Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Open Build Service HIGH 8.8
CVE-2011-3178

In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e…

Fix: 2.3.0+
Fix from $1,950 2018-03-20
Yzmcms HIGH 7.2
CVE-2018-8756

Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in t…

No fix yet
Fix from $1,950 2018-03-18
Dewesoft CRITICAL 9.8
CVE-2018-7756EPSS 61%

RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remo…

No fix yet
Fix from $2,300 2018-03-15
Connect Onsite CRITICAL 9.8
CVE-2018-5779

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …

Mitigation only
Fix from $2,300 2018-03-14
Connect Onsite CRITICAL 9.8
CVE-2018-5780

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …

Mitigation only
Fix from $2,300 2018-03-14
Connect Onsite CRITICAL 9.8
CVE-2018-5781

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …

Mitigation only
Fix from $2,300 2018-03-14
Connect Onsite CRITICAL 9.8
CVE-2018-5782EPSS 19%

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …

No fix yet
Fix from $2,300 2018-03-14
Eve CRITICAL 9.8
CVE-2018-8097EPSS 6%

io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.

Fix: 0.7.5+
Fix from $2,300 2018-03-14
Pybitmessage HIGH 8.8
CVE-2018-1000070

Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnera…

Patch available
Fix from $1,950 2018-03-13
Testlink HIGH 7.5
CVE-2018-7466EPSS 6%

install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES da…

Fix: after 1.9.16
Fix from $1,950 2018-02-25
Ucmdb Configuration Manager CRITICAL 9.8
CVE-2018-6488

Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to all…

Mitigation only
Fix from $2,300 2018-02-22
Metinfo HIGH 8.1
CVE-2018-7271

An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering i…

No fix yet
Fix from $1,950 2018-02-21
Soapui HIGH 7.8
CVE-2017-16670

The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL pro…

No fix yet
Fix from $1,950 2018-02-19
Typesetter HIGH 8.8
CVE-2018-6889EPSS 7%

An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the …

No fix yet
Fix from $1,950 2018-02-12
Go HIGH 7.8
CVE-2018-6574EPSS 8%

Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, …

Fix: after 1.8.6
Fix from $1,950 2018-02-07
Junos CRITICAL 9.8
CVE-2018-0007

An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may…

Mitigation only
Fix from $2,300 2018-01-10
Netweaver HIGH 8.8
CVE-2018-2363

SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrar…

Fix: after 7.52
Fix from $1,950 2018-01-09
Tinycards HIGH 8.1
CVE-2017-16905

The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and conseq…

Fix: 1.0+
Fix from $1,950 2018-01-05
Smarty CRITICAL 9.8
CVE-2017-1000480

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize t…

Fix: 3.1.32+
Fix from $2,300 2018-01-03
Gps Tracking Software CRITICAL 9.8
CVE-2017-17098EPSS 7%

The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary …

Fix: after 3.0
Fix from $2,300 2018-01-02
Readymade Video Sharing Script MEDIUM 6.1
CVE-2017-17649

Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.

No fix yet
Fix from $1,600 2017-12-18
Netweaver Internet Transaction Server HIGH 7.2
CVE-2017-16682

SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administra…

Fix: after 7.52
Fix from $1,950 2017-12-12
Puppet Agent CRITICAL 9.8
CVE-2016-5713

Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to …

Fix: 1.6.0+
Fix from $2,300 2017-12-06
Matrix HIGH 8.8
CVE-2017-14198

An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause…

Fix: after 5.3.6.0
Fix from $1,950 2017-11-30
Math.js CRITICAL 9.8
CVE-2017-1001002

math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could resu…

Fix: after 3.17.0
Fix from $2,300 2017-11-27
Typed Function HIGH 8.8
CVE-2017-1001004

typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name cou…

Fix: 0.10.6+
Fix from $1,950 2017-11-27
Debian Linux HIGH 8.8
CVE-2017-16664

Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In t…

Fix: 3.3.20 / 4.0.26+
Fix from $1,950 2017-11-21
Debian Linux HIGH 8.8
CVE-2017-16544EPSS 6%

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames i…

Fix: after 1.27.2
Fix from $1,950 2017-11-20
Securimage MEDIUM 6.1
CVE-2017-14077

HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_US…

Fix: after 3.6.4
Fix from $1,600 2017-11-18
Updraftplus HIGH 8.1
CVE-2017-16871

The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/upd…

Fix: after 1.13.12
Fix from $1,950 2017-11-17