Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.1 CVE-2024-42914 A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host head… Arrowcms No fix yet Fix from $2,3002024-08-23 CRITICAL 9.8 CVE-2024-43782 This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pullin… Openedx Patch available Fix from $2,3002024-08-23 CRITICAL 10.0 CVE-2024-42472 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app us… Debian Linux 1.14.10 / 1.15.10+ Fix from $2,3002024-08-15 MEDIUM 6.5 CVE-2024-31882 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default conf… Db2 after 11.5.9 Fix from $1,6002024-08-14 HIGH 8.8 CVE-2024-42489 Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` pag… Pro Macros 1.10.1+ Fix from $1,9502024-08-12 CRITICAL 9.8 CVE-2024-39227 GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4… Mt6000 Firmware No fix yet Fix from $2,3002024-08-06 MEDIUM 6.5 CVE-2024-6331 stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The in… Devika No fix yet Fix from $1,6002024-08-04 CRITICAL 9.6 CVE-2024-41127 Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-f… Monkeytype 24.30.0+ Fix from $2,3002024-08-02 MEDIUM 6.1 CVE-2024-39320 Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any doma… Discourse 3.2.5+ Fix from $1,6002024-07-30 CRITICAL 9.8 CVE-2024-7221 A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. This affects an unknown part of the file /admin/manage_u… School Log Management System No fix yet Fix from $2,3002024-07-30 CRITICAL 9.8 CVE-2024-7219 A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionali… School Log Management System No fix yet Fix from $2,3002024-07-30 CRITICAL 9.8 CVE-2024-7220 A vulnerability was found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this issue is some unknown functionality of the f… School Log Management System No fix yet Fix from $2,3002024-07-30 MEDIUM 5.4 CVE-2024-40324 A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leadi… E Staff No fix yet Fix from $1,6002024-07-25 MEDIUM 5.5 CVE-2024-40137 Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under th… Mitigation only Fix from $1,6002024-07-24 HIGH 8.8 CVE-2024-26020EPSS 15% An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbi… Anki No fix yet Fix from $1,9502024-07-22 CRITICAL 9.8 CVE-2024-6933 A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file… Limesurvey 6.6.2+ Fix from $2,3002024-07-21 HIGH 8.8 CVE-2024-41121 Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicio… Woodpecker 2.7.0+ Fix from $1,9502024-07-19 HIGH 8.8 CVE-2024-41122 Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicio… Woodpecker 2.7.0+ Fix from $1,9502024-07-19 HIGH 8.3 CVE-2024-39906 A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functi… Patch available Fix from $1,9502024-07-19 HIGH 7.2 CVE-2024-41111 Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security test… Patch available Fix from $1,9502024-07-18 HIGH 7.2 CVE-2024-20429 A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to exec… Asyncos Mitigation only Fix from $1,9502024-07-17 HIGH 7.8 CVE-2024-40637 dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a us… Dbt Core 1.6.14 / 1.7.14+ Fix from $1,9502024-07-16 MEDIUM 6.5 CVE-2024-38700 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in realmag777 WPCS allows Code Injec… Mitigation only Fix from $1,6002024-07-12 CRITICAL 9.8 CVE-2024-36522 The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste… Wicket 8.16.0 / 9.18.0+ Fix from $2,3002024-07-12 MEDIUM 5.5 CVE-2024-37442 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery … Photo Gallery 5.7.1+ Fix from $1,6002024-07-09 HIGH 8.8 CVE-2024-6469 A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the fi… Playsms No fix yet Fix from $1,9502024-07-03 CRITICAL 10.0 CVE-2024-38366EPSS 18% trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real em… Trunk.cocoapods.org 2023-09-22+ Fix from $2,3002024-07-01 HIGH 7.5 CVE-2024-36420 Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-… Flowise No fix yet Fix from $1,9502024-07-01 CRITICAL 9.8 CVE-2024-39704 Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a cli… Melty Blood Actress Again Current Code after 1.07 Fix from $2,3002024-06-28 CRITICAL 9.8 CVE-2024-39243 An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save. Skycaiji Mitigation only Fix from $2,3002024-06-26