Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 7.2 CVE-2023-49328 On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote co… B.point Mitigation only Fix from $1,9502023-12-25 CRITICAL 9.8 CVE-2023-7100 A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of th… Restaurant Table Booking System No fix yet Fix from $2,3002023-12-25 CRITICAL 9.8 CVE-2023-7096 A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. Th… Faculty Management System No fix yet Fix from $2,3002023-12-25 CRITICAL 9.8 CVE-2023-7039EPSS 14% A vulnerability classified as critical has been found in Byzoro S210 up to 20231210. Affected is an unknown function of the file /importexport.php. T… Smart S210 Firmware after 2023-12-10 Fix from $2,3002023-12-21 CRITICAL 9.8 CVE-2023-35895 IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert… Informix Jdbc Mitigation only Fix from $2,3002023-12-20 CRITICAL 9.8 CVE-2023-46726 GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co… Glpi 10.0.11+ Fix from $2,3002023-12-13 CRITICAL 9.8 CVE-2023-43364 main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution. Searchor 2.4.2+ Fix from $2,3002023-12-12 CRITICAL 9.8 CVE-2023-46456EPSS 25% In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionali… Gl Ar300m Firmware Mitigation only Fix from $2,3002023-12-12 HIGH 8.8 CVE-2023-49964EPSS 35% An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attack… Alfresco Content Services after 7.2.0 Fix from $1,9502023-12-11 CRITICAL 9.8 CVE-2023-6648 A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of… Nipah Virus Testing Management System No fix yet Fix from $2,3002023-12-10 HIGH 8.8 CVE-2023-48841 Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. Appointment Scheduler No fix yet Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-48830 Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. Shuttle Booking Software No fix yet Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-48835 Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. Car Rental Script No fix yet Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-48826 Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. Time Slots Booking Calendar No fix yet Fix from $1,9502023-12-07 MEDIUM 5.3 CVE-2023-48205 Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails. Leave Management System No fix yet Fix from $1,6002023-12-07 CRITICAL 9.8 CVE-2023-6458 Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traver… Mattermost Server 7.8.14 / 8.1.5+ Fix from $2,3002023-12-06 HIGH 8.8 CVE-2023-22522EPSS 13% This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confl… Confluence Data Center 7.19.17 / 8.4.5+ Fix from $1,9502023-12-06 MEDIUM 5.4 CVE-2023-35075 Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML… Mattermost after 8.1.3 Fix from $1,6002023-11-27 CRITICAL 9.8 CVE-2023-49214 Usedesk before 1.7.57 allows chat template injection. Usedesk 1.7.57+ Fix from $2,3002023-11-23 CRITICAL 9.8 CVE-2023-5340 The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticate… Five Star Restaurant Menu 2.4.11+ Fix from $2,3002023-11-20 CRITICAL 9.8 CVE-2022-46337 A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up … Derby 10.14.3.0 / 10.15.2.1+ Fix from $2,3002023-11-20 MEDIUM 6.5 CVE-2023-6174 SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file Wireshark after 4.0.10 Fix from $1,6002023-11-16 HIGH 7.8 CVE-2023-48199 HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script exec… Grocy No fix yet Fix from $1,9502023-11-15 CRITICAL 9.1 CVE-2023-44373 Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject… 6gk5205 3bb00 2ab2 Firmware 4.5+ Fix from $2,3002023-11-14 MEDIUM 6.1 CVE-2023-47119 Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` an… Discourse 3.1.3 / 3.2.0+ Fix from $1,6002023-11-10 CRITICAL 9.8 CVE-2017-20187 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the functi… Magnesium Php after 0.3.0 Fix from $2,3002023-11-05 MEDIUM 6.1 CVE-2023-4767 A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack… Manageengine Desktop Central Mitigation only Fix from $1,6002023-11-03 HIGH 8.8 CVE-2023-4197EPSS 33% Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing a… Dolibarr Erp\/crm after 18.0.1 Fix from $1,9502023-11-01 MEDIUM 6.1 CVE-2023-4393 HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attac… Liquidfiles 3.7.14+ Fix from $1,6002023-10-30 HIGH 7.8 CVE-2023-46468 An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function. Juzaweb Cms after 3.4 Fix from $1,9502023-10-28