Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Wpcargo Track \& Trace CRITICAL 9.8
CVE-2021-25003EPSS 56%

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on t…

Fix: 6.9.0+
Fix from $2,300 2022-03-14
Microweber MEDIUM 6.7
CVE-2022-0921

Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.

Fix: 1.2.12+
Fix from $1,600 2022-03-11
Seomatic CRITICAL 9.8
CVE-2021-44618

A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.

Patch available
Fix from $2,300 2022-03-11
Ipdio Firmware HIGH 8.8
CVE-2022-24915

The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will…

Mitigation only
Fix from $1,950 2022-03-10
Ipdio Firmware HIGH 8.8
CVE-2022-22985

The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will…

Mitigation only
Fix from $1,950 2022-03-10
Mybb HIGH 7.2
CVE-2022-24734EPSS 78%

MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correct…

Fix: 1.8.30+
Fix from $1,950 2022-03-09
Fedora MEDIUM 6.3
CVE-2022-24512

.NET and Visual Studio Remote Code Execution Vulnerability

Fix: 7.0.9 / 7.1.6+
Fix from $1,600 2022-03-09
Microweber HIGH 8.8
CVE-2022-0896

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

Fix: 1.3+
Fix from $1,950 2022-03-09
Jira Data Center HIGH 7.2
CVE-2021-43944

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected ve…

Fix: 8.13.15 / 8.20.3+
Fix from $1,950 2022-03-08
Pytorch Lightning CRITICAL 9.8
CVE-2022-0845

Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

Fix: 1.6.0+
Fix from $2,300 2022-03-05
Spring Cloud Gateway CRITICAL 10.0
CVE-2022-22947 KEVEPSS 98%

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi…

Fix: 3.0.7+
Fix from $2,300 2022-03-03
Hoteldruid HIGH 8.8
CVE-2022-22909EPSS 45%

HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payloa…

No fix yet
Fix from $1,950 2022-03-03
Dolibarr Erp\/crm HIGH 8.8
CVE-2022-0819EPSS 41%

Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

Fix: 15.0.1+
Fix from $1,950 2022-03-02
Ayacms HIGH 7.2
CVE-2021-44238

AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,

No fix yet
Fix from $1,950 2022-03-01
Pluxml HIGH 8.8
CVE-2022-25018

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

Mitigation only
Fix from $1,950 2022-03-01
Youtrack CRITICAL 9.8
CVE-2022-24442

JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

Fix: 2021.4.40426+
Fix from $2,300 2022-02-25
Emui HIGH 7.5
CVE-2021-22395

There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2022-02-25
A Blog Cms MEDIUM 6.5
CVE-2022-23810

Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prio…

Fix: 2.8.75 / 2.9.40+
Fix from $1,600 2022-02-24
Advanced Server Access Client For Windows HIGH 8.8
CVE-2022-24295EPSS 17%

Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.

Fix: 1.57.0+
Fix from $1,950 2022-02-21
Sourcegraph HIGH 8.8
CVE-2022-23642EPSS 74%

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` servi…

Fix: 3.37+
Fix from $1,950 2022-02-18
Mcms CRITICAL 9.1
CVE-2021-46063

MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.

No fix yet
Fix from $2,300 2022-02-18
Php Everywhere HIGH 8.8
CVE-2022-24663

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authent…

Fix: after 2.0.3
Fix from $1,950 2022-02-16
Php Everywhere HIGH 8.8
CVE-2022-24664

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user a…

Fix: after 2.0.3
Fix from $1,950 2022-02-16
Php Everywhere HIGH 8.8
CVE-2022-24665

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit p…

Fix: after 2.0.3
Fix from $1,950 2022-02-16
Magnolia Cms CRITICAL 9.8
CVE-2021-46362

A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers …

Fix: 6.2.4+
Fix from $2,300 2022-02-11
Android MEDIUM 6.0
CVE-2022-23426

A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

Mitigation only
Fix from $1,600 2022-02-11
Cassandra CRITICAL 9.1
CVE-2021-44521EPSS 55%

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…

Fix: 3.0.26 / 3.11.12+
Fix from $2,300 2022-02-11
Blitz CRITICAL 9.8
CVE-2022-23631

superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to r…

Fix: 0.45.3 / 1.8.1+
Fix from $2,300 2022-02-09
Twig CRITICAL 9.8
CVE-2022-23614EPSS 8%

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attac…

Fix: 2.14.11 / 3.3.8+
Fix from $2,300 2022-02-04
Icms CRITICAL 9.8
CVE-2021-44978

iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.

Fix: after 8.0.0
Fix from $2,300 2022-02-04