Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Logkitty CRITICAL 9.8
CVE-2020-8149

Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.

Fix: 0.7.1+
Fix from $2,300 2020-05-15
Xwiki HIGH 8.8
CVE-2020-11057

In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while edi…

Fix: after 11.10.2
Fix from $1,950 2020-05-12
Adaptive Server Enterprise Backup Server HIGH 7.2
CVE-2020-6248

SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while execut…

Mitigation only
Fix from $1,950 2020-05-12
Application Server HIGH 8.8
CVE-2020-6262

Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows …

Mitigation only
Fix from $1,950 2020-05-12
Adaptive Server Enterprise HIGH 8.8
CVE-2020-6243

Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks …

Mitigation only
Fix from $1,950 2020-05-12
Yale Wipc 301w Firmware CRITICAL 9.8
CVE-2020-10176

ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.

Fix: 2.x.2.43+
Fix from $2,300 2020-05-07
Sprout Forms MEDIUM 6.3
CVE-2020-11056

In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which…

Fix: 3.9.0+
Fix from $1,600 2020-05-07
Node Rules CRITICAL 9.8
CVE-2020-7609

node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled b…

Fix: 5.0.0+
Fix from $2,300 2020-04-27
Gxp1610 Firmware HIGH 8.8
CVE-2020-5739EPSS 5%

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up s…

Fix: after 1.0.4.152
Fix from $1,950 2020-04-14
Esoms MEDIUM 6.1
CVE-2019-19089

For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be i…

Fix: after 6.0.3
Fix from $1,600 2020-04-02
Command Client CRITICAL 9.8
CVE-2019-9163

The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML ob…

Fix: 2.7.2+
Fix from $2,300 2020-04-01
Alienform2 CRITICAL 9.8
CVE-2020-10948EPSS 7%

Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a differen…

No fix yet
Fix from $2,300 2020-04-01
Cutenews HIGH 8.8
CVE-2020-5558

CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.

No fix yet
Fix from $1,950 2020-03-25
Mailform CRITICAL 9.8
CVE-2020-5553

mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.

No fix yet
Fix from $2,300 2020-03-25
Ansible HIGH 7.1
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a …

Fix: 2.7.17 / 2.8.9+
Fix from $1,950 2020-03-24
Andover Continuum 9680 Firmware CRITICAL 9.8
CVE-2020-7480

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files…

Mitigation only
Fix from $2,300 2020-03-23
Ups Companion HIGH 8.8
CVE-2020-6650

UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code …

Fix: after 1.05
Fix from $1,950 2020-03-23
Desktop MEDIUM 6.7
CVE-2020-8140

A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set i…

Fix: 2.6.3+
Fix from $1,600 2020-03-20
Blamer CRITICAL 9.8
CVE-2020-8137

Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.

Fix: 1.0.1+
Fix from $2,300 2020-03-20
Phpbb HIGH 7.5
CVE-2019-16108

phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.

Patch available
Fix from $1,950 2020-03-20
Emc Data Protection Advisor HIGH 7.2
CVE-2019-18582

Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side t…

Mitigation only
Fix from $1,950 2020-03-18
Codiad CRITICAL 9.8
CVE-2019-19208EPSS 19%

Codiad Web IDE through 2.8.4 allows PHP Code injection.

Fix: after 2.8.4
Fix from $2,300 2020-03-16
Dot HIGH 8.8
CVE-2020-8141

The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they …

No fix yet
Fix from $1,950 2020-03-15
Phpkb HIGH 7.2
CVE-2020-10389

admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any PO…

No fix yet
Fix from $1,950 2020-03-12
Fat Free Framework CRITICAL 9.8
CVE-2020-5203

In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GE…

Patch available
Fix from $2,300 2020-03-11
Debian Linux HIGH 7.7
CVE-2020-5258

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to in…

Fix: 1.11.10 / 1.12.8+
Fix from $1,950 2020-03-10
Dojox HIGH 8.6
CVE-2020-5259

In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inje…

Fix: 1.11.10 / 1.12.8+
Fix from $1,950 2020-03-10
Addons CRITICAL 9.8
CVE-2020-10257EPSS 9%

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for P…

Fix: 1.0.1 / 1.0.1.2001+
Fix from $2,300 2020-03-10
Miui Firmware MEDIUM 6.5
CVE-2020-9530

An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of…

Mitigation only
Fix from $1,600 2020-03-06
Pcp HIGH 7.8
CVE-2019-3695

A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Lin…

Fix: 3.11.9-5.8.1 / 3.11.9-6.14.1+
Fix from $1,950 2020-03-03