Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.7 CVE-2022-29814 In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible Intellij Idea 2022.1+ Fix from $1,9502022-04-28 MEDIUM 6.7 CVE-2022-29815 In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible Intellij Idea 2022.1+ Fix from $1,6002022-04-28 HIGH 7.7 CVE-2022-29819 In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible Intellij Idea 2022.1+ Fix from $1,9502022-04-28 HIGH 7.7 CVE-2022-29821 In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible Pycharm 2022.1+ Fix from $1,9502022-04-28 HIGH 7.8 CVE-2022-24735 Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Re… Redis 6.2.7+ Fix from $1,9502022-04-27 CRITICAL 9.8 CVE-2022-24881 Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote… Codegen 1.0.0+ Fix from $2,3002022-04-26 CRITICAL 9.8 CVE-2022-29078EPSS 33% The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionN… Ejs Patch available Fix from $2,3002022-04-25 HIGH 7.2 CVE-2022-0661EPSS 40% The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privil… Ad Injection after 1.2.0.19 Fix from $1,9502022-04-18 CRITICAL 10.0 CVE-2022-24816 KEVEPSS 99% JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via networ… Jai Ext 1.1.22+ Fix from $2,3002022-04-13 HIGH 7.8 CVE-2022-27837 A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to … Accessibility 12.5.3.2 / 13.0.1.1+ Fix from $1,9502022-04-11 CRITICAL 9.8 CVE-2022-22954 KEVEPSS 100% VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act… Identity Manager after 8.2 Fix from $2,3002022-04-11 HIGH 8.8 CVE-2021-40219 Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side t… Bolt Cms after 4.2.0 Fix from $1,9502022-04-11 HIGH 8.8 CVE-2022-24780EPSS 5% Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the… Itop 2.7.6+ Fix from $1,9502022-04-05 HIGH 7.2 CVE-2022-26982EPSS 9% SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because… Simple Machines Forum after 2.1.1 Fix from $1,9502022-04-05 HIGH 8.8 CVE-2021-39114 Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arb… Confluence Data Center 6.13.23 / 7.4.11+ Fix from $1,9502022-04-05 CRITICAL 9.8 CVE-2022-22963 KEVEPSS 100% In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide … Spring Cloud Function after 3.2.2 Fix from $2,3002022-04-01 CRITICAL 9.8 CVE-2022-22965 KEVEPSS 100% A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit … Spring Framework 2.1.0 / 5.2.20+ Fix from $2,3002022-04-01 HIGH 7.2 CVE-2022-1159 Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation runn… Controllogix 5580 Firmware Mitigation only Fix from $1,9502022-04-01 HIGH 7.5 CVE-2021-39908 In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4… GitLab 14.2.6 / 14.3.4+ Fix from $1,9502022-04-01 HIGH 7.2 CVE-2021-43097 A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrar… Bbs No fix yet Fix from $1,9502022-03-28 CRITICAL 10.0 CVE-2021-26622 An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote… Genian Nac after 5.0.42.0827 Fix from $2,3002022-03-25 MEDIUM 6.8 CVE-2021-38745 Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a craft… Chamilo Patch available Fix from $1,6002022-03-21 CRITICAL 9.8 CVE-2021-39383 DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. Dwsurvey No fix yet Fix from $2,3002022-03-20 CRITICAL 9.8 CVE-2022-25578 taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file. Taocms Mitigation only Fix from $2,3002022-03-18 HIGH 8.8 CVE-2020-25197 A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A0… Rt430 Firmware 08a06+ Fix from $1,9502022-03-18 CRITICAL 9.8 CVE-2020-15591 fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution). Frams\' Fast File Exchange 20160919_2+ Fix from $2,3002022-03-17 CRITICAL 9.8 CVE-2022-25760 All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization.… Accesslog No fix yet Fix from $2,3002022-03-17 HIGH 8.8 CVE-2022-0811EPSS 19% A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster th… Cri O 1.19.6 / 1.20.7+ Fix from $1,9502022-03-16 CRITICAL 9.8 CVE-2022-25498 CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php. Cuppacms No fix yet Fix from $2,3002022-03-15 HIGH 7.2 CVE-2022-0944EPSS 9% Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1. Sqlpad 6.10.1+ Fix from $1,9502022-03-15