Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Mdx Mermaid HIGH 7.8
CVE-2022-36036

mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 a…

Fix: 1.3.0+
Fix from $1,950 2022-08-29
Dir 845l Firmware CRITICAL 9.8
CVE-2022-36756

DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

Fix: after 1.0.3
Fix from $2,300 2022-08-28
Tew733gr Firmware CRITICAL 9.8
CVE-2022-37053

TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.

Mitigation only
Fix from $2,300 2022-08-28
Movable Type CRITICAL 9.8
CVE-2022-38078

Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to …

Fix: 1.53 / 6.8.7+
Fix from $2,300 2022-08-24
Transposh Wordpress Translation HIGH 7.2
CVE-2022-25812

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege use…

Fix: 1.0.8+
Fix from $1,950 2022-08-22
Dedecms CRITICAL 9.8
CVE-2022-35516

DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.

Fix: after 5.7.96
Fix from $2,300 2022-08-17
Dedecms HIGH 7.2
CVE-2022-36216

DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.

Fix: after 5.7.97
Fix from $1,950 2022-08-17
Portal For Arcgis CRITICAL 9.6
CVE-2022-38193

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass…

Fix: after 10.8.1
Fix from $2,300 2022-08-16
Taocms CRITICAL 9.8
CVE-2022-36262

An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.

Mitigation only
Fix from $2,300 2022-08-15
Arvados HIGH 8.8
CVE-2022-36006

Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execut…

Fix: 2.4.2+
Fix from $1,950 2022-08-15
Go HIGH 7.8
CVE-2022-30580

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com"…

Fix: 1.17.11 / 1.18.3+
Fix from $1,950 2022-08-10
Windows 10 HIGH 8.1
CVE-2022-35766

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2022-08-09
Windows 10 HIGH 8.1
CVE-2022-35767

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

Mitigation only
Fix from $1,950 2022-08-09
Azure Site Recovery Vmware To Azure HIGH 7.2
CVE-2022-35772

Azure Site Recovery Remote Code Execution Vulnerability

Fix: 9.50.6419.1+
Fix from $1,950 2022-08-09
Visual Studio HIGH 8.8
CVE-2022-35777

Visual Studio Remote Code Execution Vulnerability

Fix: after 16.11
Fix from $1,950 2022-08-09
Azure Real Time Operating System Guix Studio HIGH 7.8
CVE-2022-35779

Azure RTOS GUIX Studio Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2022-08-09
Windows 10 HIGH 8.1
CVE-2022-34714

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

Mitigation only
Fix from $1,950 2022-08-09
Windows Server 2022 CRITICAL 9.8
CVE-2022-34715EPSS 80%

Windows Network File System Remote Code Execution Vulnerability

Mitigation only
Fix from $2,300 2022-08-09
Azure Real Time Operating System Guix Studio HIGH 7.8
CVE-2022-30175

Azure RTOS GUIX Studio Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2022-08-09
Windows 10 HIGH 7.5
CVE-2022-30194

Windows WebBrowser Control Remote Code Execution Vulnerability

Mitigation only
Fix from $1,950 2022-08-09
Android MEDIUM 5.5
CVE-2022-33721

A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.

Mitigation only
Fix from $1,600 2022-08-05
Control Panel HIGH 8.8
CVE-2022-2636

Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.

Fix: 1.6.6+
Fix from $1,950 2022-08-05
Rider HIGH 7.8
CVE-2022-37396

In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution

Fix: 2022.2+
Fix from $1,950 2022-08-03
Mealie HIGH 7.2
CVE-2022-34625

Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a cra…

No fix yet
Fix from $1,950 2022-08-02
Jira Data Center HIGH 7.2
CVE-2022-36799EPSS 45%

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected ve…

Fix: 8.13.19 / 8.20.7+
Fix from $1,950 2022-08-01
Elliegrid CRITICAL 9.8
CVE-2022-30083

EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user input as code (remote).

No fix yet
Fix from $2,300 2022-07-30
Twinsoft CRITICAL 9.8
CVE-2021-22646

The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code e…

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Intellij Idea HIGH 7.8
CVE-2022-37009

In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible

Fix: 2022.2+
Fix from $1,950 2022-07-28
Moodle CRITICAL 9.8
CVE-2022-35649EPSS 8%

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results i…

Fix: 3.9.15 / 3.11.8+
Fix from $2,300 2022-07-25
Convert Svg Core CRITICAL 9.8
CVE-2022-25759EPSS 11%

The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.

Fix: 0.6.2+
Fix from $2,300 2022-07-22