Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Pdf Image CRITICAL 9.8
CVE-2020-8132

Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based …

Fix: after 2.0.0
Fix from $2,300 2020-02-28
Online Weather CRITICAL 9.8
CVE-2020-9406

IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.

Fix: 4.3.5+
Fix from $2,300 2020-02-26
Insync HIGH 7.8
CVE-2019-4000

Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to exe…

No fix yet
Fix from $1,950 2020-02-25
Fedora CRITICAL 9.8
CVE-2020-8518EPSS 72%

Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.

No fix yet
Fix from $2,300 2020-02-17
Script Manager CRITICAL 9.8
CVE-2020-8129

An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.

Fix: after 0.8.6
Fix from $2,300 2020-02-14
Openx CRITICAL 9.8
CVE-2013-4211EPSS 71%

A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malici…

No fix yet
Fix from $2,300 2020-02-14
Restful Web Services HIGH 8.8
CVE-2013-4225

The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity wri…

Fix: 7.x-1.4 / 7.x-2.1+
Fix from $1,950 2020-02-11
Debian Linux HIGH 8.1
CVE-2020-5529

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can …

Fix: 2.37.0+
Fix from $1,950 2020-02-11
Omniauth Weibo Oauth2 CRITICAL 9.8
CVE-2019-17268

The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions …

Patch available
Fix from $2,300 2020-02-07
Playsms CRITICAL 9.8
CVE-2020-8644 KEVEPSS 87%

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

Fix: 1.4.3+
Fix from $2,300 2020-02-05
Fudforum HIGH 7.2
CVE-2013-2267EPSS 9%

PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.

Mitigation only
Fix from $1,950 2020-01-27
Hot Formula Parser CRITICAL 9.8
CVE-2020-6836

grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanit…

Fix: 3.0.1+
Fix from $2,300 2020-01-11
Exec Maven CRITICAL 9.8
CVE-2019-20343

The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin elem…

Mitigation only
Fix from $2,300 2020-01-06
Contract Lifecycle Management HIGH 8.8
CVE-2019-20155

An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may exe…

No fix yet
Fix from $1,950 2020-01-05
Mongo Express CRITICAL 9.9
CVE-2019-10758 KEVEPSS 85%

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to pe…

Fix: 0.54.0+
Fix from $2,300 2019-12-24
Open Journal System HIGH 8.8
CVE-2019-19909

An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injectio…

Fix: 3.1.2-2+
Fix from $1,950 2019-12-19
Sma 100 Firmware HIGH 8.8
CVE-2019-7486

Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA10…

Fix: after 9.0.0.4
Fix from $1,950 2019-12-19
Node Df CRITICAL 9.8
CVE-2019-15597

A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.

Mitigation only
Fix from $2,300 2019-12-18
Treekill CRITICAL 9.8
CVE-2019-15598

A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

Mitigation only
Fix from $2,300 2019-12-18
Tree Kill CRITICAL 9.8
CVE-2019-15599

A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

Mitigation only
Fix from $2,300 2019-12-18
Planning Analytics CRITICAL 9.8
CVE-2019-4716 KEVEPSS 86%

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and th…

Fix: after 2.0.8
Fix from $2,300 2019-12-18
Phpfastcache CRITICAL 9.8
CVE-2019-16774

In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.

Fix: 5.0.13+
Fix from $2,300 2019-12-12
Safer Eval CRITICAL 9.8
CVE-2019-10769

safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to A…

No fix yet
Fix from $2,300 2019-12-06
Okaycms CRITICAL 9.8
CVE-2019-16885

In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. Thi…

Fix: after 2.3.4
Fix from $2,300 2019-12-03
Webadvisor MEDIUM 6.5
CVE-2019-3665

Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the br…

Fix: 4.1.1.48+
Fix from $1,600 2019-12-03
Image Uploader And Browser For Ckeditor CRITICAL 9.8
CVE-2019-19502

Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP…

Fix: 4.1.9+
Fix from $2,300 2019-12-02
Fedora HIGH 8.8
CVE-2019-14867EPSS 7%

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the interna…

Fix: 4.6.7 / 4.7.4+
Fix from $1,950 2019-11-27
Ruby HIGH 8.1
CVE-2019-16255

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[]…

Fix: after 2.6.4
Fix from $1,950 2019-11-26
Chrome MEDIUM 6.1
CVE-2019-13714

Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS…

Fix: 78.0.3904.70+
Fix from $1,600 2019-11-25
Zxcdn Iamweb Firmware HIGH 7.2
CVE-2019-3427

The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inj…

Mitigation only
Fix from $1,950 2019-11-22