Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Advanced Cluster Management For Kubernetes HIGH 7.7
CVE-2026-44495

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets…

Fix: 2.13.9 / 4.10.3+
Fix from $1,950 2026-06-11
Hibernate Validator HIGH 7.3
CVE-2025-35036

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation me…

Fix: 6.2.0+
Fix from $1,950 2025-06-03
Satellite CRITICAL 9.1
CVE-2023-0462

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste…

Fix: 3.8.0+
Fix from $2,300 2023-09-20
Ansible Automation Platform HIGH 7.1
CVE-2021-3583

A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i…

Fix: 2.9.23 / 3.7.0+
Fix from $1,950 2021-09-22
Ansible HIGH 7.1
CVE-2020-10684

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a …

Fix: 2.7.17 / 2.8.9+
Fix from $1,950 2020-03-24
Enterprise Linux Desktop MEDIUM 6.5
CVE-2019-10182

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a vi…

Fix: after 1.7.2
Fix from $1,600 2019-07-31
Bodhi MEDIUM 6.1
CVE-2017-1002152

Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.

Fix: after 2.9.0
Fix from $1,600 2019-01-10
Openshift Container Platform HIGH 8.8
CVE-2019-0542

A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerabi…

Fix: 3.9.99 / 3.10.163+
Fix from $1,950 2019-01-09
Richfaces CRITICAL 9.8
CVE-2018-14667 KEVEPSS 74%

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate…

Fix: after 3.3.4
Fix from $2,300 2018-11-06
Cloudforms HIGH 8.8
CVE-2016-5402EPSS 6%

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces…

Mitigation only
Fix from $1,950 2018-10-31
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7465

It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …

Mitigation only
Fix from $2,300 2018-06-27
Ansible Tower HIGH 8.8
CVE-2018-1104

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar…

Fix: after 3.2.3
Fix from $1,950 2018-05-02
Gluster Storage MEDIUM 6.0
CVE-2015-5242

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authe…

Mitigation only
Fix from $1,600 2015-11-25
Richfaces MEDIUM 6.8
CVE-2015-0279

JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parame…

Fix: after 4.5.4
Fix from $1,600 2015-03-26
Openshift MEDIUM 6.5
CVE-2014-0233

Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters…

No fix yet
Fix from $1,600 2014-11-16
Openshift HIGH 7.5
CVE-2014-3666

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.

Fix: after 3.1
Fix from $1,950 2014-10-16
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2014-3518

jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po…

Mitigation only
Fix from $1,600 2014-07-22
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2014-0248

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente…

Mitigation only
Fix from $1,600 2014-07-07
Openshift HIGH 10.0
CVE-2014-3496EPSS 5%

cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metach…

Patch available
Fix from $1,950 2014-06-20
Jboss Fuse Service Works MEDIUM 6.5
CVE-2013-6469

JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression …

Mitigation only
Fix from $1,600 2014-04-22
Jboss Bpm Suite MEDIUM 6.5
CVE-2013-6468

JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java c…

Mitigation only
Fix from $1,600 2014-04-10
Cloudforms HIGH 7.5
CVE-2014-0057

The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remo…

Mitigation only
Fix from $1,950 2014-03-18
Cloudforms Management Engine HIGH 8.5
CVE-2013-4172

The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors.

Mitigation only
Fix from $1,950 2013-08-23
Openstack MEDIUM 6.0
CVE-2013-2121EPSS 25%

Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with perm…

Fix: after 1.2.0
Fix from $1,600 2013-07-31
Enterprise Linux Desktop HIGH 7.8
CVE-2012-1535 KEVEPSS 70%

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers …

Fix: 11.2.202.238 / 11.3.300.271+
Fix from $1,950 2012-08-15