Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2019-18889EPSS 33% An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces … Symfony after 4.3.7 Fix from $2,3002019-11-21 CRITICAL 9.8 CVE-2019-5509 ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully e… Ontap Select Deploy Administration Utility after 2.12.2 Fix from $2,3002019-11-21 CRITICAL 9.8 CVE-2019-19010 Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose i… Fedora 2019.11.09+ Fix from $2,3002019-11-16 HIGH 8.1 CVE-2019-15388 The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-ins… Mega 5 Firmware Mitigation only Fix from $1,9502019-11-14 CRITICAL 9.8 CVE-2013-1666 Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro. Foswiki 1.1.8+ Fix from $2,3002019-11-01 CRITICAL 10.0 CVE-2018-4031 An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsin… Smart Firewall Mitigation only Fix from $2,3002019-10-31 CRITICAL 9.8 CVE-2019-10211 Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected di… PostgreSQL 9.4.24 / 9.5.19+ Fix from $2,3002019-10-29 CRITICAL 9.8 CVE-2019-17526 An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web app… Sagemathcell Patch available Fix from $2,3002019-10-18 CRITICAL 9.8 CVE-2019-17613 qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply … Qibosoft No fix yet Fix from $2,3002019-10-15 CRITICAL 9.8 CVE-2019-17408 parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be… Zzzphp No fix yet Fix from $2,3002019-10-14 MEDIUM 5.3 CVE-2019-3652 Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their mali… Endpoint Security 10.6.1+ Fix from $1,6002019-10-09 HIGH 8.8 CVE-2018-21023 getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter. Centreon Web 2.8.28 / 18.10.5+ Fix from $1,9502019-10-08 HIGH 7.2 CVE-2019-17299 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17300 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17301 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17302 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17303 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17304 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17305 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17306 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17307 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17308 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17309 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17310 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 CRITICAL 9.8 CVE-2019-15746 SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute sy… Sitos Six Mitigation only Fix from $2,3002019-10-07 CRITICAL 9.8 CVE-2019-17132EPSS 12% vBulletin through 5.5.4 mishandles custom avatars. Vbulletin after 5.5.4 Fix from $2,3002019-10-04 CRITICAL 9.9 CVE-2019-10431 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constru… Script Security after 1.64 Fix from $2,3002019-10-01 CRITICAL 9.8 CVE-2019-16759 KEVEPSS 100% vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. Vbulletin after 5.5.4 Fix from $2,3002019-09-24 HIGH 8.6 CVE-2019-16645EPSS 8% An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostna… Goahead No fix yet Fix from $1,9502019-09-20 HIGH 7.2 CVE-2019-15087 An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote … Adas Patch available Fix from $1,9502019-09-20