8.8
CVE-2021-21480EPSS 51%

SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a r…

No fix yet
Fix from $1,950 2021-03-09
Xmlhttprequest HIGH 8.1
CVE-2020-28502

This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=Fal…

Fix: 1.7.0+
Fix from $1,950 2021-03-05
Total.js CRITICAL 9.8
CVE-2021-23344

The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.

Fix: 3.4.8+
Fix from $2,300 2021-03-04
Pug CRITICAL 9.0
CVE-2021-21353

Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty…

Fix: 2.0.3 / 3.0.1+
Fix from $2,300 2021-03-03
Fedora CRITICAL 9.8
CVE-2021-25283EPSS 11%

An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2021-02-27
Nagios Xi HIGH 7.2
CVE-2021-3273EPSS 7%

Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must ha…

Fix: 5.7+
Fix from $1,950 2021-02-25
Debian Linux CRITICAL 9.8
CVE-2021-26120EPSS 82%

Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.

Fix: 3.1.39+
Fix from $2,300 2021-02-22
74cms CRITICAL 9.8
CVE-2020-35339

In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Comm…

No fix yet
Fix from $2,300 2021-02-17
Batflat HIGH 7.2
CVE-2020-35734EPSS 7%

Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the …

No fix yet
Fix from $1,950 2021-02-15
Active Iq Unified Manager HIGH 7.2
CVE-2021-23337EPSS 21%

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Fix: 4.17.21+
Fix from $1,950 2021-02-15
Antivirus\+ Security 2020 HIGH 7.2
CVE-2021-25251

The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker t…

Mitigation only
Fix from $1,950 2021-02-10
Inoerp CRITICAL 9.8
CVE-2020-28870

In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalizati…

No fix yet
Fix from $2,300 2021-02-10
Commerce CRITICAL 9.9
CVE-2021-21477EPSS 30%

SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attack…

Mitigation only
Fix from $2,300 2021-02-09
Smartfoxserver HIGH 8.8
CVE-2021-26551

An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by…

No fix yet
Fix from $1,950 2021-02-09
Carrierwave HIGH 8.8
CVE-2021-21305EPSS 13%

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions…

Fix: 1.3.2 / 2.1.1+
Fix from $1,950 2021-02-08
Youtrack CRITICAL 9.8
CVE-2021-25770

In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.

Fix: 2020.5.3123+
Fix from $2,300 2021-02-03
Angular Expressions HIGH 8.8
CVE-2021-21277

angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2…

Fix: 1.1.2+
Fix from $1,950 2021-02-01
Quick.cart HIGH 7.2
CVE-2020-35754EPSS 10%

OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via …

Fix: 6.7+
Fix from $1,950 2021-01-28
Moodle HIGH 7.2
CVE-2021-20187

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts v…

Fix: 3.5.16 / 3.8.7+
Fix from $1,950 2021-01-28
Onedev HIGH 8.8
CVE-2021-21248

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. I…

Fix: 4.0.3+
Fix from $1,950 2021-01-15
Onedev CRITICAL 9.8
CVE-2021-21244

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injectio…

Fix: 4.0.3+
Fix from $2,300 2021-01-15
Business Warehouse HIGH 8.8
CVE-2021-21466

SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to …

No fix yet
Fix from $1,950 2021-01-12
Cockpit CRITICAL 9.8
CVE-2020-35131EPSS 51%

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/…

Fix: 0.6.1+
Fix from $2,300 2021-01-08
Secure Mail MEDIUM 6.5
CVE-2020-8274

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated acce…

Fix: 20.11.0+
Fix from $1,600 2021-01-06