Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2020-8149 Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1. Logkitty 0.7.1+ Fix from $2,3002020-05-15 HIGH 8.8 CVE-2020-11057 In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while edi… Xwiki after 11.10.2 Fix from $1,9502020-05-12 HIGH 7.2 CVE-2020-6248 SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while execut… Adaptive Server Enterprise Backup Server Mitigation only Fix from $1,9502020-05-12 HIGH 8.8 CVE-2020-6262 Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows … Application Server Mitigation only Fix from $1,9502020-05-12 HIGH 8.8 CVE-2020-6243 Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks … Adaptive Server Enterprise Mitigation only Fix from $1,9502020-05-12 CRITICAL 9.8 CVE-2020-10176 ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands. Yale Wipc 301w Firmware 2.x.2.43+ Fix from $2,3002020-05-07 MEDIUM 6.3 CVE-2020-11056 In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which… Sprout Forms 3.9.0+ Fix from $1,6002020-05-07 CRITICAL 9.8 CVE-2020-7609 node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled b… Node Rules 5.0.0+ Fix from $2,3002020-04-27 HIGH 8.8 CVE-2020-5739EPSS 5% Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up s… Gxp1610 Firmware after 1.0.4.152 Fix from $1,9502020-04-14 MEDIUM 6.1 CVE-2019-19089 For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be i… Esoms after 6.0.3 Fix from $1,6002020-04-02 CRITICAL 9.8 CVE-2019-9163 The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML ob… Command Client 2.7.2+ Fix from $2,3002020-04-01 CRITICAL 9.8 CVE-2020-10948EPSS 7% Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a differen… Alienform2 No fix yet Fix from $2,3002020-04-01 HIGH 8.8 CVE-2020-5558 CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. Cutenews No fix yet Fix from $1,9502020-03-25 CRITICAL 9.8 CVE-2020-5553 mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors. Mailform No fix yet Fix from $2,3002020-03-25 HIGH 7.1 CVE-2020-10684 A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a … Ansible 2.7.17 / 2.8.9+ Fix from $1,9502020-03-24 CRITICAL 9.8 CVE-2020-7480 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files… Andover Continuum 9680 Firmware Mitigation only Fix from $2,3002020-03-23 HIGH 8.8 CVE-2020-6650 UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code … Ups Companion after 1.05 Fix from $1,9502020-03-23 MEDIUM 6.7 CVE-2020-8140 A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set i… Desktop 2.6.3+ Fix from $1,6002020-03-20 CRITICAL 9.8 CVE-2020-8137 Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker. Blamer 1.0.1+ Fix from $2,3002020-03-20 HIGH 7.5 CVE-2019-16108 phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode. Phpbb Patch available Fix from $1,9502020-03-20 HIGH 7.2 CVE-2019-18582 Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side t… Emc Data Protection Advisor Mitigation only Fix from $1,9502020-03-18 CRITICAL 9.8 CVE-2019-19208EPSS 19% Codiad Web IDE through 2.8.4 allows PHP Code injection. Codiad after 2.8.4 Fix from $2,3002020-03-16 HIGH 8.8 CVE-2020-8141 The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they … Dot No fix yet Fix from $1,9502020-03-15 HIGH 7.2 CVE-2020-10389 admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any PO… Phpkb No fix yet Fix from $1,9502020-03-12 CRITICAL 9.8 CVE-2020-5203 In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GE… Fat Free Framework Patch available Fix from $2,3002020-03-11 HIGH 7.7 CVE-2020-5258 In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to in… Debian Linux 1.11.10 / 1.12.8+ Fix from $1,9502020-03-10 HIGH 8.6 CVE-2020-5259 In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inje… Dojox 1.11.10 / 1.12.8+ Fix from $1,9502020-03-10 CRITICAL 9.8 CVE-2020-10257EPSS 9% The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for P… Addons 1.0.1 / 1.0.1.2001+ Fix from $2,3002020-03-10 MEDIUM 6.5 CVE-2020-9530 An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of… Miui Firmware Mitigation only Fix from $1,6002020-03-06 HIGH 7.8 CVE-2019-3695 A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Lin… Pcp 3.11.9-5.8.1 / 3.11.9-6.14.1+ Fix from $1,9502020-03-03