Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Frauscher Diagnostic System 101 CRITICAL 9.8
CVE-2023-4291

Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability vi…

Fix: after 1.4.24
Fix from $2,300 2023-09-21
Satellite CRITICAL 9.1
CVE-2023-0462

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste…

Fix: 3.8.0+
Fix from $2,300 2023-09-20
Bitbucket Data Center HIGH 8.8
CVE-2023-22513EPSS 14%

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Co…

Fix: 8.9.5 / 8.10.5+
Fix from $1,950 2023-09-19
Apex One HIGH 7.2
CVE-2023-41179 KEV

A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-F…

Mitigation only
Fix from $1,950 2023-09-19
Modulys Gp Firmware HIGH 8.8
CVE-2023-40221

The absence of filters when loading some sections in the web application of the vulnerable device allows potential attackers to inject malicious code…

Mitigation only
Fix from $1,950 2023-09-18
Insydeh2o HIGH 7.8
CVE-2023-34195

An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage met…

Fix: 5.2.05.28.22 / 5.3.05.37.22+
Fix from $1,950 2023-09-18
Rts Vlink Virtual Matrix HIGH 7.2
CVE-2023-34999

A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perfo…

Fix: 5.7.6 / 6.5.0+
Fix from $1,950 2023-09-18
Allow Php In Posts And Pages MEDIUM 6.4
CVE-2023-4994

The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' sh…

Fix: after 3.0.4
Fix from $1,600 2023-09-16
Librenms MEDIUM 5.4
CVE-2023-4977

Code Injection in GitHub repository librenms/librenms prior to 23.9.0.

Fix: 23.9.0+
Fix from $1,600 2023-09-15
Craft Cms CRITICAL 9.8
CVE-2023-41892EPSS 93%

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations befo…

Fix: 4.4.15+
Fix from $2,300 2023-09-13
Powerdesigner MEDIUM 6.3
CVE-2023-40621

SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecti…

Mitigation only
Fix from $1,600 2023-09-12
Life CRITICAL 9.8
CVE-2023-42470

The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported comp…

Fix: after 6.8.0
Fix from $2,300 2023-09-11
Wave CRITICAL 9.8
CVE-2023-42471

The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It con…

Fix: after 1.0.35
Fix from $2,300 2023-09-11
Go CRITICAL 9.8
CVE-2023-39320

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "…

Fix: 1.21.1+
Fix from $2,300 2023-09-08
Electron MEDIUM 6.6
CVE-2023-39956

Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as c…

Fix: 22.3.9 / 23.3.13+
Fix from $1,600 2023-09-06
Arubaos MEDIUM 6.4
CVE-2023-38484

Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbit…

Fix: 8.6.0.22 / 8.10.0.7+
Fix from $1,600 2023-09-06
Fides HIGH 7.2
CVE-2023-41319

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem…

Fix: 2.19.0+
Fix from $1,950 2023-09-06
Cuppacms CRITICAL 9.8
CVE-2023-39681

Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vul…

No fix yet
Fix from $2,300 2023-09-05
Access Management System HIGH 8.8
CVE-2022-41763

An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to…

No fix yet
Fix from $1,950 2023-09-05
Langchain CRITICAL 9.8
CVE-2023-39631

An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.

Patch available
Fix from $2,300 2023-09-01
Mybb CRITICAL 9.8
CVE-2020-22612

Installer RCE on settings file write in MyBB before 1.8.22.

Fix: 1.8.22+
Fix from $2,300 2023-09-01
Hjson HIGH 7.5
CVE-2023-39685

An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.

Fix: after 3.0.0
Fix from $1,950 2023-09-01
Mybb HIGH 7.2
CVE-2023-41362

MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some vali…

Fix: 1.8.36+
Fix from $1,950 2023-08-29
Pagekit HIGH 7.8
CVE-2023-41005

An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateCont…

No fix yet
Fix from $1,950 2023-08-28
Ansible Semaphore HIGH 8.8
CVE-2023-39059

An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.

No fix yet
Fix from $1,950 2023-08-28
Xwiki HIGH 8.8
CVE-2023-40177

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content fiel…

Fix: 14.10.5+
Fix from $1,950 2023-08-23
Edgeconnect Sd Wan Orchestrator HIGH 7.2
CVE-2023-37427

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrar…

Fix: after 9.2.5
Fix from $1,950 2023-08-22
Langchain CRITICAL 9.8
CVE-2023-36281

An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ …

No fix yet
Fix from $2,300 2023-08-22
Edgeconnect Sd Wan Orchestrator HIGH 8.1
CVE-2023-37424

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitr…

Fix: after 9.2.5
Fix from $1,950 2023-08-22
Pandasai CRITICAL 9.8
CVE-2023-39660

An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt func…

Fix: after 0.8.0
Fix from $2,300 2023-08-21