Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2020-28464 This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine. Djv 2.1.4+ Fix from $2,3002021-01-04 CRITICAL 9.8 CVE-2020-20298 Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to ex… Zzzphp No fix yet Fix from $2,3002020-12-18 HIGH 7.5 CVE-2020-28367 Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags speci… Go 1.14.12 / 1.15.5+ Fix from $1,9502020-11-18 HIGH 7.5 CVE-2020-28366 Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symb… Go 1.14.12 / 1.15.5+ Fix from $1,9502020-11-18 CRITICAL 9.8 CVE-2020-11851 Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remot… Arcsight Logger 7.1.1+ Fix from $2,3002020-11-17 HIGH 8.8 CVE-2020-25538EPSS 10% An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web p… Cmsuno No fix yet Fix from $1,9502020-11-13 HIGH 8.8 CVE-2020-25557EPSS 10% In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs… Cmsuno No fix yet Fix from $1,9502020-11-13 CRITICAL 9.8 CVE-2020-7472 An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9… Sugarcrm 8.0.7 / 9.0.4+ Fix from $2,3002020-11-12 HIGH 7.8 CVE-2020-17091 Microsoft Teams Remote Code Execution Vulnerability Teams Patch available Fix from $1,9502020-11-11 CRITICAL 9.8 CVE-2020-7373EPSS 45% vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.… Vbulletin after 5.6.2 Fix from $2,3002020-10-30 HIGH 7.1 CVE-2020-7745 This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. … Mintegraladsdk 6.6.0.0+ Fix from $1,9502020-10-19 HIGH 8.8 CVE-2020-15252 In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet … Xwiki 11.10.6 / 12.5+ Fix from $1,9502020-10-16 CRITICAL 9.8 CVE-2020-8349 An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ option… Cloud Networking Operating System 10.10.6.0+ Fix from $2,3002020-10-14 HIGH 7.5 CVE-2017-18924 oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is sim… Oauth2 Server after 3.1.1 Fix from $1,9502020-10-04 HIGH 8.8 CVE-2020-24628 A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3. Kvm Ip Console Switch G2 Firmware 2.8.3+ Fix from $1,9502020-10-02 CRITICAL 9.8 CVE-2020-18185 class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment. Pluxml No fix yet Fix from $2,3002020-10-02 HIGH 8.8 CVE-2020-26124EPSS 67% openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, beca… Openmediavault 4.1.36 / 5.5.12+ Fix from $1,9502020-10-02 CRITICAL 9.8 CVE-2020-15227EPSS 34% Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters… Debian Linux 2.0.19 / 2.1.13+ Fix from $2,3002020-10-01 HIGH 7.2 CVE-2020-8243 KEVEPSS 91% A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform … Connect Secure after 9.0 Fix from $1,9502020-09-30 HIGH 8.1 CVE-2019-20920 Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allow… Handlebars 3.0.8 / 4.5.3+ Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2020-15371 Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation … Fabric Operating System Mitigation only Fix from $2,3002020-09-25 HIGH 7.2 CVE-2019-7177 Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin. Pexip Infinity 20.1+ Fix from $1,9502020-09-25 MEDIUM 6.7 CVE-2020-3513 Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation… Ios Xe Mitigation only Fix from $1,6002020-09-24 MEDIUM 6.7 CVE-2020-3416 Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation… Ios Xe Mitigation only Fix from $1,6002020-09-24 HIGH 8.8 CVE-2020-11803EPSS 8% An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could le… Spamtitan No fix yet Fix from $1,9502020-09-17 HIGH 8.8 CVE-2020-11804EPSS 7% An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection c… Spamtitan No fix yet Fix from $1,9502020-09-17 MEDIUM 6.6 CVE-2020-15171 In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servle… Xwiki 11.10.5 / 12.2.1+ Fix from $1,6002020-09-10 HIGH 7.2 CVE-2020-6318EPSS 6% A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of thi… Abap Platform No fix yet Fix from $1,9502020-09-09 HIGH 7.8 CVE-2020-7381 In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by a… Nexpose 6.6.40+ Fix from $1,9502020-09-03 HIGH 8.6 CVE-2020-15167 In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to … Miller No fix yet Fix from $1,9502020-09-02