Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Ilx F509 Firmware HIGH 8.0
CVE-2024-23963

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must fi…

Mitigation only
Fix from $1,950 2025-01-31
Borderless HIGH 7.2
CVE-2024-11600

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Remote Code Execution in al…

Fix: after 1.5.9
Fix from $1,950 2025-01-30
Unclassified HIGH 7.3
CVE-2024-13453

The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions u…

Mitigation only
Fix from $1,950 2025-01-30
Library Card System MEDIUM 6.1
CVE-2025-0844

A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown fun…

No fix yet
Fix from $1,600 2025-01-30
Enterprise Server HIGH 7.1
CVE-2024-10001

A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via…

Fix: 3.11.6 / 3.12.10+
Fix from $1,950 2025-01-29
Job Recruitment MEDIUM 6.1
CVE-2025-0806

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the f…

No fix yet
Fix from $1,600 2025-01-29
Cdg MEDIUM 6.1
CVE-2025-0795

A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the file /todolistjump.jsp. The …

No fix yet
Fix from $1,600 2025-01-29
Cdg MEDIUM 6.1
CVE-2025-0794

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown functionality of the file /todoDet…

No fix yet
Fix from $1,600 2025-01-29
Cdg MEDIUM 6.1
CVE-2025-0790

A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the file /doneDetail.jsp. The mani…

No fix yet
Fix from $1,600 2025-01-29
Cdg MEDIUM 6.1
CVE-2025-0785

A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing of the file /SysConfig.jsp. Th…

Mitigation only
Fix from $1,600 2025-01-28
Cdg MEDIUM 5.4
CVE-2025-0787

A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Mitigation only
Fix from $1,600 2025-01-28
Unclassified HIGH 7.0
CVE-2025-24482

A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and al…

No fix yet
Fix from $1,950 2025-01-28
Android MEDIUM 6.5
CVE-2024-40673

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper inp…

Mitigation only
Fix from $1,600 2025-01-28
Recipes CRITICAL 9.9
CVE-2025-23211

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to e…

Fix: 1.5.24+
Fix from $2,300 2025-01-28
Ipados HIGH 7.8
CVE-2025-24159

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonom…

Fix: 2.3 / 11.3+
Fix from $1,950 2025-01-27
Image Gallery Management System MEDIUM 6.1
CVE-2025-0721

A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.ph…

No fix yet
Fix from $1,600 2025-01-27
School Management Software MEDIUM 5.4
CVE-2025-0710

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /no…

No fix yet
Fix from $1,600 2025-01-24
Opencms MEDIUM 5.4
CVE-2025-0708

A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/mode…

Mitigation only
Fix from $1,600 2025-01-24
Bootplus MEDIUM 5.4
CVE-2025-0706

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this issue …

Fix: after 2020-08-24
Fix from $1,600 2025-01-24
Gamipress HIGH 7.3
CVE-2024-13495

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary s…

Fix: 7.2.2+
Fix from $1,950 2025-01-22
Gamipress HIGH 7.3
CVE-2024-13499

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary s…

Fix: 7.2.2+
Fix from $1,950 2025-01-22
Android CRITICAL 9.8
CVE-2024-49747

In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote …

Mitigation only
Fix from $2,300 2025-01-21
Android HIGH 8.8
CVE-2024-43770

In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 8.8
CVE-2024-43771

In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/a…

Mitigation only
Fix from $1,950 2025-01-21
Magma CRITICAL 9.8
CVE-2024-24421

A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attacker…

Fix: after 1.8.0
Fix from $2,300 2025-01-21
Ambari HIGH 8.8
CVE-2024-51941

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbit…

Fix: after 2.7.8
Fix from $1,950 2025-01-21
Reyee Os CRITICAL 9.8
CVE-2024-42936

The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT b…

No fix yet
Fix from $2,300 2025-01-21
Unclassified MEDIUM 5.5
CVE-2024-55504

An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and…

Mitigation only
Fix from $1,600 2025-01-21
School Management Software MEDIUM 5.4
CVE-2025-0581

A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. This affects an unknown part of the file /chat/…

No fix yet
Fix from $1,600 2025-01-20
Craft Cms HIGH 8.1
CVE-2025-23209 KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerab…

Fix: 4.13.8 / 5.5.8+
Fix from $1,950 2025-01-18