Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.2 CVE-2017-18108 The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute… Crowd 2.10.2+ Fix from $1,9502019-03-29 CRITICAL 9.8 CVE-2018-19641 Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior t… Solutions Business Manager 11.5+ Fix from $2,3002019-03-27 CRITICAL 9.8 CVE-2014-5401EPSS 5% Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthent… Mednet after 5.8 Fix from $2,3002019-03-26 CRITICAL 10.0 CVE-2019-7609 KEVEPSS 95% Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion … Kibana 5.6.15 / 6.6.1+ Fix from $2,3002019-03-25 CRITICAL 9.0 CVE-2019-7610 Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securi… Kibana 5.6.15 / 6.6.1+ Fix from $2,3002019-03-25 HIGH 7.2 CVE-2019-10015 baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this co… Baigo Sso Mitigation only Fix from $1,9502019-03-24 CRITICAL 9.8 CVE-2019-5413 An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1. Morgan 1.9.1+ Fix from $2,3002019-03-21 CRITICAL 9.8 CVE-2019-9651 An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, res… Sdcms No fix yet Fix from $2,3002019-03-11 HIGH 8.1 CVE-2013-7468 Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter. Simple Machines Forum No fix yet Fix from $1,9502019-03-07 CRITICAL 9.8 CVE-2019-9227 An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter… Baigo Cms No fix yet Fix from $2,3002019-02-28 CRITICAL 9.8 CVE-2019-9115 In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage. Irisnet Crypto 1.1.7+ Fix from $2,3002019-02-25 HIGH 8.8 CVE-2019-9082 KEVEPSS 97% ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefu… Thinkphp 3.2.4+ Fix from $1,9502019-02-24 MEDIUM 6.7 CVE-2018-3700 Code injection vulnerability in the installer for Intel(R) USB 3.0 eXtensible Host Controller Driver for Microsoft Windows 7 before version 5.0.4.43v… Usb 3.0 Extensible Host Controller Driver 5.0.4.43v2+ Fix from $1,6002019-02-18 CRITICAL 9.8 CVE-2019-8341EPSS 45% An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parame… Jinja2 No fix yet Fix from $2,3002019-02-15 CRITICAL 9.8 CVE-2019-7719 Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request. Nibbleblog No fix yet Fix from $2,3002019-02-11 CRITICAL 9.8 CVE-2019-7720 taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request. Taocms after 2014-05-24 Fix from $2,3002019-02-11 HIGH 7.2 CVE-2018-20775 admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file … Frog Cms No fix yet Fix from $1,9502019-02-11 HIGH 7.2 CVE-2018-20772 Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI. Frog Cms No fix yet Fix from $1,9502019-02-11 HIGH 7.2 CVE-2018-20773 Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines. Frog Cms No fix yet Fix from $1,9502019-02-11 CRITICAL 9.8 CVE-2018-20768 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC… Workcentre 3655i Firmware 073.060.048.15000 / 073.190.048.15000+ Fix from $2,3002019-02-10 CRITICAL 9.8 CVE-2019-7692 install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file misha… Cim No fix yet Fix from $2,3002019-02-10 HIGH 8.8 CVE-2019-7580EPSS 10% ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mish… Thinkcmf No fix yet Fix from $1,9502019-02-07 HIGH 7.8 CVE-2018-19002 LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may … Laquis Scada 4.1.0.4150+ Fix from $1,9502019-02-05 MEDIUM 6.2 CVE-2019-4038 IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypass… Security Identity Manager after 7.0.1.10 Fix from $1,6002019-02-04 CRITICAL 9.8 CVE-2019-6713 app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving port… Thinkcmf Mitigation only Fix from $2,3002019-01-23 HIGH 8.8 CVE-2018-19011 CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code u… Cx Supervisor after 3.42 Fix from $1,9502019-01-22 HIGH 8.8 CVE-2017-18356 In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account th… Woocommerce 3.2.4+ Fix from $1,9502019-01-15 HIGH 8.8 CVE-2018-20717 In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of … Prestashop 1.7.2.5+ Fix from $1,9502019-01-15 MEDIUM 6.1 CVE-2017-1002152 Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles. Bodhi after 2.9.0 Fix from $1,6002019-01-10 HIGH 8.8 CVE-2018-0461 A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection a… Ip Phone 8800 Series Firmware Mitigation only Fix from $1,9502019-01-10