Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.2 CVE-2021-23358 The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template fu… Debian Linux 1.12.1 / 1.13.0-2+ Fix from $1,9502021-03-29 HIGH 8.8 CVE-2021-27438 The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Re… Reason Dr60 Firmware 02a04.1+ Fix from $1,9502021-03-25 CRITICAL 9.9 CVE-2021-21345EPSS 72% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 7.2 CVE-2021-27928EPSS 38% A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percon… MariaDB 10.2.37 / 10.3.28+ Fix from $1,9502021-03-19 HIGH 8.8 CVE-2021-27230 ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to wri… Expressionengine 5.4.2 / 6.0.3+ Fix from $1,9502021-03-15 MEDIUM 6.7 CVE-2021-3411 A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linki… Linux Kernel 5.10+ Fix from $1,6002021-03-09 HIGH 8.8 CVE-2021-21480EPSS 51% SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a r… Manufacturing Integration And Intelligence No fix yet Fix from $1,9502021-03-09 HIGH 8.1 CVE-2020-28502 This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=Fal… Xmlhttprequest 1.7.0+ Fix from $1,9502021-03-05 CRITICAL 9.8 CVE-2021-23344 The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set. Total.js 3.4.8+ Fix from $2,3002021-03-04 CRITICAL 9.0 CVE-2021-21353 Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty… Pug 2.0.3 / 3.0.1+ Fix from $2,3002021-03-03 CRITICAL 9.8 CVE-2021-25283EPSS 11% An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks. Fedora 2015.8.10 / 2015.8.13+ Fix from $2,3002021-02-27 HIGH 7.2 CVE-2021-3273EPSS 7% Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must ha… Nagios Xi 5.7+ Fix from $1,9502021-02-25 CRITICAL 9.8 CVE-2021-26120EPSS 82% Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. Debian Linux 3.1.39+ Fix from $2,3002021-02-22 CRITICAL 9.8 CVE-2020-35339 In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Comm… 74cms No fix yet Fix from $2,3002021-02-17 HIGH 7.2 CVE-2020-35734EPSS 7% Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the … Batflat No fix yet Fix from $1,9502021-02-15 HIGH 7.2 CVE-2021-23337EPSS 21% Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. Active Iq Unified Manager 4.17.21+ Fix from $1,9502021-02-15 HIGH 7.2 CVE-2021-25251 The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker t… Antivirus\+ Security 2020 Mitigation only Fix from $1,9502021-02-10 CRITICAL 9.8 CVE-2020-28870 In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalizati… Inoerp No fix yet Fix from $2,3002021-02-10 CRITICAL 9.9 CVE-2021-21477EPSS 30% SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attack… Commerce Mitigation only Fix from $2,3002021-02-09 HIGH 8.8 CVE-2021-26551 An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by… Smartfoxserver No fix yet Fix from $1,9502021-02-09 HIGH 8.8 CVE-2021-21305EPSS 13% CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions… Carrierwave 1.3.2 / 2.1.1+ Fix from $1,9502021-02-08 CRITICAL 9.8 CVE-2021-25770 In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution. Youtrack 2020.5.3123+ Fix from $2,3002021-02-03 HIGH 8.8 CVE-2021-21277 angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2… Angular Expressions 1.1.2+ Fix from $1,9502021-02-01 HIGH 7.2 CVE-2020-35754EPSS 10% OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via … Quick.cart 6.7+ Fix from $1,9502021-01-28 HIGH 7.2 CVE-2021-20187 It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts v… Moodle 3.5.16 / 3.8.7+ Fix from $1,9502021-01-28 HIGH 8.8 CVE-2021-21248 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. I… Onedev 4.0.3+ Fix from $1,9502021-01-15 CRITICAL 9.8 CVE-2021-21244 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injectio… Onedev 4.0.3+ Fix from $2,3002021-01-15 HIGH 8.8 CVE-2021-21466 SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to … Business Warehouse No fix yet Fix from $1,9502021-01-12 CRITICAL 9.8 CVE-2020-35131EPSS 51% Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/… Cockpit 0.6.1+ Fix from $2,3002021-01-08 MEDIUM 6.5 CVE-2020-8274 Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated acce… Secure Mail 20.11.0+ Fix from $1,6002021-01-06