Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Opensis CRITICAL 9.8
CVE-2020-6143EPSS 6%

A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in ins…

No fix yet
Fix from $2,300 2020-09-01
Opensis CRITICAL 9.8
CVE-2020-6144EPSS 6%

A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in ins…

No fix yet
Fix from $2,300 2020-09-01
Paginator CRITICAL 9.8
CVE-2020-15150

There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to …

Fix: 1.0.0+
Fix from $2,300 2020-09-01
Red Discord Bot HIGH 8.5
CVE-2020-15147

Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users wit…

Fix: after 3.3.11
Fix from $1,950 2020-08-21
Safe Eval CRITICAL 9.8
CVE-2020-7710

This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.

No fix yet
Fix from $2,300 2020-08-21
Zulip Server HIGH 8.8
CVE-2020-15070

Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write…

Fix: 2.1.7+
Fix from $1,950 2020-08-21
Reports CRITICAL 9.8
CVE-2020-15865EPSS 5%

A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the …

No fix yet
Fix from $2,300 2020-08-18
Openapi Python Client CRITICAL 9.0
CVE-2020-15142

In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subs…

Fix: 0.5.3+
Fix from $2,300 2020-08-14
Desigo Consumption Control CRITICAL 9.8
CVE-2020-10055EPSS 6%

A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications …

Patch available
Fix from $2,300 2020-08-14
Desktop HIGH 7.8
CVE-2020-8224

A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.

Fix: 2.6.5+
Fix from $1,950 2020-08-10
Connect Secure HIGH 7.2
CVE-2020-8218 KEVEPSS 32%

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution …

Fix: after 9.0
Fix from $1,950 2020-07-30
Uvicorn HIGH 7.5
CVE-2020-7694

This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever an…

No fix yet
Fix from $1,950 2020-07-27
Mc Works32 CRITICAL 9.1
CVE-2020-12013

A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi El…

Fix: after 10.95.208.31
Fix from $2,300 2020-07-16
Superwebmailer CRITICAL 9.8
CVE-2020-11546EPSS 33%

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticat…

Fix: 7.40.0.01550+
Fix from $2,300 2020-07-14
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8194EPSS 11%

Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SD…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Rails HIGH 8.8
CVE-2020-8163EPSS 82%

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `rend…

Fix: 5.0.1+
Fix from $1,950 2020-07-02
Cloud Cnm Secumanager CRITICAL 9.8
CVE-2020-15348

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python c…

No fix yet
Fix from $2,300 2020-06-26
Mattermost Desktop CRITICAL 9.8
CVE-2016-11064

An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.

Fix: 3.4.0+
Fix from $2,300 2020-06-19
Zenphoto HIGH 8.8
CVE-2020-5593

Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.

Fix: 1.5.7+
Fix from $1,950 2020-06-11
Mosc HIGH 8.6
CVE-2020-7672

mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, result…

Fix: after 1.0.0
Fix from $1,950 2020-06-10
Node Extend CRITICAL 9.8
CVE-2020-7673

node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` l…

Fix: after 0.2.0
Fix from $2,300 2020-06-10
Access Policy CRITICAL 9.8
CVE-2020-7674

access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` funct…

Fix: after 3.1.0
Fix from $2,300 2020-06-10
Cd Messenger CRITICAL 9.8
CVE-2020-7675

cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function re…

Fix: after 2.7.26
Fix from $2,300 2020-06-10
Talk CRITICAL 9.9
CVE-2020-8180

A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an adminis…

Fix: 6.0.5 / 7.0.3+
Fix from $2,300 2020-06-08
Kibana HIGH 8.8
CVE-2020-7012EPSS 18%

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privile…

Fix: after 7.6.2
Fix from $1,950 2020-06-03
Kibana HIGH 7.2
CVE-2020-7013

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualiza…

Fix: 6.8.9 / 7.7.0+
Fix from $1,950 2020-06-03
Php Css Parser CRITICAL 9.8
CVE-2020-13756EPSS 55%

Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or g…

Fix: 8.3.1+
Fix from $2,300 2020-06-03
Node Dns Sync CRITICAL 9.8
CVE-2020-11079

node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client o…

Fix: 0.2.1+
Fix from $2,300 2020-05-28
Video Insight Vms CRITICAL 9.8
CVE-2019-5997

Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.

Fix: after 7.5
Fix from $2,300 2020-05-20
Open Edx Platform HIGH 8.8
CVE-2020-13144EPSS 11%

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new…

No fix yet
Fix from $1,950 2020-05-18