Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Langchain CRITICAL 9.8
CVE-2023-38896

An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colore…

Fix: after 0.0.194
Fix from $2,300 2023-08-15
Langchain CRITICAL 9.8
CVE-2023-39659

An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLT…

Fix: after 0.0.232
Fix from $2,300 2023-08-15
Churchcrm HIGH 8.8
CVE-2020-28848

CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.

No fix yet
Fix from $1,950 2023-08-11
Checkmk HIGH 8.8
CVE-2023-31209

Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authe…

Fix: 2.0.0+
Fix from $1,950 2023-08-10
Lindell17 HIGH 8.1
CVE-2023-33242

Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in …

No fix yet
Fix from $1,950 2023-08-09
Gg18 CRITICAL 9.1
CVE-2023-33241

Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallie…

No fix yet
Fix from $2,300 2023-08-09
Virtual Desktop Infrastructure CRITICAL 9.8
CVE-2023-39213

Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to…

Fix: 5.15.2+
Fix from $2,300 2023-08-08
Motocms CRITICAL 9.8
CVE-2023-36210EPSS 31%

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword paramet…

No fix yet
Fix from $2,300 2023-08-01
macOS HIGH 7.5
CVE-2023-38609

An injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass certain Priv…

Fix: 13.5+
Fix from $1,950 2023-07-28
Otrs HIGH 8.8
CVE-2023-38060

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic I…

Fix: 7.0.45 / 8.0.35+
Fix from $1,950 2023-07-24
Swoole MEDIUM 6.5
CVE-2020-24275

A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.

Patch available
Fix from $1,600 2023-07-20
Grav HIGH 8.8
CVE-2023-37897

Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vu…

Patch available
Fix from $1,950 2023-07-18
House Rental And Property Listing CRITICAL 9.8
CVE-2023-3694

A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Property Listing 1.0. This issue a…

No fix yet
Fix from $2,300 2023-07-17
Collection HIGH 8.8
CVE-2023-37473

zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing _callable strings_ (ie `system`) caused the functio…

Patch available
Fix from $1,950 2023-07-14
Xwiki HIGH 8.8
CVE-2023-37462EPSS 91%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode…

Fix: 14.4.8 / 14.10.4+
Fix from $1,950 2023-07-14
Sqlfluff HIGH 7.8
CVE-2023-36830

SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files, there is a potential securit…

Fix: 2.1.2+
Fix from $1,950 2023-07-06
Langchain CRITICAL 9.8
CVE-2023-36188

An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.

Patch available
Fix from $2,300 2023-07-06
Opentsdb CRITICAL 9.8
CVE-2023-36812EPSS 17%

OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writin…

Fix: 2.4.2+
Fix from $2,300 2023-06-30
Pacparser MEDIUM 6.1
CVE-2023-37360

pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (wh…

Fix: 1.4.2+
Fix from $1,600 2023-06-30
Xwiki HIGH 8.8
CVE-2023-36469EPSS 82%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile…

Fix: 14.10.6+
Fix from $1,950 2023-06-29
Xwiki HIGH 8.8
CVE-2023-36470

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an exist…

Fix: 14.10.6+
Fix from $1,950 2023-06-29
Commons MEDIUM 5.4
CVE-2023-36471

Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowe…

Fix: 14.10.6+
Fix from $1,600 2023-06-29
Openedge HIGH 8.8
CVE-2023-34203

In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a U…

Fix: 11.7.16 / 12.2.12+
Fix from $1,950 2023-06-23
Wn579x3 Firmware CRITICAL 9.8
CVE-2023-3380

A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi…

Fix: after 2023-06-15
Fix from $2,300 2023-06-23
Bigfix Osd Bare Metal Server MEDIUM 6.1
CVE-2023-28016

Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause …

Fix: after 311.12
Fix from $1,600 2023-06-22
Sugarcrm HIGH 7.2
CVE-2023-35810

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been ident…

Fix: 11.0.6 / 12.0.3+
Fix from $1,950 2023-06-17
Mattermost MEDIUM 6.5
CVE-2023-2797

Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink…

Fix: after 7.8.4
Fix from $1,600 2023-06-16
Zoom MEDIUM 6.5
CVE-2023-28598

Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in …

Fix: 5.13.10+
Fix from $1,600 2023-06-13
Go CRITICAL 9.8
CVE-2023-29405

The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…

Fix: 1.19.10 / 1.20.5+
Fix from $2,300 2023-06-08
Email Templates HIGH 8.8
CVE-2019-25150

The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers …

Fix: 1.3.1+
Fix from $1,950 2023-06-07