Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
B.point HIGH 7.2
CVE-2023-49328

On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote co…

Mitigation only
Fix from $1,950 2023-12-25
Restaurant Table Booking System CRITICAL 9.8
CVE-2023-7100

A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of th…

No fix yet
Fix from $2,300 2023-12-25
Faculty Management System CRITICAL 9.8
CVE-2023-7096

A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. Th…

No fix yet
Fix from $2,300 2023-12-25
Smart S210 Firmware CRITICAL 9.8
CVE-2023-7039EPSS 14%

A vulnerability classified as critical has been found in Byzoro S210 up to 20231210. Affected is an unknown function of the file /importexport.php. T…

Fix: after 2023-12-10
Fix from $2,300 2023-12-21
Informix Jdbc CRITICAL 9.8
CVE-2023-35895

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert…

Mitigation only
Fix from $2,300 2023-12-20
Glpi CRITICAL 9.8
CVE-2023-46726

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…

Fix: 10.0.11+
Fix from $2,300 2023-12-13
Searchor CRITICAL 9.8
CVE-2023-43364

main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

Fix: 2.4.2+
Fix from $2,300 2023-12-12
Gl Ar300m Firmware CRITICAL 9.8
CVE-2023-46456EPSS 25%

In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionali…

Mitigation only
Fix from $2,300 2023-12-12
Alfresco Content Services HIGH 8.8
CVE-2023-49964EPSS 35%

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attack…

Fix: after 7.2.0
Fix from $1,950 2023-12-11
Nipah Virus Testing Management System CRITICAL 9.8
CVE-2023-6648

A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of…

No fix yet
Fix from $2,300 2023-12-10
Appointment Scheduler HIGH 8.8
CVE-2023-48841

Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

No fix yet
Fix from $1,950 2023-12-07
Shuttle Booking Software HIGH 8.8
CVE-2023-48830

Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.

No fix yet
Fix from $1,950 2023-12-07
Car Rental Script HIGH 8.8
CVE-2023-48835

Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

No fix yet
Fix from $1,950 2023-12-07
Time Slots Booking Calendar HIGH 8.8
CVE-2023-48826

Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.

No fix yet
Fix from $1,950 2023-12-07
Leave Management System MEDIUM 5.3
CVE-2023-48205

Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.

No fix yet
Fix from $1,600 2023-12-07
Mattermost Server CRITICAL 9.8
CVE-2023-6458

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traver…

Fix: 7.8.14 / 8.1.5+
Fix from $2,300 2023-12-06
Confluence Data Center HIGH 8.8
CVE-2023-22522EPSS 13%

This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confl…

Fix: 7.19.17 / 8.4.5+
Fix from $1,950 2023-12-06
Mattermost MEDIUM 5.4
CVE-2023-35075

Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML…

Fix: after 8.1.3
Fix from $1,600 2023-11-27
Usedesk CRITICAL 9.8
CVE-2023-49214

Usedesk before 1.7.57 allows chat template injection.

Fix: 1.7.57+
Fix from $2,300 2023-11-23
Five Star Restaurant Menu CRITICAL 9.8
CVE-2023-5340

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticate…

Fix: 2.4.11+
Fix from $2,300 2023-11-20
Derby CRITICAL 9.8
CVE-2022-46337

A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up …

Fix: 10.14.3.0 / 10.15.2.1+
Fix from $2,300 2023-11-20
Wireshark MEDIUM 6.5
CVE-2023-6174

SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file

Fix: after 4.0.10
Fix from $1,600 2023-11-16
Grocy HIGH 7.8
CVE-2023-48199

HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script exec…

No fix yet
Fix from $1,950 2023-11-15
6gk5205 3bb00 2ab2 Firmware CRITICAL 9.1
CVE-2023-44373

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject…

Fix: 4.5+
Fix from $2,300 2023-11-14
Discourse MEDIUM 6.1
CVE-2023-47119

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` an…

Fix: 3.1.3 / 3.2.0+
Fix from $1,600 2023-11-10
Magnesium Php CRITICAL 9.8
CVE-2017-20187

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the functi…

Fix: after 0.3.0
Fix from $2,300 2023-11-05
Manageengine Desktop Central MEDIUM 6.1
CVE-2023-4767

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…

Mitigation only
Fix from $1,600 2023-11-03
Dolibarr Erp\/crm HIGH 8.8
CVE-2023-4197EPSS 33%

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing a…

Fix: after 18.0.1
Fix from $1,950 2023-11-01
Liquidfiles MEDIUM 6.1
CVE-2023-4393

HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attac…

Fix: 3.7.14+
Fix from $1,600 2023-10-30
Juzaweb Cms HIGH 7.8
CVE-2023-46468

An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.

Fix: after 3.4
Fix from $1,950 2023-10-28