Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2013-4810 KEV |
|
[KEV] Code Injection in Hewlett packard (hp) hewlett-packard-hp (CVE-2013-4810)
code injection in Hewlett packard (hp) hewlett-packard-hp (CVE-2013-4810). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2009-1151 KEV |
|
[KEV] Code Injection in phpmyadmin (CVE-2009-1151)
code injection in phpmyadmin (CVE-2009-1151). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-25578 |
|
Code Injection in taogogo (CVE-2022-25578)
code injection in taogogo (CVE-2022-25578). Successful exploitation can lead to full system takeover.
|
| CVE-2022-24512 |
|
Code Injection in Microsoft.NETCore.App.Runtime.linux-arm (CVE-2022-24512)
code injection in Microsoft.NETCore.App.Runtime.linux-arm (CVE-2022-24512). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.3` or later.
|
| CVE-2020-8218 KEV |
|
[KEV] Code Injection in Pulse secure pulse-secure (CVE-2020-8218)
code injection in Pulse secure pulse-secure (CVE-2020-8218). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2013-1347 KEV |
|
[KEV] Code Injection in Microsoft internet-explorer (CVE-2013-1347)
code injection in Microsoft internet-explorer (CVE-2013-1347). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2012-1856 KEV |
|
[KEV] Code Injection in Microsoft office (CVE-2012-1856)
code injection in Microsoft office (CVE-2012-1856). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2010-0188 KEV |
|
[KEV] Code Injection in Adobe reader-and-acrobat (CVE-2010-0188)
code injection in Adobe reader-and-acrobat (CVE-2010-0188). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2009-3129 KEV |
|
[KEV] Code Injection in Microsoft excel (CVE-2009-3129)
code injection in Microsoft excel (CVE-2009-3129). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-25018 |
|
Code Injection in pluxml (CVE-2022-25018)
code injection in pluxml (CVE-2022-25018). Successful exploitation can lead to full system takeover.
|
| CVE-2014-6352 KEV |
|
[KEV] Code Injection in Microsoft windows (CVE-2014-6352)
code injection in Microsoft windows (CVE-2014-6352). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-9841 KEV |
|
[KEV] Code Injection in phpunit (CVE-2017-9841)
code injection in phpunit (CVE-2017-9841). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2013-3906 KEV |
|
[KEV] Code Injection in Microsoft graphics-component (CVE-2013-3906)
code injection in Microsoft graphics-component (CVE-2013-3906). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2015-1635 KEV |
|
[KEV] Code Injection in Microsoft httpsys (CVE-2015-1635)
code injection in Microsoft httpsys (CVE-2015-1635). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-46117 |
|
Code Injection in jpress (CVE-2021-46117)
code injection in jpress (CVE-2021-46117). Successful exploitation can lead to full system takeover.
|
| CVE-2021-46114 |
|
Code Injection in jpress (CVE-2021-46114)
code injection in jpress (CVE-2021-46114). Successful exploitation can lead to full system takeover.
|
| CVE-2021-46118 |
|
Code Injection in jpress (CVE-2021-46118)
code injection in jpress (CVE-2021-46118). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45806 |
|
Code Injection in jpress (CVE-2021-45806)
code injection in jpress (CVE-2021-45806). Successful exploitation can lead to full system takeover.
|
| CVE-2015-7450 KEV |
|
[KEV] Code Injection in Ibm websphere-application-server-and-server-hypervisor-edition (CVE-2015-7450)
code injection in Ibm websphere-application-server-and-server-hypervisor-edition (CVE-2015-7450). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-7609 KEV |
|
[KEV] Code Injection in Elastic kibana (CVE-2019-7609)
code injection in Elastic kibana (CVE-2019-7609). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0193 KEV |
|
[KEV] Code Injection in Apache solr (CVE-2019-0193)
code injection in Apache solr (CVE-2019-0193). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-43221 |
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
| CVE-2021-43208 |
|
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43209.
