Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
We1626 Firmware CRITICAL 9.8
CVE-2022-45553

An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connectio…

Mitigation only
Fix from $2,300 2023-03-03
Enterprise Server HIGH 8.8
CVE-2023-22381

A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environm…

Fix: 3.4.15 / 3.5.12+
Fix from $1,950 2023-03-02
Xwiki CRITICAL 9.8
CVE-2023-26477EPSS 75%

XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, P…

Fix: 13.10.10 / 14.4.6+
Fix from $2,300 2023-03-02
Eg7035 M11 Firmware CRITICAL 9.8
CVE-2023-1097

Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Comman…

Mitigation only
Fix from $2,300 2023-03-01
Safari HIGH 8.8
CVE-2023-23496

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS…

Fix: 9.3 / 13.2+
Fix from $1,950 2023-02-27
Online Boat Reservation System MEDIUM 6.1
CVE-2023-1030

A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vul…

No fix yet
Fix from $1,600 2023-02-24
Markdown Electron HIGH 7.8
CVE-2023-1005

A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown functionality. The manipulat…

No fix yet
Fix from $1,950 2023-02-24
Marktext HIGH 7.8
CVE-2023-1004

A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functiona…

Fix: after 0.17.1
Fix from $1,950 2023-02-24
Typecho CRITICAL 9.8
CVE-2023-24114

typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.

Fix: 1.2.0+
Fix from $2,300 2023-02-22
Hour Of Code Python 2015 CRITICAL 9.8
CVE-2023-24107

hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package …

No fix yet
Fix from $2,300 2023-02-22
Nautobot CRITICAL 9.8
CVE-2023-25657

Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions earlier than 1.5.7 are impacted by a remote cod…

Fix: 1.5.7+
Fix from $2,300 2023-02-21
Checkmk HIGH 8.8
CVE-2022-46836

PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an atta…

No fix yet
Fix from $1,950 2023-02-20
Frame Service CRITICAL 9.8
CVE-2021-26277

The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.

Fix: 2021.6.30+
Fix from $2,300 2023-02-17
Wms CRITICAL 9.8
CVE-2021-33949

An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.

No fix yet
Fix from $2,300 2023-02-17
Fuguhub HIGH 8.8
CVE-2023-24078EPSS 53%

Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.

Fix: after 8.1
Fix from $1,950 2023-02-17
Froxlor HIGH 8.8
CVE-2023-0877

Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.

Fix: 2.0.11+
Fix from $1,950 2023-02-17
Kardex Control Center CRITICAL 9.8
CVE-2023-22855EPSS 15%

Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path i…

No fix yet
Fix from $2,300 2023-02-15
Azure Devops Server HIGH 7.5
CVE-2023-21553

Azure DevOps Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2023-02-14
Ruckus Wireless Admin CRITICAL 9.8
CVE-2023-25717 KEVEPSS 98%

Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_us…

Fix: 3.6.2.0.795 / 5.2.1.3+
Fix from $2,300 2023-02-13
X 600m Firmware CRITICAL 9.8
CVE-2023-23551

Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.

Fix: 1.16.00+
Fix from $2,300 2023-02-13
Phpmyfaq CRITICAL 9.8
CVE-2023-0788

Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

Fix: 3.1.11+
Fix from $2,300 2023-02-12
Phpmyfaq MEDIUM 5.4
CVE-2023-0792

Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

Fix: 3.1.11+
Fix from $1,600 2023-02-12
Ecu R Firmware CRITICAL 9.8
CVE-2022-45699EPSS 77%

Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary comma…

No fix yet
Fix from $2,300 2023-02-10
Usg Firmware HIGH 8.8
CVE-2023-23912

A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCP…

Fix: 2.0.9 / 4.4.57+
Fix from $1,950 2023-02-09
Yugabytedb CRITICAL 9.8
CVE-2023-0575

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Win…

Fix: 2.2.0.0+
Fix from $2,300 2023-02-09
Froxlor HIGH 8.8
CVE-2023-0671

Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.

Fix: 2.0.10+
Fix from $1,950 2023-02-04
Emc Networker CRITICAL 9.8
CVE-2023-24576

EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsre…

Fix: after 19.8
Fix from $2,300 2023-02-03
Websphere Application Server CRITICAL 9.8
CVE-2023-23477

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft…

Mitigation only
Fix from $2,300 2023-02-03
Phpwcms CRITICAL 9.8
CVE-2021-36424

An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

Fix: 1.9.26+
Fix from $2,300 2023-02-03
Seacms HIGH 7.2
CVE-2022-48093

Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.

No fix yet
Fix from $1,950 2023-02-01