Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Crowd HIGH 7.2
CVE-2017-18108

The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute…

Fix: 2.10.2+
Fix from $1,950 2019-03-29
Solutions Business Manager CRITICAL 9.8
CVE-2018-19641

Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior t…

Fix: 11.5+
Fix from $2,300 2019-03-27
Mednet CRITICAL 9.8
CVE-2014-5401EPSS 5%

Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthent…

Fix: after 5.8
Fix from $2,300 2019-03-26
Kibana CRITICAL 10.0
CVE-2019-7609 KEVEPSS 95%

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion …

Fix: 5.6.15 / 6.6.1+
Fix from $2,300 2019-03-25
Kibana CRITICAL 9.0
CVE-2019-7610

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securi…

Fix: 5.6.15 / 6.6.1+
Fix from $2,300 2019-03-25
Baigo Sso HIGH 7.2
CVE-2019-10015

baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this co…

Mitigation only
Fix from $1,950 2019-03-24
Morgan CRITICAL 9.8
CVE-2019-5413

An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

Fix: 1.9.1+
Fix from $2,300 2019-03-21
Sdcms CRITICAL 9.8
CVE-2019-9651

An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, res…

No fix yet
Fix from $2,300 2019-03-11
Simple Machines Forum HIGH 8.1
CVE-2013-7468

Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.

No fix yet
Fix from $1,950 2019-03-07
Baigo Cms CRITICAL 9.8
CVE-2019-9227

An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter…

No fix yet
Fix from $2,300 2019-02-28
Irisnet Crypto CRITICAL 9.8
CVE-2019-9115

In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage.

Fix: 1.1.7+
Fix from $2,300 2019-02-25
Thinkphp HIGH 8.8
CVE-2019-9082 KEVEPSS 97%

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefu…

Fix: 3.2.4+
Fix from $1,950 2019-02-24
Usb 3.0 Extensible Host Controller Driver MEDIUM 6.7
CVE-2018-3700

Code injection vulnerability in the installer for Intel(R) USB 3.0 eXtensible Host Controller Driver for Microsoft Windows 7 before version 5.0.4.43v…

Fix: 5.0.4.43v2+
Fix from $1,600 2019-02-18
Jinja2 CRITICAL 9.8
CVE-2019-8341EPSS 45%

An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parame…

No fix yet
Fix from $2,300 2019-02-15
Nibbleblog CRITICAL 9.8
CVE-2019-7719

Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.

No fix yet
Fix from $2,300 2019-02-11
Taocms CRITICAL 9.8
CVE-2019-7720

taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.

Fix: after 2014-05-24
Fix from $2,300 2019-02-11
Frog Cms HIGH 7.2
CVE-2018-20775

admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file …

No fix yet
Fix from $1,950 2019-02-11
Frog Cms HIGH 7.2
CVE-2018-20772

Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.

No fix yet
Fix from $1,950 2019-02-11
Frog Cms HIGH 7.2
CVE-2018-20773

Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.

No fix yet
Fix from $1,950 2019-02-11
Workcentre 3655i Firmware CRITICAL 9.8
CVE-2018-20768

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…

Fix: 073.060.048.15000 / 073.190.048.15000+
Fix from $2,300 2019-02-10
Cim CRITICAL 9.8
CVE-2019-7692

install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file misha…

No fix yet
Fix from $2,300 2019-02-10
Thinkcmf HIGH 8.8
CVE-2019-7580EPSS 10%

ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mish…

No fix yet
Fix from $1,950 2019-02-07
Laquis Scada HIGH 7.8
CVE-2018-19002

LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may …

Fix: 4.1.0.4150+
Fix from $1,950 2019-02-05
Security Identity Manager MEDIUM 6.2
CVE-2019-4038

IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypass…

Fix: after 7.0.1.10
Fix from $1,600 2019-02-04
Thinkcmf CRITICAL 9.8
CVE-2019-6713

app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving port…

Mitigation only
Fix from $2,300 2019-01-23
Cx Supervisor HIGH 8.8
CVE-2018-19011

CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code u…

Fix: after 3.42
Fix from $1,950 2019-01-22
Woocommerce HIGH 8.8
CVE-2017-18356

In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account th…

Fix: 3.2.4+
Fix from $1,950 2019-01-15
Prestashop HIGH 8.8
CVE-2018-20717

In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of …

Fix: 1.7.2.5+
Fix from $1,950 2019-01-15
Bodhi MEDIUM 6.1
CVE-2017-1002152

Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.

Fix: after 2.9.0
Fix from $1,600 2019-01-10
Ip Phone 8800 Series Firmware HIGH 8.8
CVE-2018-0461

A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection a…

Mitigation only
Fix from $1,950 2019-01-10