Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-5043
Ingress nginx annotation injection causes arbitrary command execution.
Ingress Nginx
1.9.0+
HIGH 7.5
CVE-2023-32786
In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing …
Langchain
after 0.0.155
CRITICAL 9.8
CVE-2022-47583
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
Mintty
3.6.3+
MEDIUM 6.5
CVE-2023-45540
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of…
Leave Management System
No fix yet
HIGH 7.5
CVE-2023-43667
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects …
Inlong
after 1.8.0
HIGH 8.8
CVE-2023-43661EPSS 47%
Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to e…
Cachet
2.4+
HIGH 7.5
CVE-2023-44109
Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.
Harmonyos
No fix yet
HIGH 8.8
CVE-2023-45303
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports fre…
Thingsboard
3.5+
MEDIUM 5.3
CVE-2022-4145
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, e…
Openshift Container Platform
Mitigation only
HIGH 7.8
CVE-2023-3665
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via envir…
Endpoint Security
after 10.7.0
HIGH 8.8
CVE-2023-43835
Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings o…
Super Store Finder
after 3.7
HIGH 7.5
CVE-2023-41580
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerabi…
Phpipam
1.5.2+
MEDIUM 5.3
CVE-2023-44270
An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can pr…
Postcss
8.4.31+
HIGH 8.8
CVE-2023-43655
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed …
Debian Linux
1.10.27 / 2.2.21+
HIGH 8.8
CVE-2023-5269
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function o…
Best Courier Management System
No fix yet
MEDIUM 5.3
CVE-2023-26148
All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can …
Libhv
No fix yet
CRITICAL 9.0
CVE-2023-43656
matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation f…
Hookshot
4.5.0+
MEDIUM 6.1
CVE-2023-41834
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject…
Flink Stateful Functions
after 3.2.0
HIGH 7.8
CVE-2023-36250
CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating…
Gnome Time Tracker
No fix yet
MEDIUM 6.1
CVE-2023-26142
All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values ar…
Crow
No fix yet
HIGH 8.8
CVE-2023-39424
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such…
Internet Reservation Module Next Generation
Mitigation only
CRITICAL 10.0
CVE-2023-1523
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause ar…
Snapd
2.59.5+
HIGH 7.7
CVE-2023-41039
RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling t…
Restrictedpython
5.4 / 6.2+
HIGH 8.2
CVE-2023-4478
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thu…
Mattermost Server
7.8.9 / 7.10.5+
HIGH 7.2
CVE-2023-40035
Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code e…
Craft Cms
3.8.15 / 4.4.15+
MEDIUM 6.8
CVE-2023-4212
A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as …
Xl824 Firmware
after 5.9.8
CRITICAL 9.8
CVE-2023-4450EPSS 12%
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functio…
Jimureport
1.6.1+
CRITICAL 9.8
CVE-2022-24989EPSS 32%
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Objec…
Terramaster Operating System
4.2.31+
CRITICAL 9.8
CVE-2023-39661
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.
Pandasai
after 0.9.1
CRITICAL 9.8
CVE-2023-39662
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
Llamaindex
after 0.7.13