Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Action Launcher MEDIUM 5.5
CVE-2022-47028

An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function inse…

No fix yet
Fix from $1,600 2023-05-30
Pydio Cells HIGH 8.8
CVE-2023-2980

A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creatio…

No fix yet
Fix from $1,950 2023-05-30
Apache Airflow Providers Cncf Kubernetes HIGH 7.2
CVE-2023-33234

Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow …

Fix: 7.0.0+
Fix from $1,950 2023-05-30
Cpp Httplib HIGH 8.8
CVE-2023-26130

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type …

Fix: 0.12.4+
Fix from $1,950 2023-05-30
Craft Cms HIGH 7.2
CVE-2023-32679

Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execu…

Fix: 4.4.6+
Fix from $1,950 2023-05-19
Vm2 MEDIUM 5.3
CVE-2023-32313

vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write re…

Fix: 3.9.18+
Fix from $1,600 2023-05-15
Vm2 CRITICAL 10.0
CVE-2023-32314EPSS 8%

vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and includ…

Fix: 3.9.18+
Fix from $2,300 2023-05-15
Go HIGH 7.3
CVE-2023-24539

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/'…

Fix: 1.19.9 / 1.20.4+
Fix from $1,950 2023-05-11
Go HIGH 7.3
CVE-2023-29400

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results w…

Fix: 1.19.9 / 1.20.4+
Fix from $1,950 2023-05-11
Ranger HIGH 8.8
CVE-2022-45048

Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affe…

Mitigation only
Fix from $1,950 2023-05-05
Ejs CRITICAL 9.8
CVE-2023-29827EPSS 6%

ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the config…

Patch available
Fix from $2,300 2023-05-04
Streampark MEDIUM 5.4
CVE-2022-45801

Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that constru…

Fix: 2.0.0+
Fix from $1,600 2023-05-01
Er X Firmware HIGH 7.2
CVE-2023-2377EPSS 8%

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Manageme…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Er X Firmware HIGH 7.2
CVE-2023-2378EPSS 8%

A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Er X Firmware HIGH 7.2
CVE-2023-2376EPSS 8%

A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the componen…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Er X Firmware HIGH 7.2
CVE-2023-2374EPSS 7%

A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Ma…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Er X Firmware HIGH 7.2
CVE-2023-2375EPSS 9%

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interfa…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Edgemax Edgerouter Firmware HIGH 7.2
CVE-2023-2373EPSS 8%

A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of the component Web Management…

Fix: 2.0.9+
Fix from $1,950 2023-04-28
Git HIGH 7.8
CVE-2023-29007EPSS 6%

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a spe…

Fix: 2.30.9 / 2.31.8+
Fix from $1,950 2023-04-25
Strapi HIGH 7.2
CVE-2023-22621EPSS 77%

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remo…

Fix: 4.5.6+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29524EPSS 76%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the r…

Fix: 14.10.3+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29525EPSS 78%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to co…

Fix: 14.4.8 / 14.10.3+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29526

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to displa…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29527

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script o…

Fix: 14.10.3+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29510

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every user can add translations th…

Fix: 14.10.2+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29512

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., i…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29514

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on any document (e…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29516EPSS 66%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.Attachme…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29518

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitr…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29519

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code ex…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19