Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2020-8132 Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based … Pdf Image after 2.0.0 Fix from $2,3002020-02-28 CRITICAL 9.8 CVE-2020-9406 IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service. Online Weather 4.3.5+ Fix from $2,3002020-02-26 HIGH 7.8 CVE-2019-4000 Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to exe… Insync No fix yet Fix from $1,9502020-02-25 CRITICAL 9.8 CVE-2020-8518EPSS 72% Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. Fedora No fix yet Fix from $2,3002020-02-17 CRITICAL 9.8 CVE-2020-8129 An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code. Script Manager after 0.8.6 Fix from $2,3002020-02-14 CRITICAL 9.8 CVE-2013-4211EPSS 71% A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malici… Openx No fix yet Fix from $2,3002020-02-14 HIGH 8.8 CVE-2013-4225 The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity wri… Restful Web Services 7.x-1.4 / 7.x-2.1+ Fix from $1,9502020-02-11 HIGH 8.1 CVE-2020-5529 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can … Debian Linux 2.37.0+ Fix from $1,9502020-02-11 CRITICAL 9.8 CVE-2019-17268 The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions … Omniauth Weibo Oauth2 Patch available Fix from $2,3002020-02-07 CRITICAL 9.8 CVE-2020-8644 KEVEPSS 87% PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. Playsms 1.4.3+ Fix from $2,3002020-02-05 HIGH 7.2 CVE-2013-2267EPSS 9% PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. Fudforum Mitigation only Fix from $1,9502020-01-27 CRITICAL 9.8 CVE-2020-6836 grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanit… Hot Formula Parser 3.0.1+ Fix from $2,3002020-01-11 CRITICAL 9.8 CVE-2019-20343 The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin elem… Exec Maven Mitigation only Fix from $2,3002020-01-06 HIGH 8.8 CVE-2019-20155 An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may exe… Contract Lifecycle Management No fix yet Fix from $1,9502020-01-05 CRITICAL 9.9 CVE-2019-10758 KEVEPSS 85% mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to pe… Mongo Express 0.54.0+ Fix from $2,3002019-12-24 HIGH 8.8 CVE-2019-19909 An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injectio… Open Journal System 3.1.2-2+ Fix from $1,9502019-12-19 HIGH 8.8 CVE-2019-7486 Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA10… Sma 100 Firmware after 9.0.0.4 Fix from $1,9502019-12-19 CRITICAL 9.8 CVE-2019-15597 A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input. Node Df Mitigation only Fix from $2,3002019-12-18 CRITICAL 9.8 CVE-2019-15598 A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command. Treekill Mitigation only Fix from $2,3002019-12-18 CRITICAL 9.8 CVE-2019-15599 A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command. Tree Kill Mitigation only Fix from $2,3002019-12-18 CRITICAL 9.8 CVE-2019-4716 KEVEPSS 86% IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and th… Planning Analytics after 2.0.8 Fix from $2,3002019-12-18 CRITICAL 9.8 CVE-2019-16774 In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. Phpfastcache 5.0.13+ Fix from $2,3002019-12-12 CRITICAL 9.8 CVE-2019-10769 safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to A… Safer Eval No fix yet Fix from $2,3002019-12-06 CRITICAL 9.8 CVE-2019-16885 In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. Thi… Okaycms after 2.3.4 Fix from $2,3002019-12-03 MEDIUM 6.5 CVE-2019-3665 Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the br… Webadvisor 4.1.1.48+ Fix from $1,6002019-12-03 CRITICAL 9.8 CVE-2019-19502 Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP… Image Uploader And Browser For Ckeditor 4.1.9+ Fix from $2,3002019-12-02 HIGH 8.8 CVE-2019-14867EPSS 7% A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the interna… Fedora 4.6.7 / 4.7.4+ Fix from $1,9502019-11-27 HIGH 8.1 CVE-2019-16255 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[]… Ruby after 2.6.4 Fix from $1,9502019-11-26 MEDIUM 6.1 CVE-2019-13714 Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS… Chrome 78.0.3904.70+ Fix from $1,6002019-11-25 HIGH 7.2 CVE-2019-3427 The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inj… Zxcdn Iamweb Firmware Mitigation only Fix from $1,9502019-11-22