Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2021-42139 Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. Deno Standard Modules 0.107.0+ Fix from $2,3002021-10-11 HIGH 8.8 CVE-2020-21650 Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() meth… Myucms No fix yet Fix from $1,9502021-10-06 CRITICAL 9.8 CVE-2020-21651 Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() metho… Myucms No fix yet Fix from $2,3002021-10-06 CRITICAL 9.8 CVE-2020-21652 Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() me… Myucms No fix yet Fix from $2,3002021-10-06 HIGH 7.9 CVE-2021-25470 An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE. Android Mitigation only Fix from $1,9502021-10-06 HIGH 7.8 CVE-2021-22557 SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Genera… Slo Generator 2.0.1+ Fix from $1,9502021-10-04 CRITICAL 9.8 CVE-2021-40323EPSS 87% Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection. Cobbler after 3.3.0 Fix from $2,3002021-10-04 HIGH 8.8 CVE-2020-20124 Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php. Wuzhicms No fix yet Fix from $1,9502021-09-28 HIGH 8.8 CVE-2021-22952 A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequen… Unifi Talk after 1.12.3 Fix from $1,9502021-09-23 HIGH 7.1 CVE-2021-3583 A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i… Ansible Automation Platform 2.9.23 / 3.7.0+ Fix from $1,9502021-09-22 HIGH 7.2 CVE-2021-39402 MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate m… Maianaffiliate No fix yet Fix from $1,9502021-09-20 HIGH 7.2 CVE-2021-39128 Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators acc… Jira Data Center 8.13.12 / 8.19.1+ Fix from $1,9502021-09-16 MEDIUM 6.8 CVE-2021-33693 SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potenti… Cloud Connector Patch available Fix from $1,6002021-09-15 CRITICAL 9.8 CVE-2021-40373 playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that … Playsms 1.4.5+ Fix from $2,3002021-09-10 HIGH 8.1 CVE-2021-32836 ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserializat… Zstack 3.10.12 / 4.1.6+ Fix from $1,9502021-09-09 CRITICAL 9.9 CVE-2021-32834 Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy… Keti No fix yet Fix from $2,3002021-09-09 HIGH 7.2 CVE-2021-39503 PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker ca… Phpmywind No fix yet Fix from $1,9502021-09-07 HIGH 7.2 CVE-2021-39115 Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arb… Jira Service Desk 4.13.9 / 4.18.0+ Fix from $1,9502021-09-01 HIGH 7.2 CVE-2021-32831 Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django … Total.js 3.4.9+ Fix from $1,9502021-08-30 CRITICAL 9.8 CVE-2021-29772 IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774. Api Connect after 5.0.8.11 Fix from $2,3002021-08-26 HIGH 7.2 CVE-2020-19822 A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" an… Zzcms No fix yet Fix from $1,9502021-08-26 CRITICAL 9.8 CVE-2021-39159 BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In a… Binderhub 0.2.0-n653+ Fix from $2,3002021-08-25 HIGH 8.8 CVE-2021-39160 nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted li… Nbgitpuller 0.10.2+ Fix from $1,9502021-08-25 CRITICAL 9.8 CVE-2021-40084 opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execut… Opensysusers after 0.6 Fix from $2,3002021-08-25 HIGH 8.5 CVE-2021-39144 KEVEPSS 98% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.8 CVE-2020-22120 A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitr… Imcat Patch available Fix from $1,9502021-08-18 CRITICAL 9.8 CVE-2020-22937 A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to th… Empirecms No fix yet Fix from $2,3002021-08-17 MEDIUM 6.8 CVE-2021-3615 A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card… Smart Camera C2e Firmware 01.03.29.16+ Fix from $1,6002021-08-17 CRITICAL 9.9 CVE-2021-32829 ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networki… Rest Api 3.8.21 / 3.10.8+ Fix from $2,3002021-08-17 MEDIUM 5.3 CVE-2021-32822 The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnera… Hbs No fix yet Fix from $1,6002021-08-16