3D Viewer Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-43209.
|
| CVE-2021-42296 |
|
Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
|
| CVE-2021-42298 |
|
Microsoft Defender Remote Code Execution Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
|
| CVE-2021-22205 KEV |
|
[KEV] Code Injection in Gitlab community-and-enterprise-editions (CVE-2021-22205)
code injection in Gitlab community-and-enterprise-editions (CVE-2021-22205). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-4716 KEV |
|
[KEV] Code Injection in Ibm planning-analytics (CVE-2019-4716)
code injection in Ibm planning-analytics (CVE-2019-4716). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2012-0158 KEV |
|
[KEV] Code Injection in Microsoft mscomctlocx (CVE-2012-0158)
code injection in Microsoft mscomctlocx (CVE-2012-0158). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8644 KEV |
|
[KEV] Code Injection in playsms (CVE-2020-8644)
code injection in playsms (CVE-2020-8644). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8243 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2020-8243)
code injection in Ivanti pulse-connect-secure (CVE-2020-8243). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22900 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2021-22900)
code injection in Ivanti pulse-connect-secure (CVE-2021-22900). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22894 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2021-22894)
code injection in Ivanti pulse-connect-secure (CVE-2021-22894). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-9082 KEV |
|
[KEV] Vulnerability in thinkphp (CVE-2019-9082)
vulnerability in thinkphp (CVE-2019-9082). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-16759 KEV |
|
[KEV] Code Injection in vbulletin (CVE-2019-16759)
code injection in vbulletin (CVE-2019-16759). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25877 |
|
Code Injection in youphptube (CVE-2021-25877)
code injection in youphptube (CVE-2021-25877). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14853 |
|
The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attac...
The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attacker is able to run shell commands and receive valid output from the device.
|
| CVE-2017-17649 |
|
Code Injection in readymade-video-sharing-script-project (CVE-2017-17649)
code injection in readymade-video-sharing-script-project (CVE-2017-17649). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-16682 |
|
Code Injection in sap (CVE-2017-16682)
code injection in sap (CVE-2017-16682). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1336 |
|
Code Injection in ibm (CVE-2017-1336)
code injection in ibm (CVE-2017-1336). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-5713 |
|
Code Injection in puppet (CVE-2016-5713)
code injection in puppet (CVE-2016-5713). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14198 |
|
Code Injection in squiz (CVE-2017-14198)
code injection in squiz (CVE-2017-14198). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1001002 |
|
Code Injection in mathjs (CVE-2017-1001002)
code injection in mathjs (CVE-2017-1001002). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1001004 |
|
Code Injection in typed-function-project (CVE-2017-1001004)
code injection in typed-function-project (CVE-2017-1001004). Successful exploitation can lead to full system takeover.
|
| CVE-2017-16664 |
|
Code Injection in otrs (CVE-2017-16664)
code injection in otrs (CVE-2017-16664). Successful exploitation can lead to full system takeover.
|
| CVE-2017-16544 |
|
Code Injection in c (CVE-2017-16544)
code injection in c (CVE-2017-16544). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14077 |
|
Code Injection in phpcaptcha (CVE-2017-14077)
code injection in phpcaptcha (CVE-2017-14077). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-16871 |
|
Code Injection in wordpress (CVE-2017-16871)
code injection in wordpress (CVE-2017-16871). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1000196 |
|
Code Injection in octobercms (CVE-2017-1000196)
code injection in octobercms (CVE-2017-1000196). Successful exploitation can lead to full system takeover.
|
| CVE-2014-4000 |
|
Code Injection in cacti (CVE-2014-4000)
code injection in cacti (CVE-2014-4000). Successful exploitation can lead to full system takeover.
|
| CVE-2017-15806 |
|
Code Injection in zetacomponents (CVE-2017-15806)
code injection in zetacomponents (CVE-2017-15806). Successful exploitation can lead to full system takeover.
|