Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Command Centre MEDIUM 5.4
CVE-2024-21838

Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML c…

Fix: 8.70.2526 / 8.80.1526+
Fix from $1,600 2024-03-05
Security HIGH 8.8
CVE-2024-1619

Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an a…

Fix: after 8.0.3.30
Fix from $1,950 2024-02-29
James Mime4j MEDIUM 5.3
CVE-2024-21742

Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an atta…

Fix: after 0.8.9
Fix from $1,600 2024-02-27
Employee Management System CRITICAL 9.8
CVE-2024-1833

A vulnerability was found in SourceCodester Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functio…

No fix yet
Fix from $2,300 2024-02-23
Hertzbeat CRITICAL 9.8
CVE-2023-51388

Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no …

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Hertzbeat CRITICAL 9.8
CVE-2023-51653

Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec…

Fix: 1.4.1+
Fix from $2,300 2024-02-22
Mantisbt HIGH 8.3
CVE-2024-23830

MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hija…

Fix: 2.26.1+
Fix from $1,950 2024-02-20
Admin Classic Bundle CRITICAL 9.3
CVE-2024-25625

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic…

Fix: 1.3.4+
Fix from $2,300 2024-02-19
Operational Decision Manager CRITICAL 9.8
CVE-2024-22319EPSS 76%

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JND…

Patch available
Fix from $2,300 2024-02-02
Glpi HIGH 8.1
CVE-2023-51446

GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform L…

Fix: 10.0.12+
Fix from $1,950 2024-02-01
Relic HIGH 8.8
CVE-2023-51939

An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive informat…

Patch available
Fix from $1,950 2024-02-01
Craft Cms HIGH 7.5
CVE-2023-36260

An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings …

Fix: 4.6.1.1+
Fix from $1,950 2024-01-30
Nginx Ui HIGH 8.8
CVE-2024-23828

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when cha…

Fix: 2.0.0+
Fix from $1,950 2024-01-29
Admin Classic Bundle HIGH 8.8
CVE-2024-23648

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a pas…

Fix: 1.2.3+
Fix from $1,950 2024-01-24
X2000r Firmware CRITICAL 9.8
CVE-2024-0579

A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDe…

Mitigation only
Fix from $2,300 2024-01-16
Ark Wysiwyg Comment Editor MEDIUM 5.3
CVE-2021-4227

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to …

Fix: after 2.15.6
Fix from $1,600 2024-01-16
Confluence Data Center CRITICAL 9.8
CVE-2023-22527 KEVEPSS 100%

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an aff…

Fix: 8.5.4+
Fix from $2,300 2024-01-16
Paydroid HIGH 7.6
CVE-2023-4818

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PA…

No fix yet
Fix from $1,950 2024-01-15
Paydroid MEDIUM 6.8
CVE-2023-42135

PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypass…

Fix: after 8.1.0_sagittarius_11.1.50_20230614
Fix from $1,600 2024-01-15
Paydroid HIGH 7.8
CVE-2023-42136

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system …

Fix: after 8.1.0_sagittarius_11.1.50_20230614
Fix from $1,950 2024-01-15
Smartrobot CRITICAL 9.8
CVE-2024-0552

Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to e…

Fix: after 6.0.0-202012tw
Fix from $2,300 2024-01-15
Dgx A100 Firmware HIGH 7.5
CVE-2023-31025

NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead …

Fix: 00.22.05+
Fix from $1,950 2024-01-12
Pyload MEDIUM 5.3
CVE-2024-21645EPSS 25%

pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any una…

Fix: after 0.4.9
Fix from $1,600 2024-01-08
Ox App Suite CRITICAL 9.6
CVE-2023-29050

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the i…

Fix: 7.10.6+
Fix from $2,300 2024-01-08
Api Gateway Manager MEDIUM 6.1
CVE-2023-50093

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.

No fix yet
Fix from $1,600 2024-01-03
Couchauth CRITICAL 9.6
CVE-2023-39655

A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in…

Fix: after 0.20.0
Fix from $2,300 2024-01-03
Otclient CRITICAL 9.8
CVE-2024-21623

OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah/otclient "`Analysis - SonarC…

Fix: 2023-12-30+
Fix from $2,300 2024-01-02
Mattermost HIGH 8.8
CVE-2023-7114

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

Fix: 2.10.1+
Fix from $1,950 2023-12-29
Firefox Css MEDIUM 5.3
CVE-2023-52081

ffcss is a CLI interface to apply and configure Firefox CSS themes. Prior to 0.2.0, the function `lookupPreprocess()` is meant to apply some transfor…

Fix: 0.2.0+
Fix from $1,600 2023-12-28
Changed Files CRITICAL 9.8
CVE-2023-51664

tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows fo…

Fix: 41.0.0+
Fix from $2,300 2023-12-27