Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
GitLab MEDIUM 5.7
CVE-2023-1178

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all vers…

Fix: 15.9.6 / 15.10.5+
Fix from $1,600 2023-05-03
Iuclid HIGH 8.8
CVE-2023-26546

European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) …

Fix: 6.27.6+
Fix from $1,950 2023-05-02
Mccms MEDIUM 6.5
CVE-2023-26782

An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cach…

No fix yet
Fix from $1,600 2023-04-28
Jfinal Cms CRITICAL 9.8
CVE-2023-30349

JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.

No fix yet
Fix from $2,300 2023-04-27
Wireless N Repeater Mini Router Firmware CRITICAL 9.8
CVE-2023-30404

Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in t…

Mitigation only
Fix from $2,300 2023-04-26
Alf HIGH 7.2
CVE-2023-2259

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

Fix: 2.0-m4-2304+
Fix from $1,950 2023-04-24
Dawnsparks Node Tesseract CRITICAL 9.8
CVE-2023-29566

huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the ch…

Patch available
Fix from $2,300 2023-04-24
Netact HIGH 8.8
CVE-2023-26060

An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a clie…

Fix: 20.1+
Fix from $1,950 2023-04-24
Orion Platform HIGH 7.2
CVE-2022-36963EPSS 8%

The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds …

Fix: 2023.2+
Fix from $1,950 2023-04-21
Struxureware Data Center Expert CRITICAL 9.8
CVE-2023-25549

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter…

Fix: after 7.9.2
Fix from $2,300 2023-04-18
Struxureware Data Center Expert CRITICAL 9.8
CVE-2023-25550

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” paramet…

Fix: after 7.9.2
Fix from $2,300 2023-04-18
Shopware HIGH 8.8
CVE-2023-2017

Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform …

Fix: after 6.4.20.0
Fix from $1,950 2023-04-17
Xwiki HIGH 8.8
CVE-2023-29509EPSS 76%

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents ca…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-04-16
Xwiki HIGH 8.8
CVE-2023-30537

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on …

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-04-16
Xwiki HIGH 8.8
CVE-2023-29212

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Pytho…

Fix: 14.4.7+
Fix from $1,950 2023-04-16
Xwiki HIGH 8.8
CVE-2023-29214

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Pytho…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-04-16
Xwiki HIGH 8.8
CVE-2023-29211

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execut…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-04-16
Score CRITICAL 9.8
CVE-2020-29007

The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. …

Fix: after 0.3.0
Fix from $2,300 2023-04-15
Xwiki HIGH 8.8
CVE-2023-29209

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents in…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-04-15
Xwiki HIGH 8.8
CVE-2023-29210

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents in…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-04-15
Dedecms CRITICAL 9.8
CVE-2023-2056

A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.p…

Fix: after 5.7.87
Fix from $2,300 2023-04-14
Unify Openscape Bcf HIGH 7.2
CVE-2023-30638

Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated ad…

Fix: 10r3.1.2 / 10r3.1.3+
Fix from $1,950 2023-04-14
Novi Survey CRITICAL 9.8
CVE-2023-29492 KEV

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not pro…

Fix: 8.9.43676+
Fix from $2,300 2023-04-11
Customer Relationship Management MEDIUM 6.3
CVE-2023-27897

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authoriz…

Mitigation only
Fix from $1,600 2023-04-11
Launcher CRITICAL 9.8
CVE-2023-27650

An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.

No fix yet
Fix from $2,300 2023-04-10
Taocms CRITICAL 9.8
CVE-2023-1947

A vulnerability was found in taoCMS 3.0.2. It has been classified as critical. Affected is an unknown function of the file /admin/admin.php. The mani…

No fix yet
Fix from $2,300 2023-04-07
Airflow Hive Provider CRITICAL 9.8
CVE-2023-28706

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects…

Fix: 6.0.0+
Fix from $2,300 2023-04-07
Codefever HIGH 8.8
CVE-2023-26817

codefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the component /controllers/api/use…

Fix: 2023-02-07+
Fix from $1,950 2023-04-07
Go CRITICAL 9.8
CVE-2023-24538

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, …

Fix: 1.19.8 / 1.20.3+
Fix from $2,300 2023-04-06
GitLab CRITICAL 9.8
CVE-2023-1708

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-p…

Fix: 15.8.5 / 15.9.4+
Fix from $2,300 2023-04-05