Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Jira Server HIGH 7.2
CVE-2019-15001EPSS 11%

The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before…

Fix: 7.6.16 / 7.13.8+
Fix from $1,950 2019-09-19
Webaccess CRITICAL 9.8
CVE-2019-13558

In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote …

Fix: after 8.4.1
Fix from $2,300 2019-09-18
Rsa Identity Governance And Lifecycle HIGH 8.1
CVE-2019-3759

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerab…

No fix yet
Fix from $1,950 2019-09-11
Netweaver Application Server Java HIGH 7.2
CVE-2019-0355

SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6…

Mitigation only
Fix from $1,950 2019-09-10
Profilegrid HIGH 8.8
CVE-2019-15873

The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php reque…

Fix: 2.8.6+
Fix from $1,950 2019-09-03
MongoDB HIGH 7.8
CVE-2019-2390

An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs ship…

Fix: 3.4.22 / 3.6.14+
Fix from $1,950 2019-08-30
Bbpress Move Topics CRITICAL 9.8
CVE-2018-21005

The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.

Fix: 1.1.6+
Fix from $2,300 2019-08-27
Groundhogg HIGH 8.8
CVE-2019-15647

The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.

Fix: 1.3.5+
Fix from $1,950 2019-08-27
Webmin HIGH 8.8
CVE-2019-15642EPSS 35%

rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call.…

Fix: after 1.920
Fix from $1,950 2019-08-26
Google Forms HIGH 7.5
CVE-2018-20988

The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.

Fix: 0.94+
Fix from $1,950 2019-08-22
Oscommerce HIGH 7.2
CVE-2018-18573

osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.…

Mitigation only
Fix from $1,950 2019-08-22
Easy Forms For Mailchimp CRITICAL 9.8
CVE-2019-15318

The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.

Fix: 6.5.3+
Fix from $2,300 2019-08-22
Rest Client CRITICAL 9.8
CVE-2019-15224

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Ver…

Fix: after 1.6.13
Fix from $2,300 2019-08-19
Windows 10 HIGH 7.8
CVE-2019-1157

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully …

Patch available
Fix from $1,950 2019-08-14
Windows 10 HIGH 8.8
CVE-2019-1150EPSS 26%

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succe…

Patch available
Fix from $1,950 2019-08-14
Windows 10 HIGH 7.5
CVE-2019-1057

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exp…

Patch available
Fix from $1,950 2019-08-14
Commerce Cloud HIGH 8.8
CVE-2019-0343

SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject …

Mitigation only
Fix from $1,950 2019-08-14
Events Manager CRITICAL 9.8
CVE-2015-9298

The events-manager plugin before 5.6 for WordPress has code injection.

Fix: 5.6+
Fix from $2,300 2019-08-13
Frappe CRITICAL 9.8
CVE-2019-14965

An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.

Fix: 12.0.4+
Fix from $2,300 2019-08-12
Kuaifancms CRITICAL 9.8
CVE-2019-14746

A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.…

No fix yet
Fix from $2,300 2019-08-07
Cpanel MEDIUM 6.3
CVE-2017-18468

cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).

Fix: 56.0.46 / 58.0.45+
Fix from $1,600 2019-08-05
Magento HIGH 8.8
CVE-2019-7871

A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbit…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Happypoint HIGH 8.1
CVE-2019-9140

When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascrip…

Mitigation only
Fix from $1,950 2019-08-01
Cpanel MEDIUM 6.3
CVE-2018-20931

cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).

Fix: 62.0.42 / 68.0.33+
Fix from $1,600 2019-08-01
Solr HIGH 7.2
CVE-2019-0193 KEVEPSS 84%

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh…

Fix: 7.7.3 / 8.1.2+
Fix from $1,950 2019-08-01
Enterprise Linux Desktop MEDIUM 6.5
CVE-2019-10182

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a vi…

Fix: after 1.7.2
Fix from $1,600 2019-07-31
Dolibarr Erp\/crm HIGH 8.0
CVE-2019-11201

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that th…

No fix yet
Fix from $1,950 2019-07-29
Datagrid CRITICAL 9.8
CVE-2019-14281

The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.

Mitigation only
Fix from $2,300 2019-07-26
Simple Captcha2 CRITICAL 9.8
CVE-2019-14282

The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.

Mitigation only
Fix from $2,300 2019-07-26
Xstream CRITICAL 9.8
CVE-2019-10173EPSS 95%

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has…

Fix: after 8.2.2
Fix from $2,300 2019-07-23