Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Go CRITICAL 9.8
CVE-2023-29404

The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…

Fix: 1.19.10 / 1.20.5+
Fix from $2,300 2023-06-08
Go CRITICAL 9.8
CVE-2023-29402

The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses…

Fix: 1.19.10 / 1.20.5+
Fix from $2,300 2023-06-08
Sabnzbd CRITICAL 9.8
CVE-2023-34237

SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remote code execution. Manipulatin…

Fix: 4.0.2+
Fix from $2,300 2023-06-07
Activello CRITICAL 9.8
CVE-2020-36708EPSS 65%

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activell…

Fix: 1.0.6 / 1.1.2+
Fix from $2,300 2023-06-07
Webaccess\/scada CRITICAL 9.8
CVE-2023-32540

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file…

Fix: after 9.1.3
Fix from $2,300 2023-06-06
Reportlab HIGH 7.8
CVE-2023-33733

Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.

Fix: after 3.6.12
Fix from $1,950 2023-06-05
Titan Ftp Server Nextgen HIGH 7.8
CVE-2023-27744

An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privilege escalation leading to remote code ex…

Fix: 2.1.0.2174+
Fix from $1,950 2023-06-02
Windows 10 1507 HIGH 7.8
CVE-2022-35743

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Fix: 10.0.10240.19387 / 10.0.14393.5291+
Fix from $1,950 2023-05-31
Networker CRITICAL 9.8
CVE-2023-25539

Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially …

Fix: 19.7.0.4+
Fix from $2,300 2023-05-31
Codeigniter CRITICAL 9.8
CVE-2023-32692

CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. Th…

Fix: 4.3.5+
Fix from $2,300 2023-05-30
Openemr HIGH 8.8
CVE-2023-2943

Code Injection in GitHub repository openemr/openemr prior to 7.0.1.

Fix: 7.0.1+
Fix from $1,950 2023-05-27
Dedecms HIGH 8.8
CVE-2023-2928EPSS 51%

A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t…

Fix: after 5.7.106
Fix from $1,950 2023-05-27
Faculty Evaluation System HIGH 7.2
CVE-2023-33440EPSS 15%

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.

No fix yet
Fix from $1,950 2023-05-26
Camaleon Cms CRITICAL 9.8
CVE-2023-30145EPSS 46%

Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.

Fix: after 2.7.0
Fix from $2,300 2023-05-26
Rocketmq CRITICAL 9.8
CVE-2023-33246 KEVEPSS 97%

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu…

Fix: 4.9.6 / 5.1.1+
Fix from $2,300 2023-05-24
Teampass HIGH 8.8
CVE-2023-2859

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Fix: 3.0.9+
Fix from $1,950 2023-05-24
Sqlite Jdbc CRITICAL 9.8
CVE-2023-32697

SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JD…

Fix: 3.41.2.2+
Fix from $2,300 2023-05-23
Drive Explorer CRITICAL 9.8
CVE-2023-25953

Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected…

Fix: after 3.5.4
Fix from $2,300 2023-05-23
Dvtel Camera Firmware CRITICAL 9.8
CVE-2023-29861

An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of…

No fix yet
Fix from $2,300 2023-05-15
Agasio Camera Firmware CRITICAL 9.8
CVE-2023-29862

An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameter…

No fix yet
Fix from $2,300 2023-05-15
Jedox HIGH 7.5
CVE-2022-47879EPSS 6%

A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the…

No fix yet
Fix from $1,950 2023-05-12
Craft Cms HIGH 8.8
CVE-2023-30130

An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.

No fix yet
Fix from $1,950 2023-05-12
Go HIGH 7.3
CVE-2023-24539

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/'…

Fix: 1.19.9 / 1.20.4+
Fix from $1,950 2023-05-11
Go HIGH 7.3
CVE-2023-29400

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results w…

Fix: 1.19.9 / 1.20.4+
Fix from $1,950 2023-05-11
Phpok CRITICAL 9.8
CVE-2022-47129

PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.

No fix yet
Fix from $2,300 2023-05-11
Sharepoint Enterprise Server HIGH 7.2
CVE-2023-24955 KEVEPSS 85%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-05-09
Jsreport CRITICAL 10.0
CVE-2023-2583

Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.

Fix: 3.11.3+
Fix from $2,300 2023-05-08
S Cms HIGH 7.2
CVE-2023-29963

S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.

No fix yet
Fix from $1,950 2023-05-05
Kibana HIGH 8.8
CVE-2023-31414

Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could…

Fix: after 8.7.0
Fix from $1,950 2023-05-04
Kibana HIGH 8.8
CVE-2023-31415

Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request…

Mitigation only
Fix from $1,950 2023-05-04