Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Vigor2620 Firmware CRITICAL 9.8
CVE-2023-31447

user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to m…

Fix: 3.9.8.4+
Fix from $2,300 2023-08-21
Wrc 1467ghbk A Firmware HIGH 8.8
CVE-2023-39445

Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitr…

Mitigation only
Fix from $1,950 2023-08-18
Lan Wh300n\/re Firmware HIGH 8.0
CVE-2023-38576

Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbitrary OS…

Mitigation only
Fix from $1,950 2023-08-18
Lan W300n\/rs Firmware CRITICAL 9.8
CVE-2023-32626

Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the p…

Mitigation only
Fix from $2,300 2023-08-18
Horizon HIGH 8.8
CVE-2023-40313

A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow…

Fix: 32.0.2 / 2020.1.38+
Fix from $1,950 2023-08-17
Xwiki HIGH 8.8
CVE-2023-37914

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` c…

Fix: 14.4.8 / 14.10.6+
Fix from $1,950 2023-08-17
Genian Nac CRITICAL 9.8
CVE-2023-40252

Improper Control of Generation of Code ('Code Injection') vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite…

Fix: 4.0.156 / 5.0.55+
Fix from $2,300 2023-08-17
Telepresence Video Communication Server HIGH 7.2
CVE-2023-20209EPSS 41%

A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow …

Fix: 14.3.1+
Fix from $1,950 2023-08-16
Langchain CRITICAL 9.8
CVE-2023-38860

An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.

No fix yet
Fix from $2,300 2023-08-15
Alluxio CRITICAL 9.8
CVE-2023-38889

An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.Com…

Fix: after 2.9.3
Fix from $2,300 2023-08-15
Via Go2 Firmware HIGH 7.8
CVE-2023-33469

In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior…

Fix: 4.0.1.1326+
Fix from $1,950 2023-08-09
Powerdesigner HIGH 7.8
CVE-2023-36923

SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious…

Mitigation only
Fix from $1,950 2023-08-08
Langchain CRITICAL 9.8
CVE-2023-36095

An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected funct…

Mitigation only
Fix from $2,300 2023-08-05
Shuize 0x727 HIGH 8.8
CVE-2023-38943

ShuiZe_0x727 v1.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /iniFile/config.ini.

No fix yet
Fix from $1,950 2023-08-05
Metabase CRITICAL 9.8
CVE-2023-37470

Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3…

Fix: 0.43.7.3 / 0.44.7.3+
Fix from $2,300 2023-08-04
Wp Ultimate Csv Importer HIGH 8.8
CVE-2023-4141

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' par…

Fix: after 7.9.8
Fix from $1,950 2023-08-04
Wp Ultimate Csv Importer HIGH 8.8
CVE-2023-4142

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' par…

Fix: after 7.9.8
Fix from $1,950 2023-08-04
Eramba HIGH 8.8
CVE-2023-36255EPSS 53%

An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter…

Mitigation only
Fix from $1,950 2023-08-03
GitLab MEDIUM 6.5
CVE-2023-3401

An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting fro…

Fix: 16.0.8 / 16.1.3+
Fix from $1,600 2023-08-02
Rg Ew1200r Firmware CRITICAL 9.8
CVE-2023-34644

Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series …

Patch available
Fix from $2,300 2023-07-31
Dedecms CRITICAL 9.8
CVE-2023-34842

Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.ph…

Fix: after 5.7.109
Fix from $2,300 2023-07-31
Nifi HIGH 8.8
CVE-2023-36542

Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an …

Fix: after 1.22.0
Fix from $1,950 2023-07-29
Bboss CRITICAL 9.8
CVE-2023-39016

bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLM…

Fix: after 6.0.9
Fix from $2,300 2023-07-28
Quartz CRITICAL 9.8
CVE-2023-39017

quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.exec…

Fix: after 2.3.2
Fix from $2,300 2023-07-28
Ffmpeg Cli Wrapper CRITICAL 9.8
CVE-2023-39018

FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerab…

Fix: after 0.7.0
Fix from $2,300 2023-07-28
Stanford Parser CRITICAL 9.8
CVE-2023-39020

stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStre…

Fix: 4.5.5+
Fix from $2,300 2023-07-28
Wix Embedded Mysql CRITICAL 9.8
CVE-2023-39021

wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply.…

Fix: after 4.6.1
Fix from $2,300 2023-07-28
Oscore CRITICAL 9.8
CVE-2023-39022

oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. Thi…

Fix: after 2.2.6
Fix from $2,300 2023-07-28
University Compass CRITICAL 9.8
CVE-2023-39023

university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecut…

Fix: after 2.2.0
Fix from $2,300 2023-07-28
Boofcv CRITICAL 9.8
CVE-2023-39010

BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability i…

No fix yet
Fix from $2,300 2023-07-28