Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Xwiki HIGH 8.8
CVE-2023-29521

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitr…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29522

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitr…

Fix: 14.4.8 / 14.10.3+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29523

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile…

Fix: 13.10.11 / 14.4.8+
Fix from $1,950 2023-04-19
Xwiki HIGH 8.8
CVE-2023-29213

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-04-17
Vm2 CRITICAL 10.0
CVE-2023-30547EPSS 72%

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 …

Fix: after 3.9.16
Fix from $2,300 2023-04-17
Nashorn Sandbox HIGH 7.2
CVE-2023-26919

delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can …

No fix yet
Fix from $1,950 2023-04-10
Rav4 Firmware MEDIUM 6.8
CVE-2023-29389

Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle b…

No fix yet
Fix from $1,600 2023-04-05
Langchain CRITICAL 9.8
CVE-2023-29374EPSS 40%

In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.

Fix: after 0.0.131
Fix from $2,300 2023-04-05
Mastodon MEDIUM 6.5
CVE-2023-28853

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in vers…

Fix: 3.5.8 / 4.0.4+
Fix from $1,600 2023-04-04
Vantara Pentaho Business Analytics Server HIGH 7.2
CVE-2022-43769 KEVEPSS 98%

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property v…

Fix: 9.3.0.2+
Fix from $1,950 2023-04-03
Curl HIGH 8.8
CVE-2023-27533

A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously c…

Fix: after 7.881
Fix from $1,950 2023-03-30
Dataease HIGH 8.8
CVE-2023-28637

DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected …

Fix: 1.18.5+
Fix from $1,950 2023-03-28
Cocos Engine HIGH 8.8
CVE-2023-26493

Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `w…

Fix: 2023-02-20+
Fix from $1,950 2023-03-27
Simple Image Gallery Web App CRITICAL 9.8
CVE-2023-27040

Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.

No fix yet
Fix from $2,300 2023-03-16
Business Objects Business Intelligence Platform HIGH 8.8
CVE-2023-25616

In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection …

Mitigation only
Fix from $1,950 2023-03-14
Enovia Live Collaboration CRITICAL 9.8
CVE-2023-1287

An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.

No fix yet
Fix from $2,300 2023-03-09
Waap Cloud CRITICAL 9.8
CVE-2023-26261

In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user…

Fix: 6.5.6 / 6.11.0+
Fix from $2,300 2023-03-08
Xwiki CRITICAL 9.9
CVE-2023-27479

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…

Fix: 13.10.11 / 14.4.7+
Fix from $2,300 2023-03-07
Debmany HIGH 7.8
CVE-2023-27635

debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is…

Mitigation only
Fix from $1,950 2023-03-05
Xcode HIGH 7.8
CVE-2022-42797

An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.

Fix: 14.1+
Fix from $1,950 2023-02-27
Doctors Appointment System HIGH 8.8
CVE-2023-1059

A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the fil…

No fix yet
Fix from $1,950 2023-02-27
Doctors Appointment System HIGH 8.8
CVE-2023-1061

A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown p…

No fix yet
Fix from $1,950 2023-02-27
Carbon Black App Control HIGH 7.2
CVE-2023-20858EPSS 17%

VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious …

Fix: 8.7.8 / 8.8.6+
Fix from $1,950 2023-02-22
Kerby Ldap Backend CRITICAL 9.8
CVE-2023-25613

An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. 

Fix: 2.0.3+
Fix from $2,300 2023-02-20
Security Verify Access MEDIUM 6.5
CVE-2022-36775

IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation …

Patch available
Fix from $1,600 2023-02-17
Fortiproxy MEDIUM 5.4
CVE-2022-42472

A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 throu…

Fix: after 7.0.8
Fix from $1,600 2023-02-16
Node.js MEDIUM 5.4
CVE-2023-23936

Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP he…

Fix: 5.19.1 / 16.19.1+
Fix from $1,600 2023-02-16
Sling Jcr Base HIGH 7.5
CVE-2023-25141

Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility funct…

Fix: 3.1.12+
Fix from $1,950 2023-02-14
Control HIGH 8.8
CVE-2023-25719

ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl…

Fix: 22.9.10032+
Fix from $1,950 2023-02-13
Wrangler HIGH 7.5
CVE-2022-43756

A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote atta…

Fix: 0.7.4 / 0.8.5+
Fix from $1,950 2023-02-07