Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2011-3178 In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to e… Open Build Service 2.3.0+ Fix from $1,9502018-03-20 HIGH 7.2 CVE-2018-8756 Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in t… Yzmcms No fix yet Fix from $1,9502018-03-18 CRITICAL 9.8 CVE-2018-7756EPSS 61% RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remo… Dewesoft No fix yet Fix from $2,3002018-03-15 CRITICAL 9.8 CVE-2018-5779 A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, … Connect Onsite Mitigation only Fix from $2,3002018-03-14 CRITICAL 9.8 CVE-2018-5780 A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, … Connect Onsite Mitigation only Fix from $2,3002018-03-14 CRITICAL 9.8 CVE-2018-5781 A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, … Connect Onsite Mitigation only Fix from $2,3002018-03-14 CRITICAL 9.8 CVE-2018-5782EPSS 19% A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, … Connect Onsite No fix yet Fix from $2,3002018-03-14 CRITICAL 9.8 CVE-2018-8097EPSS 6% io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter. Eve 0.7.5+ Fix from $2,3002018-03-14 HIGH 8.8 CVE-2018-1000070 Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnera… Pybitmessage Patch available Fix from $1,9502018-03-13 HIGH 7.5 CVE-2018-7466EPSS 6% install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES da… Testlink after 1.9.16 Fix from $1,9502018-02-25 CRITICAL 9.8 CVE-2018-6488 Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to all… Ucmdb Configuration Manager Mitigation only Fix from $2,3002018-02-22 HIGH 8.1 CVE-2018-7271 An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering i… Metinfo No fix yet Fix from $1,9502018-02-21 HIGH 7.8 CVE-2017-16670 The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL pro… Soapui No fix yet Fix from $1,9502018-02-19 HIGH 8.8 CVE-2018-6889EPSS 7% An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the … Typesetter No fix yet Fix from $1,9502018-02-12 HIGH 7.8 CVE-2018-6574EPSS 8% Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, … Go after 1.8.6 Fix from $1,9502018-02-07 CRITICAL 9.8 CVE-2018-0007 An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may… Junos Mitigation only Fix from $2,3002018-01-10 HIGH 8.8 CVE-2018-2363 SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrar… Netweaver after 7.52 Fix from $1,9502018-01-09 HIGH 8.1 CVE-2017-16905 The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and conseq… Tinycards 1.0+ Fix from $1,9502018-01-05 CRITICAL 9.8 CVE-2017-1000480 Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize t… Smarty 3.1.32+ Fix from $2,3002018-01-03 CRITICAL 9.8 CVE-2017-17098EPSS 7% The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary … Gps Tracking Software after 3.0 Fix from $2,3002018-01-02 MEDIUM 6.1 CVE-2017-17649 Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter. Readymade Video Sharing Script No fix yet Fix from $1,6002017-12-18 HIGH 7.2 CVE-2017-16682 SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administra… Netweaver Internet Transaction Server after 7.52 Fix from $1,9502017-12-12 CRITICAL 9.8 CVE-2016-5713 Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to … Puppet Agent 1.6.0+ Fix from $2,3002017-12-06 HIGH 8.8 CVE-2017-14198 An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause… Matrix after 5.3.6.0 Fix from $1,9502017-11-30 CRITICAL 9.8 CVE-2017-1001002 math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could resu… Math.js after 3.17.0 Fix from $2,3002017-11-27 HIGH 8.8 CVE-2017-1001004 typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name cou… Typed Function 0.10.6+ Fix from $1,9502017-11-27 HIGH 8.8 CVE-2017-16664 Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In t… Debian Linux 3.3.20 / 4.0.26+ Fix from $1,9502017-11-21 HIGH 8.8 CVE-2017-16544EPSS 6% In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames i… Debian Linux after 1.27.2 Fix from $1,9502017-11-20 MEDIUM 6.1 CVE-2017-14077 HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_US… Securimage after 3.6.4 Fix from $1,6002017-11-18 HIGH 8.1 CVE-2017-16871 The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/upd… Updraftplus after 1.13.12 Fix from $1,9502017-11-17