Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Code42 For Enterprise HIGH 7.0
CVE-2019-11552

Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A p…

Fix: 6.7.5 / 6.8.8+
Fix from $1,950 2019-07-19
Discuz\!ml CRITICAL 9.8
CVE-2019-13956

Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5…

Fix: after 3.4
Fix from $2,300 2019-07-18
Ubuntu Linux CRITICAL 9.8
CVE-2019-9848EPSS 31%

LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. …

Fix: 6.2.5+
Fix from $2,300 2019-07-17
Proclima CRITICAL 9.8
CVE-2019-6823

A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker…

Fix: 8.0.0+
Fix from $2,300 2019-07-15
Diagnostics Agent CRITICAL 9.1
CVE-2019-0330

The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to …

Mitigation only
Fix from $2,300 2019-07-10
Strong Password CRITICAL 9.8
CVE-2019-13354

The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current ver…

Mitigation only
Fix from $2,300 2019-07-08
Central Wifimanager CRITICAL 9.8
CVE-2019-13372EPSS 82%

/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PH…

Fix: after 1.03
Fix from $2,300 2019-07-06
Teamcity MEDIUM 6.1
CVE-2019-12843

A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 201…

Fix: 2018.2.3+
Fix from $1,600 2019-07-03
Teamcity MEDIUM 6.1
CVE-2019-12844

A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.

Fix: 2018.2.3+
Fix from $1,600 2019-07-03
Youtrack Integration CRITICAL 9.8
CVE-2019-10100

In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an…

Fix: 1.8.1.3+
Fix from $2,300 2019-07-03
Curl HIGH 7.8
CVE-2019-5443

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 au…

Fix: after 8.0.17
Fix from $1,950 2019-07-02
Traps MEDIUM 6.3
CVE-2019-1577

Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML.

Fix: after 5.0.5
Fix from $1,600 2019-07-01
Teamwire HIGH 8.1
CVE-2018-17170

Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend…

Fix: 1.9.0+
Fix from $1,950 2019-06-28
Netdata MEDIUM 6.5
CVE-2018-18836

An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client_api_request_v1_data in web/a…

Patch available
Fix from $1,600 2019-06-18
Weather Microserver Firmware HIGH 8.8
CVE-2018-18879

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating sys…

Mitigation only
Fix from $1,950 2019-06-18
Debian Linux HIGH 8.8
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacke…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Pyxdg HIGH 7.5
CVE-2019-12761

A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_…

Fix: 0.26+
Fix from $1,950 2019-06-06
Siteomat HIGH 8.6
CVE-2017-14853

The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct she…

Fix: 6.4.414.122+
Fix from $1,950 2019-06-03
Advanced Bash Scripting Guide CRITICAL 9.8
CVE-2019-9891

The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands …

No fix yet
Fix from $2,300 2019-05-31
Modicon Quantum Firmware CRITICAL 9.1
CVE-2019-6816

In Modicon Quantum all firmware versions, a CWE-94: Code Injection vulnerability could cause an unauthorized firmware modification with possible Deni…

Mitigation only
Fix from $2,300 2019-05-22
Converged Security And Management Engine HIGH 7.8
CVE-2019-0091

Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may …

Fix: 3.1.65 / 4.0.15+
Fix from $1,950 2019-05-17
Oneshield Policy HIGH 8.8
CVE-2019-11642

A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authenticated remote adversaries can…

Fix: 5.1.10+
Fix from $1,950 2019-05-08
Adblock Plus HIGH 8.1
CVE-2019-11593

In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web ser…

Fix: 3.5.2+
Fix from $1,950 2019-04-29
Adblock HIGH 8.1
CVE-2019-11594

In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service…

Fix: 3.45.0+
Fix from $1,950 2019-04-29
Ekiga HIGH 8.8
CVE-2011-1830

Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.

Fix: 3.3.0+
Fix from $1,950 2019-04-22
Soy Cms HIGH 7.2
CVE-2019-11376

SOY CMS v3.0.2 allows remote attackers to execute arbitrary PHP code via a <?php substring in the second text box. NOTE: the vendor indicates that th…

No fix yet
Fix from $1,950 2019-04-20
Nas326 Firmware HIGH 8.8
CVE-2019-10633

An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker t…

Fix: after 5.21
Fix from $1,950 2019-04-09
Teemip HIGH 7.2
CVE-2019-10863EPSS 13%

A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file wi…

Fix: 2.4.0+
Fix from $1,950 2019-04-04
Bootstrap Sass CRITICAL 9.8
CVE-2019-10842

Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker…

No fix yet
Fix from $2,300 2019-04-04
74cms CRITICAL 9.8
CVE-2019-10684

Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Adm…

No fix yet
Fix from $2,300 2019-04-01