Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.7 CVE-2026-44495 Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets… Advanced Cluster Management For Kubernetes 2.13.9 / 4.10.3+ Fix from $1,9502026-06-11 HIGH 7.3 CVE-2025-35036 Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation me… Hibernate Validator 6.2.0+ Fix from $1,9502025-06-03 CRITICAL 9.1 CVE-2023-0462 An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste… Satellite 3.8.0+ Fix from $2,3002023-09-20 HIGH 7.1 CVE-2021-3583 A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template i… Ansible Automation Platform 2.9.23 / 3.7.0+ Fix from $1,9502021-09-22 HIGH 7.1 CVE-2020-10684 A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a … Ansible 2.7.17 / 2.8.9+ Fix from $1,9502020-03-24 MEDIUM 6.5 CVE-2019-10182 It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a vi… Enterprise Linux Desktop after 1.7.2 Fix from $1,6002019-07-31 MEDIUM 6.1 CVE-2017-1002152 Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles. Bodhi after 2.9.0 Fix from $1,6002019-01-10 HIGH 8.8 CVE-2019-0542 A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerabi… Openshift Container Platform 3.9.99 / 3.10.163+ Fix from $1,9502019-01-09 CRITICAL 9.8 CVE-2018-14667 KEVEPSS 74% The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticate… Richfaces after 3.3.4 Fix from $2,3002018-11-06 HIGH 8.8 CVE-2016-5402EPSS 6% A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with acces… Cloudforms Mitigation only Fix from $1,9502018-10-31 CRITICAL 9.8 CVE-2017-7465 It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw … Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-06-27 HIGH 8.8 CVE-2018-1104 Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrar… Ansible Tower after 3.2.3 Fix from $1,9502018-05-02 MEDIUM 6.0 CVE-2015-5242 OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authe… Gluster Storage Mitigation only Fix from $1,6002015-11-25 MEDIUM 6.8 CVE-2015-0279 JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parame… Richfaces after 4.5.4 Fix from $1,6002015-03-26 MEDIUM 6.5 CVE-2014-0233 Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters… Openshift No fix yet Fix from $1,6002014-11-16 HIGH 7.5 CVE-2014-3666 Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel. Openshift after 3.1 Fix from $1,9502014-10-16 MEDIUM 6.8 CVE-2014-3518 jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Po… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-07-22 MEDIUM 6.8 CVE-2014-0248 org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Ente… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-07-07 HIGH 10.0 CVE-2014-3496EPSS 5% cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metach… Openshift Patch available Fix from $1,9502014-06-20 MEDIUM 6.5 CVE-2013-6469 JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression … Jboss Fuse Service Works Mitigation only Fix from $1,6002014-04-22 MEDIUM 6.5 CVE-2013-6468 JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java c… Jboss Bpm Suite Mitigation only Fix from $1,6002014-04-10 HIGH 7.5 CVE-2014-0057 The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remo… Cloudforms Mitigation only Fix from $1,9502014-03-18 HIGH 8.5 CVE-2013-4172 The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors. Cloudforms Management Engine Mitigation only Fix from $1,9502013-08-23 MEDIUM 6.0 CVE-2013-2121EPSS 25% Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with perm… Openstack after 1.2.0 Fix from $1,6002013-07-31 HIGH 7.8 CVE-2012-1535 KEVEPSS 70% Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers … Enterprise Linux Desktop 11.2.202.238 / 11.3.300.271+ Fix from $1,9502012-08-15