Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Symfony CRITICAL 9.8
CVE-2019-18889EPSS 33%

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces …

Fix: after 4.3.7
Fix from $2,300 2019-11-21
Ontap Select Deploy Administration Utility CRITICAL 9.8
CVE-2019-5509

ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully e…

Fix: after 2.12.2
Fix from $2,300 2019-11-21
Fedora CRITICAL 9.8
CVE-2019-19010

Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose i…

Fix: 2019.11.09+
Fix from $2,300 2019-11-16
Mega 5 Firmware HIGH 8.1
CVE-2019-15388

The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-ins…

Mitigation only
Fix from $1,950 2019-11-14
Foswiki CRITICAL 9.8
CVE-2013-1666

Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.

Fix: 1.1.8+
Fix from $2,300 2019-11-01
Smart Firewall CRITICAL 10.0
CVE-2018-4031

An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsin…

Mitigation only
Fix from $2,300 2019-10-31
PostgreSQL CRITICAL 9.8
CVE-2019-10211

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected di…

Fix: 9.4.24 / 9.5.19+
Fix from $2,300 2019-10-29
Sagemathcell CRITICAL 9.8
CVE-2019-17526

An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web app…

Patch available
Fix from $2,300 2019-10-18
Qibosoft CRITICAL 9.8
CVE-2019-17613

qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply …

No fix yet
Fix from $2,300 2019-10-15
Zzzphp CRITICAL 9.8
CVE-2019-17408

parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be…

No fix yet
Fix from $2,300 2019-10-14
Endpoint Security MEDIUM 5.3
CVE-2019-3652

Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their mali…

Fix: 10.6.1+
Fix from $1,600 2019-10-09
Centreon Web HIGH 8.8
CVE-2018-21023

getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.

Fix: 2.8.28 / 18.10.5+
Fix from $1,950 2019-10-08
Sugarcrm HIGH 7.2
CVE-2019-17299

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17300

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17301

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17302

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17303

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17304

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17305

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17306

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17307

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17308

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17309

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17310

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sitos Six CRITICAL 9.8
CVE-2019-15746

SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute sy…

Mitigation only
Fix from $2,300 2019-10-07
Vbulletin CRITICAL 9.8
CVE-2019-17132EPSS 12%

vBulletin through 5.5.4 mishandles custom avatars.

Fix: after 5.5.4
Fix from $2,300 2019-10-04
Script Security CRITICAL 9.9
CVE-2019-10431

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constru…

Fix: after 1.64
Fix from $2,300 2019-10-01
Vbulletin CRITICAL 9.8
CVE-2019-16759 KEVEPSS 100%

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

Fix: after 5.5.4
Fix from $2,300 2019-09-24
Goahead HIGH 8.6
CVE-2019-16645EPSS 8%

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostna…

No fix yet
Fix from $1,950 2019-09-20
Adas HIGH 7.2
CVE-2019-15087

An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote …

Patch available
Fix from $1,950 2019-09-20