Vulnerability index

Browse CVEs

29 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Debian Linux HIGH 7.8
CVE-2023-7101 KEVEPSS 17%

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut…

Fix: after 0.65
Fix from $1,950 2023-12-24
Debian Linux HIGH 8.0
CVE-2022-46648

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con…

Fix: 1.13.0+
Fix from $1,950 2023-01-17
Debian Linux HIGH 8.0
CVE-2022-47318

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con…

Fix: 1.13.0+
Fix from $1,950 2023-01-17
Debian Linux HIGH 8.8
CVE-2022-42902

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input…

Fix: 2022.10+
Fix from $1,950 2022-10-13
Debian Linux HIGH 8.8
CVE-2022-29221

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.…

Fix: 3.1.45 / 4.1.1+
Fix from $1,950 2022-05-24
Debian Linux HIGH 8.5
CVE-2021-39144 KEVEPSS 98%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.8
CVE-2021-29505EPSS 77%

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attack…

Fix: 1.4.17+
Fix from $1,950 2021-05-28
Debian Linux HIGH 8.8
CVE-2021-29472

Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitize…

Fix: 1.10.22 / 2.0.13+
Fix from $1,950 2021-04-27
Debian Linux HIGH 7.8
CVE-2021-22204 KEVEPSS 100%

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malici…

Fix: 12.24+
Fix from $1,950 2021-04-23
Debian Linux HIGH 7.2
CVE-2021-23358

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template fu…

Fix: 1.12.1 / 1.13.0-2+
Fix from $1,950 2021-03-29
Debian Linux CRITICAL 9.8
CVE-2021-26120EPSS 82%

Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.

Fix: 3.1.39+
Fix from $2,300 2021-02-22
Debian Linux CRITICAL 9.8
CVE-2020-15227EPSS 35%

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…

Fix: 2.0.19 / 2.1.13+
Fix from $2,300 2020-10-01
Debian Linux HIGH 7.7
CVE-2020-5258

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to in…

Fix: 1.11.10 / 1.12.8+
Fix from $1,950 2020-03-10
Debian Linux HIGH 8.1
CVE-2020-5529

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can …

Fix: 2.37.0+
Fix from $1,950 2020-02-11
Debian Linux HIGH 8.8
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacke…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Devscripts CRITICAL 9.8
CVE-2018-13043

scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co…

Fix: after 2.18.3
Fix from $2,300 2018-07-01
Debian Linux HIGH 8.8
CVE-2018-5158EPSS 10%

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF fil…

Fix: 52.8.0 / 60.0+
Fix from $1,950 2018-06-11
Debian Linux HIGH 8.8
CVE-2017-7798

The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, t…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11
Debian Linux HIGH 8.8
CVE-2017-16664

Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In t…

Fix: 3.3.20 / 4.0.26+
Fix from $1,950 2017-11-21
Debian Linux HIGH 8.8
CVE-2017-16544EPSS 6%

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames i…

Fix: after 1.27.2
Fix from $1,950 2017-11-20
Debian Linux CRITICAL 9.8
CVE-2017-0899EPSS 11%

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem…

Fix: after 2.6.12
Fix from $2,300 2017-08-31
Debian Linux CRITICAL 9.8
CVE-2017-7494 KEVEPSS 99%

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to up…

Fix: 4.4.0 / 4.4.14+
Fix from $2,300 2017-05-30
Debian Linux HIGH 7.3
CVE-2016-7966

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on t…

Fix: after 4.4.0
Fix from $1,950 2016-12-23
Debian Linux HIGH 7.1
CVE-2016-5424

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users…

Fix: after 9.1.22
Fix from $1,950 2016-12-09
Debian Linux CRITICAL 9.8
CVE-2016-3153

SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related …

Patch available
Fix from $2,300 2016-04-08
Debian Linux CRITICAL 9.8
CVE-2009-1151 KEVEPSS 95%

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitr…

Fix: 2.11.9.5 / 3.1.3.1+
Fix from $2,300 2009-03-26
Apt Listchanges HIGH 7.2
CVE-2008-0302

Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious…

Fix: after 2.81
Fix from $1,950 2008-01-17
Debian Linux HIGH 7.3
CVE-2005-3302

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh fil…

No fix yet
Fix from $1,950 2005-10-24
Debian Linux HIGH 7.5
CVE-2005-2498EPSS 5%

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew,…

Fix: after 1.1.1
Fix from $1,950 2005-08-15