Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2018-3608 A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attack… Antivirus \+ Security after 12.0.1191 Fix from $2,3002018-07-06 MEDIUM 5.4 CVE-2017-1242 IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe… Rational Quality Manager after 6.0.5 Fix from $1,6002018-07-06 MEDIUM 6.1 CVE-2017-1248 IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe… Rational Quality Manager after 6.0.5 Fix from $1,6002018-07-06 MEDIUM 5.4 CVE-2017-1329 IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which whe… Rational Quality Manager after 6.0.5 Fix from $1,6002018-07-06 CRITICAL 9.8 CVE-2018-13043 scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co… Devscripts after 2.18.3 Fix from $2,3002018-07-01 HIGH 8.8 CVE-2018-12994 onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen. Onefilecms after 2012-04-14 Fix from $1,9502018-06-29 HIGH 8.8 CVE-2018-12995 onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen. Onefilecms after 2012-04-14 Fix from $1,9502018-06-29 CRITICAL 9.8 CVE-2017-7465 It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw … Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-06-27 CRITICAL 9.8 CVE-2018-11587 There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.ph… Centreon Patch available Fix from $2,3002018-06-25 CRITICAL 9.8 CVE-2018-12531 An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulne… Metinfo No fix yet Fix from $2,3002018-06-18 CRITICAL 9.8 CVE-2017-3907 Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows… Mcafee Threat Intelligence Exchange Mitigation only Fix from $2,3002018-06-13 HIGH 8.8 CVE-2018-5158EPSS 10% The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF fil… Debian Linux 52.8.0 / 60.0+ Fix from $1,9502018-06-11 HIGH 8.8 CVE-2017-7798 The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, t… Debian Linux 52.3.0 / 55.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2018-6512 The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet … Pe Razor Server 1.9.0.0 / 2018.1.1+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-11228EPSS 7% Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code executio… Crestron Toolbox Protocol Firmware 2.001.0037.001+ Fix from $2,3002018-06-08 CRITICAL 9.8 CVE-2017-16151 Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent … Electron 1.7.8+ Fix from $2,3002018-06-07 CRITICAL 9.8 CVE-2017-16100EPSS 5% dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible. Dns Sync after 0.1.1 Fix from $2,3002018-06-07 CRITICAL 9.8 CVE-2017-16082EPSS 11% A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. The… Pg 2.11.2 / 3.6.4+ Fix from $2,3002018-06-07 CRITICAL 9.8 CVE-2017-16042 Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitra… Growl 1.10.2+ Fix from $2,3002018-06-04 CRITICAL 9.8 CVE-2017-16020 Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands … Summit after 0.1.21 Fix from $2,3002018-06-04 HIGH 8.8 CVE-2018-7950 The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validatio… 1288h V5 Firmware Mitigation only Fix from $1,9502018-06-01 HIGH 8.8 CVE-2018-7951 The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validatio… 1288h V5 Firmware Mitigation only Fix from $1,9502018-06-01 CRITICAL 9.8 CVE-2016-10541 The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend o… Shell Quote 1.6.1+ Fix from $2,3002018-05-31 CRITICAL 9.8 CVE-2016-10546 An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design docu… Pouchdb after 6.0.4 Fix from $2,3002018-05-31 MEDIUM 6.1 CVE-2016-10548 Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on t… Reduce Css Calc after 1.2.4 Fix from $1,6002018-05-31 MEDIUM 6.1 CVE-2014-10065 Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascri… Remarkable 1.4.1+ Fix from $1,6002018-05-31 HIGH 8.8 CVE-2018-1133EPSS 32% An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval… Moodle after 3.4.2 Fix from $1,9502018-05-25 CRITICAL 9.8 CVE-2018-1260EPSS 8% Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contai… Spring Security Oauth after 2.3.2 Fix from $2,3002018-05-11 CRITICAL 9.8 CVE-2018-2418 SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could th… Maxdb Odbc Driver 7.9.09.07+ Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2018-10740 Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php f… Axublog No fix yet Fix from $2,3002018-05-04