Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Pytorch CRITICAL 9.8
CVE-2022-45907

In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

Fix: 1.13.1+
Fix from $2,300 2022-11-26
Paddlepaddle CRITICAL 9.8
CVE-2022-45908

In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This …

Fix: 2.4+
Fix from $2,300 2022-11-26
Eyoom Builder CRITICAL 9.8
CVE-2022-41158

Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploi…

Fix: after 4.5.3
Fix from $2,300 2022-11-25
Filecloud HIGH 7.2
CVE-2022-39833

FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoint…

Fix: 21.3.7.18607+
Fix from $1,950 2022-11-23
Mivoice Connect MEDIUM 6.8
CVE-2022-41223 KEVEPSS 11%

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection atta…

Fix: after 22.22.6100.0
Fix from $1,600 2022-11-22
Super Xray CRITICAL 9.8
CVE-2022-41945

super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced ​​into the command, resu…

No fix yet
Fix from $2,300 2022-11-21
Lava CRITICAL 9.8
CVE-2022-45132

In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. Th…

Fix: 2022.11.1+
Fix from $2,300 2022-11-18
Meetings HIGH 7.3
CVE-2022-28766

Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a D…

Fix: 5.12.6+
Fix from $1,950 2022-11-17
Limesurvey HIGH 7.2
CVE-2022-43279

LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.

Patch available
Fix from $1,950 2022-11-15
Airflow HIGH 8.8
CVE-2022-40127EPSS 86%

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually …

Fix: 2.4.0+
Fix from $1,950 2022-11-14
Desktop HIGH 7.8
CVE-2022-41882

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, if a user received a maliciou…

Patch available
Fix from $1,950 2022-11-11
Espcms CRITICAL 9.8
CVE-2022-44087

ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.

Mitigation only
Fix from $2,300 2022-11-10
Espcms CRITICAL 9.8
CVE-2022-44088EPSS 20%

ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.

Mitigation only
Fix from $2,300 2022-11-10
Espcms CRITICAL 9.8
CVE-2022-44089

ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.

Mitigation only
Fix from $2,300 2022-11-10
365 Apps HIGH 7.8
CVE-2022-41061

Microsoft Word Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2022-11-09
Gui MEDIUM 6.1
CVE-2022-41205

SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registr…

Mitigation only
Fix from $1,600 2022-11-08
Wp All Import HIGH 7.2
CVE-2022-3418

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the ser…

Fix: 3.6.9+
Fix from $1,950 2022-11-07
Ootbi HIGH 8.8
CVE-2022-44794

An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrar…

Fix: 1.0.13.1611+
Fix from $1,950 2022-11-07
Froxlor MEDIUM 6.1
CVE-2022-3869

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

Fix: 0.10.38.2+
Fix from $1,600 2022-11-05
Splunk MEDIUM 6.5
CVE-2022-43572

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HE…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Bosh Editor CRITICAL 9.8
CVE-2022-31691

Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor…

Fix: 1.40.0 / 4.16.1+
Fix from $2,300 2022-11-04
Splunk HIGH 8.8
CVE-2022-43571EPSS 13%

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation c…

Fix: 8.1.12 / 8.2.9+
Fix from $1,950 2022-11-03
Ipados HIGH 7.8
CVE-2022-32924

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 …

Fix: 9.1 / 11.7+
Fix from $1,950 2022-11-01
Dir 846 Firmware CRITICAL 9.8
CVE-2020-21016

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.

No fix yet
Fix from $2,300 2022-10-31
Pimcore CRITICAL 9.8
CVE-2022-39365

Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/…

Fix: 10.5.9+
Fix from $2,300 2022-10-27
Wp All Export HIGH 7.2
CVE-2022-3394

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allow…

Fix: 1.7.9+
Fix from $1,950 2022-10-25
Github Workflows HIGH 8.8
CVE-2022-39326

kartverket/github-workflows are shared reusable workflows for GitHub Actions. Prior to version 2.7.5, all users of the `run-terraform` reusable workf…

Fix: 2.7.5+
Fix from $1,950 2022-10-25
Azure Command Line Interface CRITICAL 9.8
CVE-2022-39327

Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code in…

Fix: 2.40.0+
Fix from $2,300 2022-10-25
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26727

Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26728

Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arb…

Mitigation only
Fix from $2,300 2022-10-24