Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Ingress Nginx HIGH 8.8
CVE-2023-5043

Ingress nginx annotation injection causes arbitrary command execution.

Fix: 1.9.0+
Fix from $1,950 2023-10-25
Langchain HIGH 7.5
CVE-2023-32786

In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing …

Fix: after 0.0.155
Fix from $1,950 2023-10-20
Mintty CRITICAL 9.8
CVE-2022-47583

Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.

Fix: 3.6.3+
Fix from $2,300 2023-10-19
Leave Management System MEDIUM 6.5
CVE-2023-45540

An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of…

No fix yet
Fix from $1,600 2023-10-16
Inlong HIGH 7.5
CVE-2023-43667

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects …

Fix: after 1.8.0
Fix from $1,950 2023-10-16
Cachet HIGH 8.8
CVE-2023-43661EPSS 47%

Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to e…

Fix: 2.4+
Fix from $1,950 2023-10-11
Harmonyos HIGH 7.5
CVE-2023-44109

Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-10-11
Thingsboard HIGH 8.8
CVE-2023-45303

ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports fre…

Fix: 3.5+
Fix from $1,950 2023-10-06
Openshift Container Platform MEDIUM 5.3
CVE-2022-4145

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, e…

Mitigation only
Fix from $1,600 2023-10-05
Endpoint Security HIGH 7.8
CVE-2023-3665

A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via envir…

Fix: after 10.7.0
Fix from $1,950 2023-10-04
Super Store Finder HIGH 8.8
CVE-2023-43835

Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings o…

Fix: after 3.7
Fix from $1,950 2023-10-02
Phpipam HIGH 7.5
CVE-2023-41580

Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerabi…

Fix: 1.5.2+
Fix from $1,950 2023-10-02
Postcss MEDIUM 5.3
CVE-2023-44270

An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can pr…

Fix: 8.4.31+
Fix from $1,600 2023-09-29
Debian Linux HIGH 8.8
CVE-2023-43655

Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed …

Fix: 1.10.27 / 2.2.21+
Fix from $1,950 2023-09-29
Best Courier Management System HIGH 8.8
CVE-2023-5269

A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function o…

No fix yet
Fix from $1,950 2023-09-29
Libhv MEDIUM 5.3
CVE-2023-26148

All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can …

No fix yet
Fix from $1,600 2023-09-29
Hookshot CRITICAL 9.0
CVE-2023-43656

matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation f…

Fix: 4.5.0+
Fix from $2,300 2023-09-27
Flink Stateful Functions MEDIUM 6.1
CVE-2023-41834

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject…

Fix: after 3.2.0
Fix from $1,600 2023-09-19
Gnome Time Tracker HIGH 7.8
CVE-2023-36250

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating…

No fix yet
Fix from $1,950 2023-09-14
Crow MEDIUM 6.1
CVE-2023-26142

All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values ar…

No fix yet
Fix from $1,600 2023-09-12
Internet Reservation Module Next Generation HIGH 8.8
CVE-2023-39424

A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such…

Mitigation only
Fix from $1,950 2023-09-07
Snapd CRITICAL 10.0
CVE-2023-1523

Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause ar…

Fix: 2.59.5+
Fix from $2,300 2023-09-01
Restrictedpython HIGH 7.7
CVE-2023-41039

RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling t…

Fix: 5.4 / 6.2+
Fix from $1,950 2023-08-30
Mattermost Server HIGH 8.2
CVE-2023-4478

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thu…

Fix: 7.8.9 / 7.10.5+
Fix from $1,950 2023-08-25
Craft Cms HIGH 7.2
CVE-2023-40035

Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code e…

Fix: 3.8.15 / 4.4.15+
Fix from $1,950 2023-08-23
Xl824 Firmware MEDIUM 6.8
CVE-2023-4212

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as …

Fix: after 5.9.8
Fix from $1,600 2023-08-22
Jimureport CRITICAL 9.8
CVE-2023-4450EPSS 12%

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functio…

Fix: 1.6.1+
Fix from $2,300 2023-08-21
Terramaster Operating System CRITICAL 9.8
CVE-2022-24989EPSS 32%

TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Objec…

Fix: 4.2.31+
Fix from $2,300 2023-08-20
Pandasai CRITICAL 9.8
CVE-2023-39661

An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.

Fix: after 0.9.1
Fix from $2,300 2023-08-15
Llamaindex CRITICAL 9.8
CVE-2023-39662

An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.

Fix: after 0.7.13
Fix from $2,300 2023-08-15