Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Antivirus \+ Security CRITICAL 9.8
CVE-2018-3608

A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attack…

Fix: after 12.0.1191
Fix from $2,300 2018-07-06
Rational Quality Manager MEDIUM 5.4
CVE-2017-1242

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…

Fix: after 6.0.5
Fix from $1,600 2018-07-06
Rational Quality Manager MEDIUM 6.1
CVE-2017-1248

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…

Fix: after 6.0.5
Fix from $1,600 2018-07-06
Rational Quality Manager MEDIUM 5.4
CVE-2017-1329

IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe…

Fix: after 6.0.5
Fix from $1,600 2018-07-06
Devscripts CRITICAL 9.8
CVE-2018-13043

scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co…

Fix: after 2.18.3
Fix from $2,300 2018-07-01
Onefilecms HIGH 8.8
CVE-2018-12994

onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen.

Fix: after 2012-04-14
Fix from $1,950 2018-06-29
Onefilecms HIGH 8.8
CVE-2018-12995

onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.

Fix: after 2012-04-14
Fix from $1,950 2018-06-29
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7465

It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …

Mitigation only
Fix from $2,300 2018-06-27
Centreon CRITICAL 9.8
CVE-2018-11587

There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.ph…

Patch available
Fix from $2,300 2018-06-25
Metinfo CRITICAL 9.8
CVE-2018-12531

An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulne…

No fix yet
Fix from $2,300 2018-06-18
Mcafee Threat Intelligence Exchange CRITICAL 9.8
CVE-2017-3907

Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows…

Mitigation only
Fix from $2,300 2018-06-13
Debian Linux HIGH 8.8
CVE-2018-5158EPSS 10%

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF fil…

Fix: 52.8.0 / 60.0+
Fix from $1,950 2018-06-11
Debian Linux HIGH 8.8
CVE-2017-7798

The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, t…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11
Pe Razor Server CRITICAL 9.8
CVE-2018-6512

The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet …

Fix: 1.9.0.0 / 2018.1.1+
Fix from $2,300 2018-06-11
Crestron Toolbox Protocol Firmware CRITICAL 9.8
CVE-2018-11228EPSS 7%

Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code executio…

Fix: 2.001.0037.001+
Fix from $2,300 2018-06-08
Electron CRITICAL 9.8
CVE-2017-16151

Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent …

Fix: 1.7.8+
Fix from $2,300 2018-06-07
Dns Sync CRITICAL 9.8
CVE-2017-16100EPSS 5%

dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.

Fix: after 0.1.1
Fix from $2,300 2018-06-07
Pg CRITICAL 9.8
CVE-2017-16082EPSS 11%

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. The…

Fix: 2.11.2 / 3.6.4+
Fix from $2,300 2018-06-07
Growl CRITICAL 9.8
CVE-2017-16042

Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitra…

Fix: 1.10.2+
Fix from $2,300 2018-06-04
Summit CRITICAL 9.8
CVE-2017-16020

Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands …

Fix: after 0.1.21
Fix from $2,300 2018-06-04
1288h V5 Firmware HIGH 8.8
CVE-2018-7950

The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validatio…

Mitigation only
Fix from $1,950 2018-06-01
1288h V5 Firmware HIGH 8.8
CVE-2018-7951

The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validatio…

Mitigation only
Fix from $1,950 2018-06-01
Shell Quote CRITICAL 9.8
CVE-2016-10541

The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend o…

Fix: 1.6.1+
Fix from $2,300 2018-05-31
Pouchdb CRITICAL 9.8
CVE-2016-10546

An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design docu…

Fix: after 6.0.4
Fix from $2,300 2018-05-31
Reduce Css Calc MEDIUM 6.1
CVE-2016-10548

Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on t…

Fix: after 1.2.4
Fix from $1,600 2018-05-31
Remarkable MEDIUM 6.1
CVE-2014-10065

Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascri…

Fix: 1.4.1+
Fix from $1,600 2018-05-31
Moodle HIGH 8.8
CVE-2018-1133EPSS 32%

An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval…

Fix: after 3.4.2
Fix from $1,950 2018-05-25
Spring Security Oauth CRITICAL 9.8
CVE-2018-1260EPSS 8%

Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contai…

Fix: after 2.3.2
Fix from $2,300 2018-05-11
Maxdb Odbc Driver CRITICAL 9.8
CVE-2018-2418

SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could th…

Fix: 7.9.09.07+
Fix from $2,300 2018-05-09
Axublog CRITICAL 9.8
CVE-2018-10740

Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php f…

No fix yet
Fix from $2,300 2018-05-04