Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Djv CRITICAL 9.8
CVE-2020-28464

This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.

Fix: 2.1.4+
Fix from $2,300 2021-01-04
Zzzphp CRITICAL 9.8
CVE-2020-20298

Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to ex…

No fix yet
Fix from $2,300 2020-12-18
Go HIGH 7.5
CVE-2020-28367

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags speci…

Fix: 1.14.12 / 1.15.5+
Fix from $1,950 2020-11-18
Go HIGH 7.5
CVE-2020-28366

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symb…

Fix: 1.14.12 / 1.15.5+
Fix from $1,950 2020-11-18
Arcsight Logger CRITICAL 9.8
CVE-2020-11851

Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remot…

Fix: 7.1.1+
Fix from $2,300 2020-11-17
Cmsuno HIGH 8.8
CVE-2020-25538EPSS 10%

An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web p…

No fix yet
Fix from $1,950 2020-11-13
Cmsuno HIGH 8.8
CVE-2020-25557EPSS 10%

In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs…

No fix yet
Fix from $1,950 2020-11-13
Sugarcrm CRITICAL 9.8
CVE-2020-7472

An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9…

Fix: 8.0.7 / 9.0.4+
Fix from $2,300 2020-11-12
Teams HIGH 7.8
CVE-2020-17091

Microsoft Teams Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2020-11-11
Vbulletin CRITICAL 9.8
CVE-2020-7373EPSS 45%

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.…

Fix: after 5.6.2
Fix from $2,300 2020-10-30
Mintegraladsdk HIGH 7.1
CVE-2020-7745

This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. …

Fix: 6.6.0.0+
Fix from $1,950 2020-10-19
Xwiki HIGH 8.8
CVE-2020-15252

In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet …

Fix: 11.10.6 / 12.5+
Fix from $1,950 2020-10-16
Cloud Networking Operating System CRITICAL 9.8
CVE-2020-8349

An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ option…

Fix: 10.10.6.0+
Fix from $2,300 2020-10-14
Oauth2 Server HIGH 7.5
CVE-2017-18924

oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is sim…

Fix: after 3.1.1
Fix from $1,950 2020-10-04
Kvm Ip Console Switch G2 Firmware HIGH 8.8
CVE-2020-24628

A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.

Fix: 2.8.3+
Fix from $1,950 2020-10-02
Pluxml CRITICAL 9.8
CVE-2020-18185

class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.

No fix yet
Fix from $2,300 2020-10-02
Openmediavault HIGH 8.8
CVE-2020-26124EPSS 67%

openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, beca…

Fix: 4.1.36 / 5.5.12+
Fix from $1,950 2020-10-02
Debian Linux CRITICAL 9.8
CVE-2020-15227EPSS 34%

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…

Fix: 2.0.19 / 2.1.13+
Fix from $2,300 2020-10-01
Connect Secure HIGH 7.2
CVE-2020-8243 KEVEPSS 91%

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform …

Fix: after 9.0
Fix from $1,950 2020-09-30
Handlebars HIGH 8.1
CVE-2019-20920

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allow…

Fix: 3.0.8 / 4.5.3+
Fix from $1,950 2020-09-30
Fabric Operating System CRITICAL 9.8
CVE-2020-15371

Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation …

Mitigation only
Fix from $2,300 2020-09-25
Pexip Infinity HIGH 7.2
CVE-2019-7177

Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.

Fix: 20.1+
Fix from $1,950 2020-09-25
Ios Xe MEDIUM 6.7
CVE-2020-3513

Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation…

Mitigation only
Fix from $1,600 2020-09-24
Ios Xe MEDIUM 6.7
CVE-2020-3416

Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation…

Mitigation only
Fix from $1,600 2020-09-24
Spamtitan HIGH 8.8
CVE-2020-11803EPSS 8%

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could le…

No fix yet
Fix from $1,950 2020-09-17
Spamtitan HIGH 8.8
CVE-2020-11804EPSS 7%

An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection c…

No fix yet
Fix from $1,950 2020-09-17
Xwiki MEDIUM 6.6
CVE-2020-15171

In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servle…

Fix: 11.10.5 / 12.2.1+
Fix from $1,600 2020-09-10
Abap Platform HIGH 7.2
CVE-2020-6318EPSS 6%

A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of thi…

No fix yet
Fix from $1,950 2020-09-09
Nexpose HIGH 7.8
CVE-2020-7381

In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by a…

Fix: 6.6.40+
Fix from $1,950 2020-09-03
Miller HIGH 8.6
CVE-2020-15167

In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to …

No fix yet
Fix from $1,950 2020-09-02