Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Roxy Wi CRITICAL 9.8
CVE-2022-31161EPSS 27%

Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-15
Pbootcms CRITICAL 9.8
CVE-2022-32417EPSS 34%

PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

No fix yet
Fix from $2,300 2022-07-14
Ruggedcom Ros HIGH 8.0
CVE-2022-34663

A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCO…

Fix: 5.6.0+
Fix from $1,950 2022-07-12
Simatic Cp 1242 7 V2 Firmware HIGH 7.6
CVE-2022-34821

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE …

Fix: 3.0.22+
Fix from $1,950 2022-07-12
Custom Content Type Manager HIGH 7.2
CVE-2015-3173

custom-content-type-manager Wordpress plugin can be used by an administrator to achieve arbitrary PHP remote code execution.

Fix: 0.9.8.6+
Fix from $1,950 2022-07-06
Grav HIGH 7.2
CVE-2022-2073EPSS 10%

Code Injection in GitHub repository getgrav/grav prior to 1.7.34.

Fix: 1.7.34+
Fix from $1,950 2022-06-29
Piwigo HIGH 8.8
CVE-2021-40553

piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.

No fix yet
Fix from $1,950 2022-06-28
Analytics Stats Counter Statistics CRITICAL 9.8
CVE-2017-20099

A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing…

No fix yet
Fix from $2,300 2022-06-27
Simple Ads Manager CRITICAL 9.8
CVE-2017-20095

A vulnerability classified as critical was found in Simple Ads Manager Plugin. This vulnerability affects unknown code. The manipulation leads to cod…

No fix yet
Fix from $2,300 2022-06-24
Vaultpress HIGH 7.5
CVE-2017-20086

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code…

No fix yet
Fix from $1,950 2022-06-23
Elefant Cms HIGH 8.8
CVE-2017-20064

A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t…

No fix yet
Fix from $1,950 2022-06-20
Flatcore Cms HIGH 8.8
CVE-2021-41402

flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.

No fix yet
Fix from $1,950 2022-06-16
Member Hero CRITICAL 9.8
CVE-2022-0885EPSS 9%

The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing …

Fix: after 1.0.9
Fix from $2,300 2022-06-13
Nuitka HIGH 7.8
CVE-2022-2054

Code Injection in GitHub repository nuitka/nuitka prior to 0.9.

Fix: 0.9+
Fix from $1,950 2022-06-12
Seomatic CRITICAL 9.8
CVE-2021-41749EPSS 18%

In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowi…

Fix: after 3.4.11
Fix from $2,300 2022-06-12
Convert Svg Core HIGH 7.8
CVE-2022-24429

The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read ar…

Fix: 0.6.3+
Fix from $1,950 2022-06-10
Drawio MEDIUM 5.4
CVE-2022-2014

Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.

Fix: 19.0.2+
Fix from $1,600 2022-06-09
Metacalc CRITICAL 9.8
CVE-2022-21122

The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math c…

Fix: 0.0.2+
Fix from $2,300 2022-06-08
Active Storage CRITICAL 9.8
CVE-2022-21831

A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.

Fix: 5.2.6.3 / 6.0.4.7+
Fix from $2,300 2022-05-26
Debian Linux HIGH 8.8
CVE-2022-29221

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.…

Fix: 3.1.45 / 4.1.1+
Fix from $1,950 2022-05-24
Tensorflow HIGH 7.8
CVE-2022-29216

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is …

Fix: 2.6.4 / 2.7.2+
Fix from $1,950 2022-05-21
Cmt Svr 100 Firmware CRITICAL 9.8
CVE-2021-27446

The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privil…

Fix: 20210209 / 20210222+
Fix from $2,300 2022-05-16
Publify MEDIUM 6.5
CVE-2022-0578

Code Injection in GitHub repository publify/publify prior to 9.2.8.

Fix: 9.2.8+
Fix from $1,600 2022-05-16
Ionize CRITICAL 9.8
CVE-2022-29307EPSS 18%

IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.ph…

No fix yet
Fix from $2,300 2022-05-12
Pentest Collaboration Framework HIGH 8.8
CVE-2021-42651

A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute ar…

Patch available
Fix from $1,950 2022-05-11
Acom508 Firmware HIGH 8.8
CVE-2022-23332EPSS 5%

Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-1…

Fix: after 532-609-915-041-100-020
Fix from $1,950 2022-05-09
Sourcegraph HIGH 7.2
CVE-2022-29171

Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserv…

Fix: 3.38.0+
Fix from $1,950 2022-05-06
Flux2 CRITICAL 9.9
CVE-2022-24817

Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.…

Fix: 0.19.0 / 0.23.0+
Fix from $2,300 2022-05-06
Drawio CRITICAL 9.6
CVE-2022-1575

Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desk…

Fix: 18.0.0+
Fix from $2,300 2022-05-05
Intellij Idea MEDIUM 6.7
CVE-2022-29813

In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible

Fix: 2022.1+
Fix from $1,600 2022-04-28