Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 5.4 CVE-2024-21838 Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML c… Command Centre 8.70.2526 / 8.80.1526+ Fix from $1,6002024-03-05 HIGH 8.8 CVE-2024-1619 Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially force an a… Security after 8.0.3.30 Fix from $1,9502024-02-29 MEDIUM 5.3 CVE-2024-21742 Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an atta… James Mime4j after 0.8.9 Fix from $1,6002024-02-27 CRITICAL 9.8 CVE-2024-1833 A vulnerability was found in SourceCodester Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functio… Employee Management System No fix yet Fix from $2,3002024-02-23 CRITICAL 9.8 CVE-2023-51388 Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no … Hertzbeat 1.4.1+ Fix from $2,3002024-02-22 CRITICAL 9.8 CVE-2023-51653 Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injec… Hertzbeat 1.4.1+ Fix from $2,3002024-02-22 HIGH 8.3 CVE-2024-23830 MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hija… Mantisbt 2.26.1+ Fix from $1,9502024-02-20 CRITICAL 9.3 CVE-2024-25625 Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic… Admin Classic Bundle 1.3.4+ Fix from $2,3002024-02-19 CRITICAL 9.8 CVE-2024-22319EPSS 76% IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JND… Operational Decision Manager Patch available Fix from $2,3002024-02-02 HIGH 8.1 CVE-2023-51446 GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform L… Glpi 10.0.12+ Fix from $1,9502024-02-01 HIGH 8.8 CVE-2023-51939 An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive informat… Relic Patch available Fix from $1,9502024-02-01 HIGH 7.5 CVE-2023-36260 An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings … Craft Cms 4.6.1.1+ Fix from $1,9502024-01-30 HIGH 8.8 CVE-2024-23828 Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when cha… Nginx Ui 2.0.0+ Fix from $1,9502024-01-29 HIGH 8.8 CVE-2024-23648 Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a pas… Admin Classic Bundle 1.2.3+ Fix from $1,9502024-01-24 CRITICAL 9.8 CVE-2024-0579 A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDe… X2000r Firmware Mitigation only Fix from $2,3002024-01-16 MEDIUM 5.3 CVE-2021-4227 The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to … Ark Wysiwyg Comment Editor after 2.15.6 Fix from $1,6002024-01-16 CRITICAL 9.8 CVE-2023-22527 KEVEPSS 100% A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an aff… Confluence Data Center 8.5.4+ Fix from $2,3002024-01-16 HIGH 7.6 CVE-2023-4818 PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PA… Paydroid No fix yet Fix from $1,9502024-01-15 MEDIUM 6.8 CVE-2023-42135 PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypass… Paydroid after 8.1.0_sagittarius_11.1.50_20230614 Fix from $1,6002024-01-15 HIGH 7.8 CVE-2023-42136 PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system … Paydroid after 8.1.0_sagittarius_11.1.50_20230614 Fix from $1,9502024-01-15 CRITICAL 9.8 CVE-2024-0552 Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to e… Smartrobot after 6.0.0-202012tw Fix from $2,3002024-01-15 HIGH 7.5 CVE-2023-31025 NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead … Dgx A100 Firmware 00.22.05+ Fix from $1,9502024-01-12 MEDIUM 5.3 CVE-2024-21645EPSS 25% pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any una… Pyload after 0.4.9 Fix from $1,6002024-01-08 CRITICAL 9.6 CVE-2023-29050 The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the i… Ox App Suite 7.10.6+ Fix from $2,3002024-01-08 MEDIUM 6.1 CVE-2023-50093 APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection. Api Gateway Manager No fix yet Fix from $1,6002024-01-03 CRITICAL 9.6 CVE-2023-39655 A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in… Couchauth after 0.20.0 Fix from $2,3002024-01-03 CRITICAL 9.8 CVE-2024-21623 OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah/otclient "`Analysis - SonarC… Otclient 2023-12-30+ Fix from $2,3002024-01-02 HIGH 8.8 CVE-2023-7114 Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server. Mattermost 2.10.1+ Fix from $1,9502023-12-29 MEDIUM 5.3 CVE-2023-52081 ffcss is a CLI interface to apply and configure Firefox CSS themes. Prior to 0.2.0, the function `lookupPreprocess()` is meant to apply some transfor… Firefox Css 0.2.0+ Fix from $1,6002023-12-28 CRITICAL 9.8 CVE-2023-51664 tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows fo… Changed Files 41.0.0+ Fix from $2,3002023-12-27