Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
E Health Care System HIGH 7.5
CVE-2024-10810

A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file …

No fix yet
Fix from $1,950 2024-11-05
E Health Care System HIGH 7.5
CVE-2024-10808

A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the f…

No fix yet
Fix from $1,950 2024-11-05
E Health Care System HIGH 7.5
CVE-2024-10809

A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the fil…

No fix yet
Fix from $1,950 2024-11-05
University Event Management System HIGH 8.8
CVE-2024-10805

A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part o…

No fix yet
Fix from $1,950 2024-11-04
Hospital Appointment System CRITICAL 9.8
CVE-2024-10791

A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown proces…

No fix yet
Fix from $2,300 2024-11-04
Online Shopping Portal MEDIUM 5.4
CVE-2024-10768

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /ad…

No fix yet
Fix from $1,600 2024-11-04
Pet Shop Management System CRITICAL 9.8
CVE-2024-10752

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file /p…

No fix yet
Fix from $2,300 2024-11-04
University Event Management System CRITICAL 9.8
CVE-2024-10700

A vulnerability was found in code-projects University Event Management System 1.0. It has been declared as critical. This vulnerability affects unkno…

No fix yet
Fix from $2,300 2024-11-02
Ac6 Firmware CRITICAL 9.8
CVE-2024-10697EPSS 26%

A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of…

No fix yet
Fix from $2,300 2024-11-02
Express MEDIUM 5.3
CVE-2024-10491

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanit…

Fix: 3.21.5+
Fix from $1,600 2024-10-29
Langchain CRITICAL 9.8
CVE-2024-8309EPSS 14%

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulne…

Patch available
Fix from $2,300 2024-10-29
Lunary MEDIUM 6.5
CVE-2024-7472

lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (…

Patch available
Fix from $1,600 2024-10-29
Plenti HIGH 7.5
CVE-2024-49380

Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an …

Fix: 0.7.2+
Fix from $1,950 2024-10-25
Plenti HIGH 7.5
CVE-2024-49381

Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to …

Fix: 0.7.2+
Fix from $1,950 2024-10-25
Boat Booking System CRITICAL 9.8
CVE-2024-10157

A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the fil…

No fix yet
Fix from $2,300 2024-10-19
Boat Booking System CRITICAL 9.8
CVE-2024-10153

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functio…

No fix yet
Fix from $2,300 2024-10-19
Unclassified HIGH 8.1
CVE-2024-48918

RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prior to 1.1.0 contain a vulnerab…

Patch available
Fix from $1,950 2024-10-16
Unclassified MEDIUM 6.9
CVE-2024-47764

cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in a…

Patch available
Fix from $1,600 2024-10-04
Incontrol Web HIGH 8.8
CVE-2024-9324

A vulnerability was found in Intelbras InControl up to 2.21.57. It has been rated as critical. Affected by this issue is some unknown functionality o…

Fix: 2.21.58+
Fix from $1,950 2024-09-29
Unclassified HIGH 8.8
CVE-2024-47180

Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of…

Patch available
Fix from $1,950 2024-09-26
Dataease CRITICAL 9.8
CVE-2024-46997

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a ca…

Fix: 2.10.1+
Fix from $2,300 2024-09-23
Sofa Hessian CRITICAL 9.8
CVE-2024-46983

sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to res…

Fix: 3.5.5+
Fix from $2,300 2024-09-19
Couchbase Server MEDIUM 6.1
CVE-2024-25673

Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

Fix: 7.2.6 / 7.6.2+
Fix from $1,600 2024-09-19
Camaleon Cms CRITICAL 9.9
CVE-2024-46986EPSS 37%

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upl…

Fix: 2.8.2+
Fix from $2,300 2024-09-18
Contao MEDIUM 5.3
CVE-2024-45612

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the we…

Fix: 4.13.49 / 5.3.15+
Fix from $1,600 2024-09-17
Limesurvey MEDIUM 6.5
CVE-2024-42903

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted…

Fix: after 6.6.1
Fix from $1,600 2024-09-03
Overleaf MEDIUM 5.3
CVE-2024-45312

Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) co…

Fix: 4.2.7 / 5.0.7+
Fix from $1,600 2024-09-02
Wolfssl HIGH 8.8
CVE-2024-2881

Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remo…

Mitigation only
Fix from $1,950 2024-08-30
Wolfssl HIGH 8.8
CVE-2024-1545

Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote …

Patch available
Fix from $1,950 2024-08-29
Restsharp HIGH 7.8
CVE-2024-45302

RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF inje…

Fix: 112.0.0+
Fix from $1,950 2024-08-29