Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 8.8 CVE-2023-29521 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitr… Xwiki 13.10.11 / 14.4.8+ Fix from $1,9502023-04-19 HIGH 8.8 CVE-2023-29522 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitr… Xwiki 14.4.8 / 14.10.3+ Fix from $1,9502023-04-19 HIGH 8.8 CVE-2023-29523 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile… Xwiki 13.10.11 / 14.4.8+ Fix from $1,9502023-04-19 HIGH 8.8 CVE-2023-29213 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-04-17 CRITICAL 10.0 CVE-2023-30547EPSS 72% vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 … Vm2 after 3.9.16 Fix from $2,3002023-04-17 HIGH 7.2 CVE-2023-26919 delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can … Nashorn Sandbox No fix yet Fix from $1,9502023-04-10 MEDIUM 6.8 CVE-2023-29389 Toyota RAV4 2021 vehicles automatically trust messages from other ECUs on a CAN bus, which allows physically proximate attackers to drive a vehicle b… Rav4 Firmware No fix yet Fix from $1,6002023-04-05 CRITICAL 9.8 CVE-2023-29374EPSS 40% In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method. Langchain after 0.0.131 Fix from $2,3002023-04-05 MEDIUM 6.5 CVE-2023-28853 Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in vers… Mastodon 3.5.8 / 4.0.4+ Fix from $1,6002023-04-04 HIGH 7.2 CVE-2022-43769 KEVEPSS 98% Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property v… Vantara Pentaho Business Analytics Server 9.3.0.2+ Fix from $1,9502023-04-03 HIGH 8.8 CVE-2023-27533 A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously c… Curl after 7.881 Fix from $1,9502023-03-30 HIGH 8.8 CVE-2023-28637 DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected … Dataease 1.18.5+ Fix from $1,9502023-03-28 HIGH 8.8 CVE-2023-26493 Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `w… Cocos Engine 2023-02-20+ Fix from $1,9502023-03-27 CRITICAL 9.8 CVE-2023-27040 Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter. Simple Image Gallery Web App No fix yet Fix from $2,3002023-03-16 HIGH 8.8 CVE-2023-25616 In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection … Business Objects Business Intelligence Platform Mitigation only Fix from $1,9502023-03-14 CRITICAL 9.8 CVE-2023-1287 An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution. Enovia Live Collaboration No fix yet Fix from $2,3002023-03-09 CRITICAL 9.8 CVE-2023-26261 In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user… Waap Cloud 6.5.6 / 6.11.0+ Fix from $2,3002023-03-08 CRITICAL 9.9 CVE-2023-27479 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ… Xwiki 13.10.11 / 14.4.7+ Fix from $2,3002023-03-07 HIGH 7.8 CVE-2023-27635 debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is… Debmany Mitigation only Fix from $1,9502023-03-05 HIGH 7.8 CVE-2022-42797 An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges. Xcode 14.1+ Fix from $1,9502023-02-27 HIGH 8.8 CVE-2023-1059 A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the fil… Doctors Appointment System No fix yet Fix from $1,9502023-02-27 HIGH 8.8 CVE-2023-1061 A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown p… Doctors Appointment System No fix yet Fix from $1,9502023-02-27 HIGH 7.2 CVE-2023-20858EPSS 17% VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious … Carbon Black App Control 8.7.8 / 8.8.6+ Fix from $1,9502023-02-22 CRITICAL 9.8 CVE-2023-25613 An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.  Kerby Ldap Backend 2.0.3+ Fix from $2,3002023-02-20 MEDIUM 6.5 CVE-2022-36775 IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation … Security Verify Access Patch available Fix from $1,6002023-02-17 MEDIUM 5.4 CVE-2022-42472 A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 throu… Fortiproxy after 7.0.8 Fix from $1,6002023-02-16 MEDIUM 5.4 CVE-2023-23936 Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP he… Node.js 5.19.1 / 16.19.1+ Fix from $1,6002023-02-16 HIGH 7.5 CVE-2023-25141 Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility funct… Sling Jcr Base 3.1.12+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2023-25719 ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl… Control 22.9.10032+ Fix from $1,9502023-02-13 HIGH 7.5 CVE-2022-43756 A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote atta… Wrangler 0.7.4 / 0.8.5+ Fix from $1,9502023-02-07