Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2021-32809 ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](htt… Fedora 4.16.2 / 21.1.4+ Fix from $1,6002021-08-12 HIGH 7.2 CVE-2021-37626 Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files … Contao 4.4.56 / 4.9.18+ Fix from $1,9502021-08-11 HIGH 7.8 CVE-2021-37694 @asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection … Java Spring Cloud Stream Template 0.7.0+ Fix from $1,9502021-08-11 CRITICAL 9.8 CVE-2021-38196 An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitr… Better Macro after 2021-07-22 Fix from $2,3002021-08-08 CRITICAL 9.1 CVE-2021-36800 Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/… Akaunting 2.1.13+ Fix from $2,3002021-08-04 HIGH 8.8 CVE-2021-32706EPSS 60% Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface ve… Pi Hole 5.5.1+ Fix from $1,9502021-08-04 HIGH 8.8 CVE-2021-31630EPSS 27% Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/har… Openplc V3 Firmware No fix yet Fix from $1,9502021-08-03 HIGH 7.2 CVE-2021-24430 The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_qu… Speed Booster Pack 4.2.0+ Fix from $1,9502021-08-02 HIGH 8.8 CVE-2017-18113 The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system admi… Data Center 8.18.1+ Fix from $1,9502021-08-02 CRITICAL 9.8 CVE-2020-18172 A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges. Bridge No fix yet Fix from $2,3002021-07-26 HIGH 7.8 CVE-2021-25808 A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file. Bludit No fix yet Fix from $1,9502021-07-23 HIGH 8.8 CVE-2021-1518 A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbi… Firepower Device Manager On Box 6.4.0 / 6.7.0.2+ Fix from $1,9502021-07-22 HIGH 8.8 CVE-2021-32756 ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module o… Manageiq Mitigation only Fix from $1,9502021-07-21 HIGH 8.1 CVE-2021-32749 fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0… Fedora 0.10.7 / 0.11.3+ Fix from $1,9502021-07-16 MEDIUM 6.5 CVE-2021-33678 A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75… Netweaver Application Server Abap No fix yet Fix from $1,6002021-07-14 CRITICAL 9.8 CVE-2021-23390 The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. Total4 0.0.43+ Fix from $2,3002021-07-12 CRITICAL 9.8 CVE-2021-23389 The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. Total.js 3.4.9+ Fix from $2,3002021-07-12 HIGH 8.1 CVE-2021-1585EPSS 20% A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary co… Adaptive Security Device Manager 7.18.1.152+ Fix from $1,9502021-07-08 HIGH 8.8 CVE-2020-23219 Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" … Monstra Cms No fix yet Fix from $1,9502021-07-01 CRITICAL 9.8 CVE-2021-35514 Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel. Narou 3.8.0+ Fix from $2,3002021-06-28 CRITICAL 9.8 CVE-2020-21784 phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php. Phpwcms No fix yet Fix from $2,3002021-06-24 HIGH 8.8 CVE-2020-22201 phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php. Phpcms No fix yet Fix from $1,9502021-06-16 MEDIUM 5.5 CVE-2021-25415 Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writ… Android Mitigation only Fix from $1,6002021-06-11 MEDIUM 6.5 CVE-2021-25416 Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel… Android Mitigation only Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2021-25393 Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system ui… Android No fix yet Fix from $1,6002021-06-11 HIGH 7.3 CVE-2021-31949 Microsoft Outlook Remote Code Execution Vulnerability 365 Apps Patch available Fix from $1,9502021-06-08 CRITICAL 9.8 CVE-2021-32673 reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin throu… Reg Keygen Git Hash after 0.10.15 Fix from $2,3002021-06-08 HIGH 7.5 CVE-2021-22336 There is an Improper Control of Generation of Code vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause denial… Emui Mitigation only Fix from $1,9502021-06-03 HIGH 8.8 CVE-2021-32924EPSS 20% Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages… Ips Community Suite 4.6.0+ Fix from $1,9502021-06-01 HIGH 7.2 CVE-2021-24312 The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of … Wp Super Cache 1.7.3+ Fix from $1,9502021-06-01