Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Bagisto HIGH 8.8
CVE-2023-33570

Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

No fix yet
Fix from $1,950 2023-06-28
Informix Jdbc Driver CRITICAL 9.8
CVE-2023-27866

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using th…

Fix: 4.50.10+
Fix from $2,300 2023-06-28
Aws Dataall HIGH 8.8
CVE-2023-36467

AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1…

Fix: after 1.5.1
Fix from $1,950 2023-06-28
Mobile Security HIGH 8.8
CVE-2023-32527

Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affec…

Patch available
Fix from $1,950 2023-06-26
Mobile Security HIGH 8.8
CVE-2023-32528

Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affec…

Patch available
Fix from $1,950 2023-06-26
Jfinal CRITICAL 9.8
CVE-2021-31635

Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.

Mitigation only
Fix from $2,300 2023-06-26
Fossbilling HIGH 7.2
CVE-2023-3393

Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

Fix: 0.5.1+
Fix from $1,950 2023-06-23
Xwiki HIGH 8.0
CVE-2023-35150EPSS 78%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to ver…

Fix: 14.4.8 / 14.10.4+
Fix from $1,950 2023-06-23
Xwiki HIGH 8.8
CVE-2023-35152

XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add …

Fix: 14.4.8 / 14.10.6+
Fix from $1,950 2023-06-23
Backstage CRITICAL 9.9
CVE-2023-35926

Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox…

Fix: 1.15.0+
Fix from $2,300 2023-06-22
Pluck HIGH 7.2
CVE-2020-20918

An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when edit…

Patch available
Fix from $1,950 2023-06-20
Open Xchange Appsuite Backend HIGH 8.8
CVE-2023-26436

Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserializa…

Fix: 7.10.6+
Fix from $1,950 2023-06-20
Slider Revolution HIGH 8.8
CVE-2023-2359

The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may…

Fix: after 6.6.12
Fix from $1,950 2023-06-19
Suricata CRITICAL 9.8
CVE-2023-35853

In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by …

Fix: 6.0.13+
Fix from $2,300 2023-06-19
Experience Commerce CRITICAL 9.8
CVE-2023-35813EPSS 87%

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

Fix: after 10.3
Fix from $2,300 2023-06-17
Sugarcrm HIGH 8.8
CVE-2023-35809

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the RES…

Fix: 11.0.6 / 12.0.3+
Fix from $1,950 2023-06-17
Grav HIGH 7.2
CVE-2023-34253

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from …

Fix: 1.7.42+
Fix from $1,950 2023-06-14
Grav HIGH 7.2
CVE-2023-34448

Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability i…

Fix: 1.7.42+
Fix from $1,950 2023-06-14
Grav HIGH 7.2
CVE-2023-34251

Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is po…

Fix: 1.7.42+
Fix from $1,950 2023-06-14
Grav HIGH 7.2
CVE-2023-34252

Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby …

Fix: 1.7.42+
Fix from $1,950 2023-06-14
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2023-1049

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspi…

Fix: 3.3+
Fix from $1,950 2023-06-14
Office HIGH 8.8
CVE-2023-33131EPSS 6%

Microsoft Outlook Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-06-14
Azure Devops Server MEDIUM 5.5
CVE-2023-21569

Azure DevOps Server Spoofing Vulnerability

Patch available
Fix from $1,600 2023-06-14
Nuxt CRITICAL 9.8
CVE-2023-3224EPSS 59%

Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.

Fix: 3.4.3+
Fix from $2,300 2023-06-13
Craft Cms HIGH 7.2
CVE-2023-30179

CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Loca…

Patch available
Fix from $1,950 2023-06-13
Simatic Pcs 7 HIGH 8.8
CVE-2023-25910

A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All …

Fix: 5.7+
Fix from $1,950 2023-06-13
Nifi HIGH 8.8
CVE-2023-34468EPSS 64%

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user …

Fix: 1.22.0+
Fix from $1,950 2023-06-12
Unify Openscape 4000 Assistant CRITICAL 9.8
CVE-2023-35034

Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code…

Mitigation only
Fix from $2,300 2023-06-12
Softpaq Installer HIGH 7.8
CVE-2019-16283

A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.

No fix yet
Fix from $1,950 2023-06-09
Javacpp Presets HIGH 8.8
CVE-2023-34112

JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/javacpp-presets` use the `github.…

Fix: 1.5.9+
Fix from $1,950 2023-06-09