Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Duke CRITICAL 9.8
CVE-2023-39013

Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.

Fix: after 1.2
Fix from $2,300 2023-07-28
Webmagic CRITICAL 9.8
CVE-2023-39015

webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.Phant…

Fix: after 0.9.0
Fix from $2,300 2023-07-28
macOS HIGH 7.8
CVE-2023-32418

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. Processing a fi…

Fix: 11.7.9 / 12.6.8+
Fix from $1,950 2023-07-27
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2023-3519 KEVEPSS 100%

Unauthenticated remote code execution

Fix: 12.1-55.297 / 13.0-91.13+
Fix from $2,300 2023-07-19
Bamboo Data Center HIGH 8.8
CVE-2023-22506

This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Cen…

Fix: 9.2.3+
Fix from $1,950 2023-07-19
Megarac Sp X HIGH 8.8
CVE-2023-34330

AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A success…

Mitigation only
Fix from $1,950 2023-07-18
423 41w\/ac Firmware CRITICAL 9.8
CVE-2021-37384

RCE (Remote Code Execution) vulnerability was found in some Furukawa ONU models, this vulnerability allows remote unauthenticated users to send arbit…

Fix: 1.2.0 / 1.4.0+
Fix from $2,300 2023-07-17
Vm2 CRITICAL 10.0
CVE-2023-37466

vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of th…

Fix: after 3.9.19
Fix from $2,300 2023-07-14
Autogpt Classic HIGH 8.8
CVE-2023-37273

Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Auto-GPT version prior to 0.4.3 …

Fix: 0.4.3+
Fix from $1,950 2023-07-13
Autogpt Classic HIGH 7.8
CVE-2023-37274

Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-GPT is executed directly on th…

Fix: 0.4.3+
Fix from $1,950 2023-07-13
Anti Virus MEDIUM 6.7
CVE-2022-42045

Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zemana AntiMalware 3.2.28.

No fix yet
Fix from $1,600 2023-07-13
Wrc 1167ghbk S Firmware HIGH 8.0
CVE-2023-37565

Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a s…

Fix: after 1.24
Fix from $1,950 2023-07-13
Acme.sh CRITICAL 9.8
CVE-2023-38198

acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.

Fix: 3.0.6+
Fix from $2,300 2023-07-13
Rocketmq CRITICAL 9.8
CVE-2023-37582EPSS 90%

The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version …

Fix: after 5.1.1
Fix from $2,300 2023-07-12
Struxureware Data Center Expert HIGH 7.2
CVE-2023-37199

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on…

Fix: after 7.9.3
Fix from $1,950 2023-07-12
Struxureware Data Center Expert HIGH 7.2
CVE-2023-37198

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on…

Fix: after 7.9.3
Fix from $1,950 2023-07-12
Secure Access Client HIGH 8.8
CVE-2023-24492

A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute co…

Fix: 23.5.2+
Fix from $1,950 2023-07-11
Pandocupload HIGH 7.5
CVE-2023-35333

MediaWiki PandocUpload Extension Remote Code Execution Vulnerability

Fix: 1.0.1+
Fix from $1,950 2023-07-11
Sharepoint Server HIGH 8.8
CVE-2023-33157EPSS 41%

Microsoft SharePoint Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-07-11
Xalpha CRITICAL 9.8
CVE-2023-37659

xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).

Fix: after 0.11.8
Fix from $2,300 2023-07-11
Db2 HIGH 8.8
CVE-2023-27867

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code vi…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 8.8
CVE-2023-27868

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on…

Patch available
Fix from $1,950 2023-07-10
Db2 HIGH 8.8
CVE-2023-27869

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on…

Patch available
Fix from $1,950 2023-07-10
Teampass HIGH 7.2
CVE-2023-3551

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Fix: 3.0.10+
Fix from $1,950 2023-07-08
Travianz HIGH 7.2
CVE-2023-36992

PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.

No fix yet
Fix from $1,950 2023-07-07
M Bus 900s Firmware CRITICAL 9.8
CVE-2023-36859

PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.

No fix yet
Fix from $2,300 2023-07-06
Collaboration CRITICAL 9.8
CVE-2023-29382

An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.

Mitigation only
Fix from $2,300 2023-07-06
I CRITICAL 9.8
CVE-2023-30990

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-For…

Patch available
Fix from $2,300 2023-07-04
Langchain CRITICAL 9.8
CVE-2023-36258

An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.

No fix yet
Fix from $2,300 2023-07-03
Orthanc HIGH 8.8
CVE-2023-33466

Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific depl…

Fix: 1.12.0+
Fix from $1,950 2023-06-29