Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2020-6143EPSS 6% A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in ins… Opensis No fix yet Fix from $2,3002020-09-01 CRITICAL 9.8 CVE-2020-6144EPSS 6% A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in ins… Opensis No fix yet Fix from $2,3002020-09-01 CRITICAL 9.8 CVE-2020-15150 There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to … Paginator 1.0.0+ Fix from $2,3002020-09-01 HIGH 8.5 CVE-2020-15147 Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users wit… Red Discord Bot after 3.3.11 Fix from $1,9502020-08-21 CRITICAL 9.8 CVE-2020-7710 This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine. Safe Eval No fix yet Fix from $2,3002020-08-21 HIGH 8.8 CVE-2020-15070 Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write… Zulip Server 2.1.7+ Fix from $1,9502020-08-21 CRITICAL 9.8 CVE-2020-15865EPSS 5% A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the … Reports No fix yet Fix from $2,3002020-08-18 CRITICAL 9.0 CVE-2020-15142 In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subs… Openapi Python Client 0.5.3+ Fix from $2,3002020-08-14 CRITICAL 9.8 CVE-2020-10055EPSS 6% A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications … Desigo Consumption Control Patch available Fix from $2,3002020-08-14 HIGH 7.8 CVE-2020-8224 A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory. Desktop 2.6.5+ Fix from $1,9502020-08-10 HIGH 7.2 CVE-2020-8218 KEVEPSS 32% A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution … Connect Secure after 9.0 Fix from $1,9502020-07-30 HIGH 7.5 CVE-2020-7694 This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever an… Uvicorn No fix yet Fix from $1,9502020-07-27 CRITICAL 9.1 CVE-2020-12013 A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi El… Mc Works32 after 10.95.208.31 Fix from $2,3002020-07-16 CRITICAL 9.8 CVE-2020-11546EPSS 33% SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticat… Superwebmailer 7.40.0.01550+ Fix from $2,3002020-07-14 MEDIUM 6.5 CVE-2020-8194EPSS 11% Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SD… Application Delivery Controller Firmware 10.2.7 / 10.5-70.18+ Fix from $1,6002020-07-10 HIGH 8.8 CVE-2020-8163EPSS 82% The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `rend… Rails 5.0.1+ Fix from $1,9502020-07-02 CRITICAL 9.8 CVE-2020-15348 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python c… Cloud Cnm Secumanager No fix yet Fix from $2,3002020-06-26 CRITICAL 9.8 CVE-2016-11064 An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection. Mattermost Desktop 3.4.0+ Fix from $2,3002020-06-19 HIGH 8.8 CVE-2020-5593 Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file. Zenphoto 1.5.7+ Fix from $1,9502020-06-11 HIGH 8.6 CVE-2020-7672 mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, result… Mosc after 1.0.0 Fix from $1,9502020-06-10 CRITICAL 9.8 CVE-2020-7673 node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` l… Node Extend after 0.2.0 Fix from $2,3002020-06-10 CRITICAL 9.8 CVE-2020-7674 access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` funct… Access Policy after 3.1.0 Fix from $2,3002020-06-10 CRITICAL 9.8 CVE-2020-7675 cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function re… Cd Messenger after 2.7.26 Fix from $2,3002020-06-10 CRITICAL 9.9 CVE-2020-8180 A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an adminis… Talk 6.0.5 / 7.0.3+ Fix from $2,3002020-06-08 HIGH 8.8 CVE-2020-7012EPSS 18% Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privile… Kibana after 7.6.2 Fix from $1,9502020-06-03 HIGH 7.2 CVE-2020-7013 Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualiza… Kibana 6.8.9 / 7.7.0+ Fix from $1,9502020-06-03 CRITICAL 9.8 CVE-2020-13756EPSS 55% Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or g… Php Css Parser 8.3.1+ Fix from $2,3002020-06-03 CRITICAL 9.8 CVE-2020-11079 node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client o… Node Dns Sync 0.2.1+ Fix from $2,3002020-05-28 CRITICAL 9.8 CVE-2019-5997 Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors. Video Insight Vms after 7.5 Fix from $2,3002020-05-20 HIGH 8.8 CVE-2020-13144EPSS 11% Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new… Open Edx Platform No fix yet Fix from $1,9502020-05-18