Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Foxcms CRITICAL 9.8
CVE-2024-12900

A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the …

Fix: after 1.2
Fix from $2,300 2024-12-23
I Educar MEDIUM 5.4
CVE-2024-12893

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this issue is some unknown functio…

Fix: after 2.9
Fix from $1,600 2024-12-22
Online Exam Mastering System MEDIUM 5.4
CVE-2024-12892

A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this vulnerability is an unknown f…

No fix yet
Fix from $1,600 2024-12-22
Job Recruitment MEDIUM 6.1
CVE-2024-12883

A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown fun…

No fix yet
Fix from $1,600 2024-12-21
Unclassified HIGH 7.3
CVE-2024-11977

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…

Mitigation only
Fix from $1,950 2024-12-21
Emlog MEDIUM 6.1
CVE-2024-12845

A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unknown functionality in the libra…

Fix: after 2.4.1
Fix from $1,600 2024-12-20
Unclassified HIGH 7.8
CVE-2024-56334

systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a p…

Patch available
Fix from $1,950 2024-12-20
Emlog MEDIUM 6.1
CVE-2024-12843

A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the file /admin/p…

Fix: after 2.4.1
Fix from $1,600 2024-12-20
Emlog MEDIUM 6.1
CVE-2024-12844

A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of the file /admin/store.php. The …

Fix: after 2.4.1
Fix from $1,600 2024-12-20
Unclassified CRITICAL 9.4
CVE-2024-56333

Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of art working environment for d…

Mitigation only
Fix from $2,300 2024-12-20
Emlog MEDIUM 6.1
CVE-2024-12842

A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/u…

Fix: 2.4.1+
Fix from $1,600 2024-12-20
Emlog MEDIUM 6.1
CVE-2024-12841

A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part of the file /admin/tag.php. T…

Fix: after 2.4.1
Fix from $1,600 2024-12-20
Unclassified CRITICAL 9.8
CVE-2024-56327

pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying operatio…

Mitigation only
Fix from $2,300 2024-12-19
Firewall Firmware HIGH 8.8
CVE-2024-12729

A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version…

Fix: 21.0.1+
Fix from $1,950 2024-12-19
Pbootcms CRITICAL 9.8
CVE-2024-12789

A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/…

Fix: 3.2.4+
Fix from $2,300 2024-12-19
Hostel Management System HIGH 8.2
CVE-2024-12790

A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnerability affects unknown code o…

No fix yet
Fix from $1,950 2024-12-19
Unclassified HIGH 8.6
CVE-2024-9154

A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy …

Mitigation only
Fix from $1,950 2024-12-19
Vehicle Management System MEDIUM 6.1
CVE-2024-12783

A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affects some unknown processing of …

No fix yet
Fix from $1,600 2024-12-19
Download Manager HIGH 7.3
CVE-2024-11740

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is du…

Fix: 3.3.04+
Fix from $1,950 2024-12-19
Complaint Management System HIGH 8.8
CVE-2024-55505

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

Mitigation only
Fix from $1,950 2024-12-18
Craft Cms CRITICAL 9.8
CVE-2024-56145 KEVEPSS 97%

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this…

Fix: 3.9.14 / 4.13.2+
Fix from $2,300 2024-12-18
Opencart HIGH 7.2
CVE-2024-36694

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

No fix yet
Fix from $1,950 2024-12-18
Wordpress Learning Management System HIGH 8.8
CVE-2024-56051

Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Injection.This issue affects WPL…

Fix: 1.9.9.5+
Fix from $1,950 2024-12-18
Unclassified CRITICAL 9.3
CVE-2024-12372

A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results …

Mitigation only
Fix from $2,300 2024-12-18
Fortiwlm CRITICAL 9.8
CVE-2023-34990EPSS 25%

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or co…

Fix: 8.5.5 / 8.6.6+
Fix from $2,300 2024-12-18
Unclassified CRITICAL 9.8
CVE-2024-21546

Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and in…

Patch available
Fix from $2,300 2024-12-18
Getsimple Cms CRITICAL 9.8
CVE-2024-55085

GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used…

Mitigation only
Fix from $2,300 2024-12-16
Rebuild MEDIUM 5.4
CVE-2024-12664

A vulnerability, which was classified as problematic, has been found in ruifang-tech Rebuild 3.8.5. This issue affects some unknown processing of the…

No fix yet
Fix from $1,600 2024-12-16
Rebuild MEDIUM 5.4
CVE-2024-12665

A vulnerability, which was classified as problematic, was found in ruifang-tech Rebuild 3.8.5. Affected is an unknown function of the component Task …

No fix yet
Fix from $1,600 2024-12-16
Fastnetmon HIGH 7.5
CVE-2024-56072

An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to cause a denial of service (appl…

Fix: after 1.2.7
Fix from $1,950 2024-12-15