Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Arrowcms CRITICAL 9.1
CVE-2024-42914

A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host head…

No fix yet
Fix from $2,300 2024-08-23
Openedx CRITICAL 9.8
CVE-2024-43782

This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pullin…

Patch available
Fix from $2,300 2024-08-23
Debian Linux CRITICAL 10.0
CVE-2024-42472

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app us…

Fix: 1.14.10 / 1.15.10+
Fix from $2,300 2024-08-15
Db2 MEDIUM 6.5
CVE-2024-31882

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default conf…

Fix: after 11.5.9
Fix from $1,600 2024-08-14
Pro Macros HIGH 8.8
CVE-2024-42489

Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` pag…

Fix: 1.10.1+
Fix from $1,950 2024-08-12
Mt6000 Firmware CRITICAL 9.8
CVE-2024-39227

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…

No fix yet
Fix from $2,300 2024-08-06
Devika MEDIUM 6.5
CVE-2024-6331

stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The in…

No fix yet
Fix from $1,600 2024-08-04
Monkeytype CRITICAL 9.6
CVE-2024-41127

Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-f…

Fix: 24.30.0+
Fix from $2,300 2024-08-02
Discourse MEDIUM 6.1
CVE-2024-39320

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any doma…

Fix: 3.2.5+
Fix from $1,600 2024-07-30
School Log Management System CRITICAL 9.8
CVE-2024-7221

A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. This affects an unknown part of the file /admin/manage_u…

No fix yet
Fix from $2,300 2024-07-30
School Log Management System CRITICAL 9.8
CVE-2024-7219

A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionali…

No fix yet
Fix from $2,300 2024-07-30
School Log Management System CRITICAL 9.8
CVE-2024-7220

A vulnerability was found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this issue is some unknown functionality of the f…

No fix yet
Fix from $2,300 2024-07-30
E Staff MEDIUM 5.4
CVE-2024-40324

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leadi…

No fix yet
Fix from $1,600 2024-07-25
Unclassified MEDIUM 5.5
CVE-2024-40137

Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under th…

Mitigation only
Fix from $1,600 2024-07-24
Anki HIGH 8.8
CVE-2024-26020EPSS 15%

An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbi…

No fix yet
Fix from $1,950 2024-07-22
Limesurvey CRITICAL 9.8
CVE-2024-6933

A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file…

Fix: 6.6.2+
Fix from $2,300 2024-07-21
Woodpecker HIGH 8.8
CVE-2024-41121

Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicio…

Fix: 2.7.0+
Fix from $1,950 2024-07-19
Woodpecker HIGH 8.8
CVE-2024-41122

Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicio…

Fix: 2.7.0+
Fix from $1,950 2024-07-19
Unclassified HIGH 8.3
CVE-2024-39906

A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functi…

Patch available
Fix from $1,950 2024-07-19
Unclassified HIGH 7.2
CVE-2024-41111

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security test…

Patch available
Fix from $1,950 2024-07-18
Asyncos HIGH 7.2
CVE-2024-20429

A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to exec…

Mitigation only
Fix from $1,950 2024-07-17
Dbt Core HIGH 7.8
CVE-2024-40637

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a us…

Fix: 1.6.14 / 1.7.14+
Fix from $1,950 2024-07-16
Unclassified MEDIUM 6.5
CVE-2024-38700

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in realmag777 WPCS allows Code Injec…

Mitigation only
Fix from $1,600 2024-07-12
Wicket CRITICAL 9.8
CVE-2024-36522

The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste…

Fix: 8.16.0 / 9.18.0+
Fix from $2,300 2024-07-12
Photo Gallery MEDIUM 5.5
CVE-2024-37442

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery …

Fix: 5.7.1+
Fix from $1,600 2024-07-09
Playsms HIGH 8.8
CVE-2024-6469

A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the fi…

No fix yet
Fix from $1,950 2024-07-03
Trunk.cocoapods.org CRITICAL 10.0
CVE-2024-38366EPSS 18%

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real em…

Fix: 2023-09-22+
Fix from $2,300 2024-07-01
Flowise HIGH 7.5
CVE-2024-36420

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-…

No fix yet
Fix from $1,950 2024-07-01
Melty Blood Actress Again Current Code CRITICAL 9.8
CVE-2024-39704

Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a cli…

Fix: after 1.07
Fix from $2,300 2024-06-28
Skycaiji CRITICAL 9.8
CVE-2024-39243

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

Mitigation only
Fix from $2,300 2024-06-26