Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.8 CVE-2024-37759 DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing int… Datagear after 5.0.0 Fix from $2,3002024-06-24 MEDIUM 5.3 CVE-2024-35728 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce al… Product Addons \& Fields For Woocommerce 32.0.21+ Fix from $1,6002024-06-10 CRITICAL 9.1 CVE-2024-5184 The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct promp… Emailgpt Mitigation only Fix from $2,3002024-06-05 MEDIUM 5.3 CVE-2023-23738 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows C… Spectra 2.3.1+ Fix from $1,6002024-06-03 HIGH 8.8 CVE-2024-34448 Ghost before 5.82.0 allows CSV Injection during a member CSV export. Ghost 5.82.0+ Fix from $1,9502024-05-22 MEDIUM 5.3 CVE-2024-5193 A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of the component Request Handler. … Tinyweb Patch available Fix from $1,6002024-05-22 CRITICAL 9.8 CVE-2024-34919 An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows atta… Mitigation only Fix from $2,3002024-05-17 MEDIUM 6.1 CVE-2024-34697 FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module… Freescout 1.8.139+ Fix from $1,6002024-05-14 CRITICAL 9.6 CVE-2024-32986 PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app propertie… Patch available Fix from $2,3002024-05-03 HIGH 8.1 CVE-2023-46304 modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint … Vtiger Crm Patch available Fix from $1,9502024-04-30 HIGH 8.0 CVE-2023-48709 iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious … Itop 2.7.9 / 3.0.4+ Fix from $1,9502024-04-15 HIGH 8.8 CVE-2024-3767 A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.… News Portal Project No fix yet Fix from $1,9502024-04-15 MEDIUM 5.4 CVE-2024-28191 Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert… Contao 4.13.40 / 5.3.4+ Fix from $1,6002024-04-09 CRITICAL 9.8 CVE-2024-3366 A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file c… Xxl Job 2.4.1+ Fix from $2,3002024-04-06 HIGH 7.4 CVE-2024-28867 Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-saniti… Swift Prometheus Patch available Fix from $1,9502024-03-29 HIGH 7.5 CVE-2024-29896 Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation … Astro Shield Patch available Fix from $1,9502024-03-28 MEDIUM 6.5 CVE-2024-2777 A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical. Affected by this vulnerabi… Online Marriage Registration System No fix yet Fix from $1,6002024-03-22 MEDIUM 6.5 CVE-2024-2769 A vulnerability was detected in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the fil… Complete Online Beauty Parlor Management System No fix yet Fix from $1,6002024-03-21 CRITICAL 9.0 CVE-2024-29027 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, c… Parse Server 6.5.5+ Fix from $2,3002024-03-19 MEDIUM 6.6 CVE-2024-23333EPSS 18% LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary pat… Ldap Account Manager 8.7+ Fix from $1,6002024-03-18 MEDIUM 6.1 CVE-2024-2445 Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 … Mattermost Server 8.1.10 / 9.2.6+ Fix from $1,6002024-03-15 HIGH 8.1 CVE-2024-28181 turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing prote… Turboboost Commands 0.1.3 / 0.2.2+ Fix from $1,9502024-03-14 MEDIUM 5.3 CVE-2024-28192 your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQL injection in the public acc… Your Spotify 1.8.0+ Fix from $1,6002024-03-13 CRITICAL 9.1 CVE-2024-28114 Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peer… Peering Manager 1.8.3+ Fix from $2,3002024-03-12 MEDIUM 6.7 CVE-2024-0044 In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to loc… Android Patch available Fix from $1,6002024-03-11 MEDIUM 6.5 CVE-2024-21900EPSS 9% An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authentica… Qts 5.1.3.2578+ Fix from $1,6002024-03-08 HIGH 7.8 CVE-2024-23268 An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.… macOS 12.7.4 / 13.6.5+ Fix from $1,9502024-03-08 HIGH 7.8 CVE-2024-23274 An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.… macOS 12.7.4 / 13.6.5+ Fix from $1,9502024-03-08 MEDIUM 6.5 CVE-2024-23280 An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4… Safari 2.44.0 / 10.4+ Fix from $1,6002024-03-08 HIGH 8.8 CVE-2024-1773 The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1… Pdf Invoices And Packing Slips For Woocommerce 1.3.8+ Fix from $1,9502024-03-07