Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.0 CVE-2019-11552 Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A p… Code42 For Enterprise 6.7.5 / 6.8.8+ Fix from $1,9502019-07-19 CRITICAL 9.8 CVE-2019-13956 Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5… Discuz\!ml after 3.4 Fix from $2,3002019-07-18 CRITICAL 9.8 CVE-2019-9848EPSS 31% LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. … Ubuntu Linux 6.2.5+ Fix from $2,3002019-07-17 CRITICAL 9.8 CVE-2019-6823 A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker… Proclima 8.0.0+ Fix from $2,3002019-07-15 CRITICAL 9.1 CVE-2019-0330 The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to … Diagnostics Agent Mitigation only Fix from $2,3002019-07-10 CRITICAL 9.8 CVE-2019-13354 The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current ver… Strong Password Mitigation only Fix from $2,3002019-07-08 CRITICAL 9.8 CVE-2019-13372EPSS 82% /web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PH… Central Wifimanager after 1.03 Fix from $2,3002019-07-06 MEDIUM 6.1 CVE-2019-12843 A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 201… Teamcity 2018.2.3+ Fix from $1,6002019-07-03 MEDIUM 6.1 CVE-2019-12844 A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3. Teamcity 2018.2.3+ Fix from $1,6002019-07-03 CRITICAL 9.8 CVE-2019-10100 In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an… Youtrack Integration 1.8.1.3+ Fix from $2,3002019-07-03 HIGH 7.8 CVE-2019-5443 A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 au… Curl after 8.0.17 Fix from $1,9502019-07-02 MEDIUM 6.3 CVE-2019-1577 Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML. Traps after 5.0.5 Fix from $1,6002019-07-01 HIGH 8.1 CVE-2018-17170 Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend… Teamwire 1.9.0+ Fix from $1,9502019-06-28 MEDIUM 6.5 CVE-2018-18836 An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client_api_request_v1_data in web/a… Netdata Patch available Fix from $1,6002019-06-18 HIGH 8.8 CVE-2018-18879 In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating sys… Weather Microserver Firmware Mitigation only Fix from $1,9502019-06-18 HIGH 8.8 CVE-2019-8324 An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacke… Debian Linux after 3.0.2 Fix from $1,9502019-06-17 HIGH 7.5 CVE-2019-12761 A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_… Pyxdg 0.26+ Fix from $1,9502019-06-06 HIGH 8.6 CVE-2017-14853 The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct she… Siteomat 6.4.414.122+ Fix from $1,9502019-06-03 CRITICAL 9.8 CVE-2019-9891 The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands … Advanced Bash Scripting Guide No fix yet Fix from $2,3002019-05-31 CRITICAL 9.1 CVE-2019-6816 In Modicon Quantum all firmware versions, a CWE-94: Code Injection vulnerability could cause an unauthorized firmware modification with possible Deni… Modicon Quantum Firmware Mitigation only Fix from $2,3002019-05-22 HIGH 7.8 CVE-2019-0091 Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may … Converged Security And Management Engine 3.1.65 / 4.0.15+ Fix from $1,9502019-05-17 HIGH 8.8 CVE-2019-11642 A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authenticated remote adversaries can… Oneshield Policy 5.1.10+ Fix from $1,9502019-05-08 HIGH 8.1 CVE-2019-11593 In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web ser… Adblock Plus 3.5.2+ Fix from $1,9502019-04-29 HIGH 8.1 CVE-2019-11594 In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service… Adblock 3.45.0+ Fix from $1,9502019-04-29 HIGH 8.8 CVE-2011-1830 Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so. Ekiga 3.3.0+ Fix from $1,9502019-04-22 HIGH 7.2 CVE-2019-11376 SOY CMS v3.0.2 allows remote attackers to execute arbitrary PHP code via a <?php substring in the second text box. NOTE: the vendor indicates that th… Soy Cms No fix yet Fix from $1,9502019-04-20 HIGH 8.8 CVE-2019-10633 An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker t… Nas326 Firmware after 5.21 Fix from $1,9502019-04-09 HIGH 7.2 CVE-2019-10863EPSS 13% A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file wi… Teemip 2.4.0+ Fix from $1,9502019-04-04 CRITICAL 9.8 CVE-2019-10842 Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker… Bootstrap Sass No fix yet Fix from $2,3002019-04-04 CRITICAL 9.8 CVE-2019-10684 Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Adm… 74cms No fix yet Fix from $2,3002019-04-01