Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 8.8 CVE-2023-5043 Ingress nginx annotation injection causes arbitrary command execution. Ingress Nginx 1.9.0+ Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-32786 In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing … Langchain after 0.0.155 Fix from $1,9502023-10-20 CRITICAL 9.8 CVE-2022-47583 Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal. Mintty 3.6.3+ Fix from $2,3002023-10-19 MEDIUM 6.5 CVE-2023-45540 An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of… Leave Management System No fix yet Fix from $1,6002023-10-16 HIGH 7.5 CVE-2023-43667 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects … Inlong after 1.8.0 Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-43661EPSS 47% Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to e… Cachet 2.4+ Fix from $1,9502023-10-11 HIGH 7.5 CVE-2023-44109 Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,9502023-10-11 HIGH 8.8 CVE-2023-45303 ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports fre… Thingsboard 3.5+ Fix from $1,9502023-10-06 MEDIUM 5.3 CVE-2022-4145 A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, e… Openshift Container Platform Mitigation only Fix from $1,6002023-10-05 HIGH 7.8 CVE-2023-3665 A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via envir… Endpoint Security after 10.7.0 Fix from $1,9502023-10-04 HIGH 8.8 CVE-2023-43835 Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings o… Super Store Finder after 3.7 Fix from $1,9502023-10-02 HIGH 7.5 CVE-2023-41580 Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerabi… Phpipam 1.5.2+ Fix from $1,9502023-10-02 MEDIUM 5.3 CVE-2023-44270 An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can pr… Postcss 8.4.31+ Fix from $1,6002023-09-29 HIGH 8.8 CVE-2023-43655 Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed … Debian Linux 1.10.27 / 2.2.21+ Fix from $1,9502023-09-29 HIGH 8.8 CVE-2023-5269 A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function o… Best Courier Management System No fix yet Fix from $1,9502023-09-29 MEDIUM 5.3 CVE-2023-26148 All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can … Libhv No fix yet Fix from $1,6002023-09-29 CRITICAL 9.0 CVE-2023-43656 matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation f… Hookshot 4.5.0+ Fix from $2,3002023-09-27 MEDIUM 6.1 CVE-2023-41834 Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject… Flink Stateful Functions after 3.2.0 Fix from $1,6002023-09-19 HIGH 7.8 CVE-2023-36250 CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating… Gnome Time Tracker No fix yet Fix from $1,9502023-09-14 MEDIUM 6.1 CVE-2023-26142 All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values ar… Crow No fix yet Fix from $1,6002023-09-12 HIGH 8.8 CVE-2023-39424 A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such… Internet Reservation Module Next Generation Mitigation only Fix from $1,9502023-09-07 CRITICAL 10.0 CVE-2023-1523 Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause ar… Snapd 2.59.5+ Fix from $2,3002023-09-01 HIGH 7.7 CVE-2023-41039 RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling t… Restrictedpython 5.4 / 6.2+ Fix from $1,9502023-08-30 HIGH 8.2 CVE-2023-4478 Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thu… Mattermost Server 7.8.9 / 7.10.5+ Fix from $1,9502023-08-25 HIGH 7.2 CVE-2023-40035 Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code e… Craft Cms 3.8.15 / 4.4.15+ Fix from $1,9502023-08-23 MEDIUM 6.8 CVE-2023-4212 ​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as … Xl824 Firmware after 5.9.8 Fix from $1,6002023-08-22 CRITICAL 9.8 CVE-2023-4450EPSS 12% A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functio… Jimureport 1.6.1+ Fix from $2,3002023-08-21 CRITICAL 9.8 CVE-2022-24989EPSS 32% TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Objec… Terramaster Operating System 4.2.31+ Fix from $2,3002023-08-20 CRITICAL 9.8 CVE-2023-39661 An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function. Pandasai after 0.9.1 Fix from $2,3002023-08-15 CRITICAL 9.8 CVE-2023-39662 An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function. Llamaindex after 0.7.13 Fix from $2,3002023-08-15