Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.2 CVE-2019-15001EPSS 11% The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before… Jira Server 7.6.16 / 7.13.8+ Fix from $1,9502019-09-19 CRITICAL 9.8 CVE-2019-13558 In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote … Webaccess after 8.4.1 Fix from $2,3002019-09-18 HIGH 8.1 CVE-2019-3759 The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerab… Rsa Identity Governance And Lifecycle No fix yet Fix from $1,9502019-09-11 HIGH 7.2 CVE-2019-0355 SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6… Netweaver Application Server Java Mitigation only Fix from $1,9502019-09-10 HIGH 8.8 CVE-2019-15873 The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php reque… Profilegrid 2.8.6+ Fix from $1,9502019-09-03 HIGH 7.8 CVE-2019-2390 An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs ship… MongoDB 3.4.22 / 3.6.14+ Fix from $1,9502019-08-30 CRITICAL 9.8 CVE-2018-21005 The bbp-move-topics plugin before 1.1.6 for WordPress has code injection. Bbpress Move Topics 1.1.6+ Fix from $2,3002019-08-27 HIGH 8.8 CVE-2019-15647 The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution. Groundhogg 1.3.5+ Fix from $1,9502019-08-27 HIGH 8.8 CVE-2019-15642EPSS 35% rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call.… Webmin after 1.920 Fix from $1,9502019-08-26 HIGH 7.5 CVE-2018-20988 The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation. Google Forms 0.94+ Fix from $1,9502019-08-22 HIGH 7.2 CVE-2018-18573 osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.… Oscommerce Mitigation only Fix from $1,9502019-08-22 CRITICAL 9.8 CVE-2019-15318 The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. Easy Forms For Mailchimp 6.5.3+ Fix from $2,3002019-08-22 CRITICAL 9.8 CVE-2019-15224 The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Ver… Rest Client after 1.6.13 Fix from $2,3002019-08-19 HIGH 7.8 CVE-2019-1157 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully … Windows 10 Patch available Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-1150EPSS 26% A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who succe… Windows 10 Patch available Fix from $1,9502019-08-14 HIGH 7.5 CVE-2019-1057 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exp… Windows 10 Patch available Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-0343 SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject … Commerce Cloud Mitigation only Fix from $1,9502019-08-14 CRITICAL 9.8 CVE-2015-9298 The events-manager plugin before 5.6 for WordPress has code injection. Events Manager 5.6+ Fix from $2,3002019-08-13 CRITICAL 9.8 CVE-2019-14965 An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists. Frappe 12.0.4+ Fix from $2,3002019-08-12 CRITICAL 9.8 CVE-2019-14746 A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.… Kuaifancms No fix yet Fix from $2,3002019-08-07 MEDIUM 6.3 CVE-2017-18468 cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232). Cpanel 56.0.46 / 58.0.45+ Fix from $1,6002019-08-05 HIGH 8.8 CVE-2019-7871 A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbit… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 8.1 CVE-2019-9140 When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascrip… Happypoint Mitigation only Fix from $1,9502019-08-01 MEDIUM 6.3 CVE-2018-20931 cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405). Cpanel 62.0.42 / 68.0.33+ Fix from $1,6002019-08-01 HIGH 7.2 CVE-2019-0193 KEVEPSS 84% In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh… Solr 7.7.3 / 8.1.2+ Fix from $1,9502019-08-01 MEDIUM 6.5 CVE-2019-10182 It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a vi… Enterprise Linux Desktop after 1.7.2 Fix from $1,6002019-07-31 HIGH 8.0 CVE-2019-11201 Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that th… Dolibarr Erp\/crm No fix yet Fix from $1,9502019-07-29 CRITICAL 9.8 CVE-2019-14281 The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Datagrid Mitigation only Fix from $2,3002019-07-26 CRITICAL 9.8 CVE-2019-14282 The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Simple Captcha2 Mitigation only Fix from $2,3002019-07-26 CRITICAL 9.8 CVE-2019-10173EPSS 95% It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has… Xstream after 8.2.2 Fix from $2,3002019-07-23