Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.8 CVE-2023-38896 An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colore… Langchain after 0.0.194 Fix from $2,3002023-08-15 CRITICAL 9.8 CVE-2023-39659 An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLT… Langchain after 0.0.232 Fix from $2,3002023-08-15 HIGH 8.8 CVE-2020-28848 CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file. Churchcrm No fix yet Fix from $1,9502023-08-11 HIGH 8.8 CVE-2023-31209 Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authe… Checkmk 2.0.0+ Fix from $1,9502023-08-10 HIGH 8.1 CVE-2023-33242 Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in … Lindell17 No fix yet Fix from $1,9502023-08-09 CRITICAL 9.1 CVE-2023-33241 Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallie… Gg18 No fix yet Fix from $2,3002023-08-09 CRITICAL 9.8 CVE-2023-39213 Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to… Virtual Desktop Infrastructure 5.15.2+ Fix from $2,3002023-08-08 CRITICAL 9.8 CVE-2023-36210EPSS 31% MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword paramet… Motocms No fix yet Fix from $2,3002023-08-01 HIGH 7.5 CVE-2023-38609 An injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass certain Priv… macOS 13.5+ Fix from $1,9502023-07-28 HIGH 8.8 CVE-2023-38060 Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic I… Otrs 7.0.45 / 8.0.35+ Fix from $1,9502023-07-24 MEDIUM 6.5 CVE-2020-24275 A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL. Swoole Patch available Fix from $1,6002023-07-20 HIGH 8.8 CVE-2023-37897 Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vu… Grav Patch available Fix from $1,9502023-07-18 CRITICAL 9.8 CVE-2023-3694 A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Property Listing 1.0. This issue a… House Rental And Property Listing No fix yet Fix from $2,3002023-07-17 HIGH 8.8 CVE-2023-37473 zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing _callable strings_ (ie `system`) caused the functio… Collection Patch available Fix from $1,9502023-07-14 HIGH 8.8 CVE-2023-37462EPSS 91% XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode… Xwiki 14.4.8 / 14.10.4+ Fix from $1,9502023-07-14 HIGH 7.8 CVE-2023-36830 SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files, there is a potential securit… Sqlfluff 2.1.2+ Fix from $1,9502023-07-06 CRITICAL 9.8 CVE-2023-36188 An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method. Langchain Patch available Fix from $2,3002023-07-06 CRITICAL 9.8 CVE-2023-36812EPSS 17% OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writin… Opentsdb 2.4.2+ Fix from $2,3002023-06-30 MEDIUM 6.1 CVE-2023-37360 pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (wh… Pacparser 1.4.2+ Fix from $1,6002023-06-30 HIGH 8.8 CVE-2023-36469EPSS 82% XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile… Xwiki 14.10.6+ Fix from $1,9502023-06-29 HIGH 8.8 CVE-2023-36470 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an exist… Xwiki 14.10.6+ Fix from $1,9502023-06-29 MEDIUM 5.4 CVE-2023-36471 Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowe… Commons 14.10.6+ Fix from $1,6002023-06-29 HIGH 8.8 CVE-2023-34203 In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a U… Openedge 11.7.16 / 12.2.12+ Fix from $1,9502023-06-23 CRITICAL 9.8 CVE-2023-3380 A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi… Wn579x3 Firmware after 2023-06-15 Fix from $2,3002023-06-23 MEDIUM 6.1 CVE-2023-28016 Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause … Bigfix Osd Bare Metal Server after 311.12 Fix from $1,6002023-06-22 HIGH 7.2 CVE-2023-35810 An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been ident… Sugarcrm 11.0.6 / 12.0.3+ Fix from $1,9502023-06-17 MEDIUM 6.5 CVE-2023-2797 Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink… Mattermost after 7.8.4 Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-28598 Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in … Zoom 5.13.10+ Fix from $1,6002023-06-13 CRITICAL 9.8 CVE-2023-29405 The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a… Go 1.19.10 / 1.20.5+ Fix from $2,3002023-06-08 HIGH 8.8 CVE-2019-25150 The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers … Email Templates 1.3.1+ Fix from $1,9502023-06-07