Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Datagear CRITICAL 9.8
CVE-2024-37759

DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing int…

Fix: after 5.0.0
Fix from $2,300 2024-06-24
Product Addons \& Fields For Woocommerce MEDIUM 5.3
CVE-2024-35728

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce al…

Fix: 32.0.21+
Fix from $1,600 2024-06-10
Emailgpt CRITICAL 9.1
CVE-2024-5184

The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct promp…

Mitigation only
Fix from $2,300 2024-06-05
Spectra MEDIUM 5.3
CVE-2023-23738

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows C…

Fix: 2.3.1+
Fix from $1,600 2024-06-03
Ghost HIGH 8.8
CVE-2024-34448

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

Fix: 5.82.0+
Fix from $1,950 2024-05-22
Tinyweb MEDIUM 5.3
CVE-2024-5193

A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of the component Request Handler. …

Patch available
Fix from $1,600 2024-05-22
Unclassified CRITICAL 9.8
CVE-2024-34919

An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows atta…

Mitigation only
Fix from $2,300 2024-05-17
Freescout MEDIUM 6.1
CVE-2024-34697

FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module…

Fix: 1.8.139+
Fix from $1,600 2024-05-14
Unclassified CRITICAL 9.6
CVE-2024-32986

PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app propertie…

Patch available
Fix from $2,300 2024-05-03
Vtiger Crm HIGH 8.1
CVE-2023-46304

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint …

Patch available
Fix from $1,950 2024-04-30
Itop HIGH 8.0
CVE-2023-48709

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious …

Fix: 2.7.9 / 3.0.4+
Fix from $1,950 2024-04-15
News Portal Project HIGH 8.8
CVE-2024-3767

A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.…

No fix yet
Fix from $1,950 2024-04-15
Contao MEDIUM 5.4
CVE-2024-28191

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert…

Fix: 4.13.40 / 5.3.4+
Fix from $1,600 2024-04-09
Xxl Job CRITICAL 9.8
CVE-2024-3366

A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file c…

Fix: 2.4.1+
Fix from $2,300 2024-04-06
Swift Prometheus HIGH 7.4
CVE-2024-28867

Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-saniti…

Patch available
Fix from $1,950 2024-03-29
Astro Shield HIGH 7.5
CVE-2024-29896

Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation …

Patch available
Fix from $1,950 2024-03-28
Online Marriage Registration System MEDIUM 6.5
CVE-2024-2777

A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical. Affected by this vulnerabi…

No fix yet
Fix from $1,600 2024-03-22
Complete Online Beauty Parlor Management System MEDIUM 6.5
CVE-2024-2769

A vulnerability was detected in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the fil…

No fix yet
Fix from $1,600 2024-03-21
Parse Server CRITICAL 9.0
CVE-2024-29027

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, c…

Fix: 6.5.5+
Fix from $2,300 2024-03-19
Ldap Account Manager MEDIUM 6.6
CVE-2024-23333EPSS 18%

LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary pat…

Fix: 8.7+
Fix from $1,600 2024-03-18
Mattermost Server MEDIUM 6.1
CVE-2024-2445

Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 …

Fix: 8.1.10 / 9.2.6+
Fix from $1,600 2024-03-15
Turboboost Commands HIGH 8.1
CVE-2024-28181

turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing prote…

Fix: 0.1.3 / 0.2.2+
Fix from $1,950 2024-03-14
Your Spotify MEDIUM 5.3
CVE-2024-28192

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQL injection in the public acc…

Fix: 1.8.0+
Fix from $1,600 2024-03-13
Peering Manager CRITICAL 9.1
CVE-2024-28114

Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peer…

Fix: 1.8.3+
Fix from $2,300 2024-03-12
Android MEDIUM 6.7
CVE-2024-0044

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to loc…

Patch available
Fix from $1,600 2024-03-11
Qts MEDIUM 6.5
CVE-2024-21900EPSS 9%

An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authentica…

Fix: 5.1.3.2578+
Fix from $1,600 2024-03-08
macOS HIGH 7.8
CVE-2024-23268

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.…

Fix: 12.7.4 / 13.6.5+
Fix from $1,950 2024-03-08
macOS HIGH 7.8
CVE-2024-23274

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.…

Fix: 12.7.4 / 13.6.5+
Fix from $1,950 2024-03-08
Safari MEDIUM 6.5
CVE-2024-23280

An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4…

Fix: 2.44.0 / 10.4+
Fix from $1,600 2024-03-08
Pdf Invoices And Packing Slips For Woocommerce HIGH 8.8
CVE-2024-1773

The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1…

Fix: 1.3.8+
Fix from $1,950 2024-03-07