Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-37759
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing int…
Datagear
after 5.0.0
MEDIUM 5.3
CVE-2024-35728
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce al…
Product Addons \& Fields For Woocommerce
32.0.21+
CRITICAL 9.1
CVE-2024-5184
The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct promp…
Emailgpt
Mitigation only
MEDIUM 5.3
CVE-2023-23738
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows C…
Spectra
2.3.1+
HIGH 8.8
CVE-2024-34448
Ghost before 5.82.0 allows CSV Injection during a member CSV export.
Ghost
5.82.0+
MEDIUM 5.3
CVE-2024-5193
A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of the component Request Handler. …
Tinyweb
Patch available
CRITICAL 9.8
CVE-2024-34919
An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows atta…
Mitigation only
MEDIUM 6.1
CVE-2024-34697
FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module…
Freescout
1.8.139+
CRITICAL 9.6
CVE-2024-32986
PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app propertie…
Patch available
HIGH 8.1
CVE-2023-46304
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint …
Vtiger Crm
Patch available
HIGH 8.0
CVE-2023-48709
iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious …
Itop
2.7.9 / 3.0.4+
HIGH 8.8
CVE-2024-3767
A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.…
News Portal Project
No fix yet
MEDIUM 5.4
CVE-2024-28191
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert…
Contao
4.13.40 / 5.3.4+
CRITICAL 9.8
CVE-2024-3366
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file c…
Xxl Job
2.4.1+
HIGH 7.4
CVE-2024-28867
Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-saniti…
Swift Prometheus
Patch available
HIGH 7.5
CVE-2024-29896
Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation …
Astro Shield
Patch available
MEDIUM 6.5
CVE-2024-2777
A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical. Affected by this vulnerabi…
Online Marriage Registration System
No fix yet
MEDIUM 6.5
CVE-2024-2769
A vulnerability was detected in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the fil…
Complete Online Beauty Parlor Management System
No fix yet
CRITICAL 9.0
CVE-2024-29027
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, c…
Parse Server
6.5.5+
MEDIUM 6.6
CVE-2024-23333EPSS 18%
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary pat…
Ldap Account Manager
8.7+
MEDIUM 6.1
CVE-2024-2445
Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 …
Mattermost Server
8.1.10 / 9.2.6+
HIGH 8.1
CVE-2024-28181
turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing prote…
Turboboost Commands
0.1.3 / 0.2.2+
MEDIUM 5.3
CVE-2024-28192
your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQL injection in the public acc…
Your Spotify
1.8.0+
CRITICAL 9.1
CVE-2024-28114
Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peer…
Peering Manager
1.8.3+
MEDIUM 6.7
CVE-2024-0044
In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to loc…
Android
Patch available
MEDIUM 6.5
CVE-2024-21900EPSS 9%
An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authentica…
Qts
5.1.3.2578+
HIGH 7.8
CVE-2024-23268
An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.…
macOS
12.7.4 / 13.6.5+
HIGH 7.8
CVE-2024-23274
An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.…
macOS
12.7.4 / 13.6.5+
MEDIUM 6.5
CVE-2024-23280
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4…
Safari
2.44.0 / 10.4+
HIGH 8.8
CVE-2024-1773
The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1…
Pdf Invoices And Packing Slips For Woocommerce
1.3.8+