Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Tinyfiledialogs HIGH 7.5
CVE-2020-36767

tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.

Fix: 3.8.0+
Fix from $1,950 2023-10-30
Ads By Datafeedr.com CRITICAL 9.8
CVE-2023-5843

The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load…

Fix: after 1.1.3
Fix from $2,300 2023-10-30
Inkdrop HIGH 7.8
CVE-2023-44141

Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a specially crafted markdown file.

Fix: 5.6.0+
Fix from $1,950 2023-10-30
Crater HIGH 7.2
CVE-2023-46865EPSS 20%

/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code i…

Fix: after 6.0.6
Fix from $1,950 2023-10-30
Isula HIGH 7.8
CVE-2021-33635

When malicious images are pulled by isula pull, attackers can execute arbitrary code.

Patch available
Fix from $1,950 2023-10-29
Isula HIGH 7.8
CVE-2021-33636

When the isula load command is used to load malicious images, attackers can execute arbitrary code.

Patch available
Fix from $1,950 2023-10-29
Solarview Compact Firmware CRITICAL 9.8
CVE-2023-46509

An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.

Fix: after 6.0
Fix from $2,300 2023-10-27
Sugarcrm HIGH 8.8
CVE-2023-46816

An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified …

Fix: 12.0.4+
Fix from $1,950 2023-10-27
Ispconfig HIGH 7.2
CVE-2023-46818EPSS 16%

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_lange…

Fix: 3.2.11+
Fix from $1,950 2023-10-27
Cms Made Simple HIGH 7.8
CVE-2023-43352

An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.

No fix yet
Fix from $1,950 2023-10-26
Nessus Network Monitor HIGH 7.8
CVE-2023-5623

NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w…

Fix: 6.3.0+
Fix from $1,950 2023-10-26
Ingress Nginx HIGH 8.8
CVE-2023-5044EPSS 57%

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

Fix: 1.9.0+
Fix from $1,950 2023-10-25
Seacms CRITICAL 9.8
CVE-2023-46010

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

Fix: after 12.9
Fix from $2,300 2023-10-25
Xwiki HIGH 8.8
CVE-2023-37909

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to ve…

Fix: 14.10.8+
Fix from $1,950 2023-10-25
Oneview CRITICAL 9.8
CVE-2023-30912

A remote code execution issue exists in HPE OneView.

Fix: 8.60.00+
Fix from $2,300 2023-10-25
Client Connector HIGH 7.8
CVE-2023-28793

Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Clie…

Fix: 1.3.1.6+
Fix from $1,950 2023-10-23
Client Connector HIGH 7.8
CVE-2023-28796

Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler…

Fix: 1.3.1.6+
Fix from $1,950 2023-10-23
Photon HIGH 8.8
CVE-2023-46055

An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping funct…

No fix yet
Fix from $1,950 2023-10-21
Home Assistant Companion HIGH 7.8
CVE-2023-41898

Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL …

Fix: 2023.9.2+
Fix from $1,950 2023-10-19
Easyinstall CRITICAL 9.8
CVE-2023-30131

An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified …

No fix yet
Fix from $2,300 2023-10-19
Getsimplecms CRITICAL 9.8
CVE-2023-46042EPSS 23%

An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().

No fix yet
Fix from $2,300 2023-10-19
Esst Monitoring CRITICAL 9.8
CVE-2023-41630

eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component.

Fix: after 2.147.1
Fix from $2,300 2023-10-17
Oauth Identity CRITICAL 9.6
CVE-2023-45144

com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user …

Fix: 1.6+
Fix from $2,300 2023-10-16
Zabbix Agent2 CRITICAL 9.8
CVE-2023-29453

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, …

Fix: 5.0.35 / 6.0.18+
Fix from $2,300 2023-10-12
Cachet HIGH 8.8
CVE-2023-43661EPSS 47%

Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to e…

Fix: 2.4+
Fix from $1,950 2023-10-11
Skype For Business Server HIGH 7.2
CVE-2023-36789

Skype for Business Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-10-10
Windows 10 1507 HIGH 7.8
CVE-2023-36718

Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10
Windows 10 1507 HIGH 7.8
CVE-2023-36702

Microsoft DirectMusic Remote Code Execution Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10
Windows 10 HIGH 7.3
CVE-2023-36589

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10
Windows 10 HIGH 7.3
CVE-2023-36591

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10