Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Edraw Max HIGH 7.8
CVE-2023-27770

An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_fu…

No fix yet
Fix from $1,950 2023-04-04
Vantara Pentaho Business Analytics Server HIGH 8.8
CVE-2022-43938EPSS 26%

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disab…

Fix: 9.3.0.2+
Fix from $1,950 2023-04-03
Vantara Pentaho Business Analytics Server MEDIUM 6.3
CVE-2022-3960

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disab…

Fix: 9.3.0.2+
Fix from $1,600 2023-04-03
Vantara Pentaho Business Analytics Server HIGH 7.2
CVE-2022-43769 KEVEPSS 98%

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property v…

Fix: 9.3.0.2+
Fix from $1,950 2023-04-03
Htmlunit CRITICAL 9.8
CVE-2023-26119

Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsi…

Fix: 3.0.0+
Fix from $2,300 2023-04-03
Rockoa CRITICAL 9.8
CVE-2023-1773

A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of…

Mitigation only
Fix from $2,300 2023-03-31
Designer CRITICAL 9.8
CVE-2023-25261

Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer …

Mitigation only
Fix from $2,300 2023-03-27
Spam Sqr HIGH 7.2
CVE-2023-24835

Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with admi…

Fix: 2.221231+
Fix from $1,950 2023-03-27
Openoffice HIGH 7.8
CVE-2022-38745

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro…

Fix: 4.1.14+
Fix from $1,950 2023-03-24
Moodle CRITICAL 9.8
CVE-2023-28333

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploi…

Fix: 3.9.20 / 3.11.13+
Fix from $2,300 2023-03-23
Ipr512 Firmware HIGH 7.5
CVE-2023-24709EPSS 44%

An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.

No fix yet
Fix from $1,950 2023-03-21
Insightappsec HIGH 8.8
CVE-2023-1304

An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are nor…

Fix: 23.2.1 / 2023.02.01+
Fix from $1,950 2023-03-21
Insightappsec HIGH 8.8
CVE-2023-1306

An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead t…

Fix: 23.2.1 / 2023.02.01+
Fix from $1,950 2023-03-21
Otrs HIGH 7.8
CVE-2023-1250

Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Cod…

Fix: 7.0.42 / 8.0.31+
Fix from $1,950 2023-03-20
Hkcms HIGH 8.8
CVE-2023-1482

A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. This affects an unknown part of the file /admin.php/appcenter/…

No fix yet
Fix from $1,950 2023-03-18
Ifix CRITICAL 9.8
CVE-2023-0598

GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an att…

Mitigation only
Fix from $2,300 2023-03-16
Jhr N916r Firmware CRITICAL 9.8
CVE-2023-24795

Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.

Fix: after 21.11.1.1483
Fix from $2,300 2023-03-16
Swig Templates CRITICAL 9.8
CVE-2023-25344

An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype ano…

Fix: after 2.0.4
Fix from $2,300 2023-03-15
Solution Manager HIGH 8.8
CVE-2023-27893

An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP manag…

Mitigation only
Fix from $1,950 2023-03-14
Battery Pack Sp With Wifi Firmware HIGH 7.2
CVE-2023-0888

An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and …

Fix: after 054u000092
Fix from $1,950 2023-03-13
Enovia Live Collaboration CRITICAL 9.8
CVE-2023-1287

An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.

No fix yet
Fix from $2,300 2023-03-09
Emacs HIGH 7.8
CVE-2023-27986

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-q…

Fix: after 28.2
Fix from $1,950 2023-03-09
Qwik CRITICAL 9.8
CVE-2023-1283

Code Injection in GitHub repository builderio/qwik prior to 0.21.0.

Fix: 0.21.0+
Fix from $2,300 2023-03-08
Zephyr Enterprise CRITICAL 9.8
CVE-2023-22889

SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauth…

Fix: after 7.15
Fix from $2,300 2023-03-08
Enterprise Protection HIGH 8.8
CVE-2023-0089

The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through '…

Fix: 8.13.22 / 8.18.4+
Fix from $1,950 2023-03-08
Enterprise Protection CRITICAL 9.8
CVE-2023-0090

The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code throug…

Fix: 8.13.22 / 8.18.4+
Fix from $2,300 2023-03-08
Typora HIGH 7.8
CVE-2023-1003

A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH J…

Fix: after 1.5.5
Fix from $1,950 2023-03-07
Moodle CRITICAL 9.8
CVE-2021-36394EPSS 7%

In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

Fix: 3.9.8 / 3.10.5+
Fix from $2,300 2023-03-06
Funadmin CRITICAL 9.8
CVE-2023-24776

Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.

No fix yet
Fix from $2,300 2023-03-06
Sketchsvg HIGH 7.8
CVE-2023-26107

All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization wh…

No fix yet
Fix from $1,950 2023-03-06