Vulnerability index

Browse CVEs

29 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.8 CVE-2023-7101 KEVEPSS 17% Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut… Debian Linux after 0.65 Fix from $1,9502023-12-24 HIGH 8.0 CVE-2022-46648 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con… Debian Linux 1.13.0+ Fix from $1,9502023-01-17 HIGH 8.0 CVE-2022-47318 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con… Debian Linux 1.13.0+ Fix from $1,9502023-01-17 HIGH 8.8 CVE-2022-42902 In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input… Debian Linux 2022.10+ Fix from $1,9502022-10-13 HIGH 8.8 CVE-2022-29221 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.… Debian Linux 3.1.45 / 4.1.1+ Fix from $1,9502022-05-24 HIGH 8.5 CVE-2021-39144 KEVEPSS 98% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.8 CVE-2021-29505EPSS 77% XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attack… Debian Linux 1.4.17+ Fix from $1,9502021-05-28 HIGH 8.8 CVE-2021-29472 Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitize… Debian Linux 1.10.22 / 2.0.13+ Fix from $1,9502021-04-27 HIGH 7.8 CVE-2021-22204 KEVEPSS 100% Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malici… Debian Linux 12.24+ Fix from $1,9502021-04-23 HIGH 7.2 CVE-2021-23358 The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template fu… Debian Linux 1.12.1 / 1.13.0-2+ Fix from $1,9502021-03-29 CRITICAL 9.8 CVE-2021-26120EPSS 82% Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. Debian Linux 3.1.39+ Fix from $2,3002021-02-22 CRITICAL 9.8 CVE-2020-15227EPSS 35% Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters… Debian Linux 2.0.19 / 2.1.13+ Fix from $2,3002020-10-01 HIGH 7.7 CVE-2020-5258 In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to in… Debian Linux 1.11.10 / 1.12.8+ Fix from $1,9502020-03-10 HIGH 8.1 CVE-2020-5529 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can … Debian Linux 2.37.0+ Fix from $1,9502020-02-11 HIGH 8.8 CVE-2019-8324 An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacke… Debian Linux after 3.0.2 Fix from $1,9502019-06-17 CRITICAL 9.8 CVE-2018-13043 scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a co… Devscripts after 2.18.3 Fix from $2,3002018-07-01 HIGH 8.8 CVE-2018-5158EPSS 10% The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF fil… Debian Linux 52.8.0 / 60.0+ Fix from $1,9502018-06-11 HIGH 8.8 CVE-2017-7798 The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, t… Debian Linux 52.3.0 / 55.0+ Fix from $1,9502018-06-11 HIGH 8.8 CVE-2017-16664 Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In t… Debian Linux 3.3.20 / 4.0.26+ Fix from $1,9502017-11-21 HIGH 8.8 CVE-2017-16544EPSS 6% In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames i… Debian Linux after 1.27.2 Fix from $1,9502017-11-20 CRITICAL 9.8 CVE-2017-0899EPSS 11% RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem… Debian Linux after 2.6.12 Fix from $2,3002017-08-31 CRITICAL 9.8 CVE-2017-7494 KEVEPSS 99% Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to up… Debian Linux 4.4.0 / 4.4.14+ Fix from $2,3002017-05-30 HIGH 7.3 CVE-2016-7966 Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on t… Debian Linux after 4.4.0 Fix from $1,9502016-12-23 HIGH 7.1 CVE-2016-5424 PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users… Debian Linux after 9.1.22 Fix from $1,9502016-12-09 CRITICAL 9.8 CVE-2016-3153 SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related … Debian Linux Patch available Fix from $2,3002016-04-08 CRITICAL 9.8 CVE-2009-1151 KEVEPSS 95% Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitr… Debian Linux 2.11.9.5 / 3.1.3.1+ Fix from $2,3002009-03-26 HIGH 7.2 CVE-2008-0302 Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious… Apt Listchanges after 2.81 Fix from $1,9502008-01-17 HIGH 7.3 CVE-2005-3302 Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh fil… Debian Linux No fix yet Fix from $1,9502005-10-24 HIGH 7.5 CVE-2005-2498EPSS 5% Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew,… Debian Linux after 1.1.1 Fix from $1,9502005-08-15