Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Dragonfly Folio G3 2 In 1 Firmware HIGH 7.8
CVE-2022-27537

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation o…

No fix yet
Fix from $1,950 2023-02-01
Rukovoditel CRITICAL 9.8
CVE-2022-48175

Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/aja…

No fix yet
Fix from $2,300 2023-01-30
Eta HIGH 8.8
CVE-2022-25967

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with vi…

Fix: 2.0.0+
Fix from $1,950 2023-01-30
Psiturk HIGH 8.8
CVE-2021-4315

A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unknown code of the file psiturk/…

Fix: 3.2.1+
Fix from $1,950 2023-01-28
Ayacms HIGH 7.2
CVE-2022-48116

AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.

No fix yet
Fix from $1,950 2023-01-27
Modelina HIGH 8.8
CVE-2023-23619

Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vul…

Fix: 1.0.0+
Fix from $1,950 2023-01-26
Simple Git CRITICAL 9.8
CVE-2022-25860

Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() metho…

Fix: 3.16.0+
Fix from $2,300 2023-01-26
Uflo CRITICAL 9.8
CVE-2022-25894

All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.create…

No fix yet
Fix from $2,300 2023-01-26
Grand Theft Auto V HIGH 7.3
CVE-2023-24059

Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.

No fix yet
Fix from $1,950 2023-01-22
Gii HIGH 8.8
CVE-2020-36655

Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbit…

Fix: 2.2.2+
Fix from $1,950 2023-01-21
Tl Wdr7660 Firmware HIGH 8.0
CVE-2021-37774

An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2023-01-19
Opentext Extended Ecm HIGH 8.8
CVE-2022-45928

A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the…

Fix: after 22.3
Fix from $1,950 2023-01-18
Emc Metro Node HIGH 8.8
CVE-2022-34456

Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially explo…

Fix: 7.1+
Fix from $1,950 2023-01-18
Vm Virtualbox HIGH 8.1
CVE-2023-21886

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.…

Fix: 6.1.42 / 7.0.6+
Fix from $1,950 2023-01-18
Communications Converged Application Server CRITICAL 9.8
CVE-2023-21890

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that …

Patch available
Fix from $2,300 2023-01-18
Shopware HIGH 8.8
CVE-2023-22731

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is po…

Fix: 6.4.18.1+
Fix from $1,950 2023-01-17
Debian Linux HIGH 8.0
CVE-2022-46648

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con…

Fix: 1.13.0+
Fix from $1,950 2023-01-17
Debian Linux HIGH 8.0
CVE-2022-47318

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con…

Fix: 1.13.0+
Fix from $1,950 2023-01-17
Pyload CRITICAL 9.8
CVE-2023-0297EPSS 96%

Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.

Fix: after 0.4.20
Fix from $2,300 2023-01-14
Tiki HIGH 8.8
CVE-2023-22853

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

Fix: 24.1+
Fix from $1,950 2023-01-14
Nvidia Isaac Sim HIGH 7.8
CVE-2022-42268

Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications all…

Fix: 2022.2 / 2022.2.0+
Fix from $1,950 2023-01-13
Sugarcrm HIGH 8.8
CVE-2023-22952 KEVEPSS 80%

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Fix: 11.0.5 / 12.0.2+
Fix from $1,950 2023-01-11
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2023-0022

SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by…

Mitigation only
Fix from $1,950 2023-01-10
Window Control HIGH 7.8
CVE-2022-25926

Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.

Fix: 1.4.5+
Fix from $1,950 2023-01-04
Daloradius HIGH 8.8
CVE-2023-0048EPSS 32%

Code Injection in GitHub repository lirantal/daloradius prior to master-branch.

Fix: 2023-01-04+
Fix from $1,950 2023-01-04
Nterchange CRITICAL 9.8
CVE-2015-10009

A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getContent of the file app/contro…

Fix: 4.1.1+
Fix from $2,300 2023-01-02
Firefox HIGH 8.8
CVE-2022-46874

A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This cou…

Fix: 102.6 / 108.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-22756

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable s…

Fix: 91.6 / 97.0+
Fix from $1,950 2022-12-22
Ayacms HIGH 8.8
CVE-2022-46101

AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious cod…

No fix yet
Fix from $1,950 2022-12-22
Intellij Idea HIGH 7.8
CVE-2022-47896

In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.

Fix: 2022.3.1+
Fix from $1,950 2022-12-22