Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26729

Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker t…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26731

Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticate…

Mitigation only
Fix from $2,300 2022-10-24
Katalon HIGH 8.8
CVE-2022-43416

Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be executed and allows invoking Kat…

Fix: 1.0.33+
Fix from $1,950 2022-10-19
Vm Virtualbox HIGH 8.1
CVE-2022-39424

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4…

Fix: 6.1.40+
Fix from $1,950 2022-10-18
Getsimple Cms CRITICAL 9.8
CVE-2022-41544EPSS 10%

GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.

No fix yet
Fix from $2,300 2022-10-18
Emui HIGH 7.8
CVE-2022-41576

The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be i…

No fix yet
Fix from $1,950 2022-10-14
October HIGH 7.2
CVE-2022-35944

October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations t…

Fix: 2.2.34 / 3.0.66+
Fix from $1,950 2022-10-13
Online Diagnostic Lab Management System HIGH 7.2
CVE-2022-41534

Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrd…

No fix yet
Fix from $1,950 2022-10-13
Commons Text CRITICAL 9.8
CVE-2022-42889EPSS 100%

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat…

Fix: 1.10.0 / 7.5.0+
Fix from $2,300 2022-10-13
Debian Linux HIGH 8.8
CVE-2022-42902

In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input…

Fix: 2022.10+
Fix from $1,950 2022-10-13
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2022-40871EPSS 33%

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if …

Fix: after 15.0.3
Fix from $2,300 2022-10-12
Ikuaios HIGH 8.8
CVE-2022-40469

iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.

Fix: 3.6.8+
Fix from $1,950 2022-10-12
Gridea HIGH 7.8
CVE-2022-40274

Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file throug…

No fix yet
Fix from $1,950 2022-09-30
Archer Ax10 V1 Firmware HIGH 8.8
CVE-2022-40486

TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary co…

No fix yet
Fix from $1,950 2022-09-28
Wazuh HIGH 8.8
CVE-2022-40497

Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability vi…

Fix: after 4.3.7
Fix from $1,950 2022-09-28
Joblib CRITICAL 9.8
CVE-2022-21797

The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval()…

Fix: 1.1.1+
Fix from $2,300 2022-09-26
En6200 Prime Quad 35 Firmware CRITICAL 9.8
CVE-2022-40628

This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive),…

Fix: 22.21.2+
Fix from $2,300 2022-09-23
Firewall CRITICAL 9.8
CVE-2022-3236 KEVEPSS 99%

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and olde…

Fix: after 19.0.1
Fix from $2,300 2022-09-23
Pinot CRITICAL 9.8
CVE-2022-26112

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to…

Fix: 0.11.0+
Fix from $2,300 2022-09-23
Wp All Import HIGH 7.2
CVE-2022-36386

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

Fix: after 3.6.7
Fix from $1,950 2022-09-21
Integrated Lights Out 5 Firmware HIGH 8.8
CVE-2022-28640

A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availabili…

Fix: 2.72+
Fix from $1,950 2022-09-20
Zutty CRITICAL 9.8
CVE-2022-41138

In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.

Fix: 0.13+
Fix from $2,300 2022-09-20
Microweber MEDIUM 6.1
CVE-2022-3245

HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, inject…

Fix: 1.3.2+
Fix from $1,600 2022-09-20
Microweber MEDIUM 6.1
CVE-2022-3242

Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

Fix: 1.3.2+
Fix from $1,600 2022-09-20
Xwiki HIGH 8.8
CVE-2022-36099EPSS 76%

XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 …

Fix: 13.10.6 / 14.4+
Fix from $1,950 2022-09-08
Xwiki HIGH 8.8
CVE-2022-36100EPSS 74%

XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki…

Fix: 13.10.6 / 14.4+
Fix from $1,950 2022-09-08
Poetry HIGH 7.3
CVE-2022-36069

Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various comm…

Fix: 1.1.9+
Fix from $1,950 2022-09-07
Openremote CRITICAL 9.8
CVE-2022-31860

An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.

Fix: after 1.0.4
Fix from $2,300 2022-09-06
Fortisoar HIGH 8.8
CVE-2022-35847

An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 thro…

Fix: after 7.0.3
Fix from $1,950 2022-09-06
Ofbiz HIGH 7.5
CVE-2022-25813EPSS 67%

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a …

Fix: 18.12.06+
Fix from $1,950 2022-09-02