Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Pulse HIGH 8.8
CVE-2024-55661EPSS 29%

Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in L…

Fix: 1.3.1+
Fix from $1,950 2024-12-13
Unclassified CRITICAL 10.0
CVE-2024-21576

ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and Fin…

Mitigation only
Fix from $2,300 2024-12-13
Unclassified CRITICAL 10.0
CVE-2024-21577

ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary u…

Mitigation only
Fix from $2,300 2024-12-13
Unclassified MEDIUM 6.3
CVE-2024-11012

The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via njt_nofi_text AJAX action in…

Mitigation only
Fix from $1,600 2024-12-13
Unclassified MEDIUM 6.5
CVE-2024-12417

The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This i…

Mitigation only
Fix from $1,600 2024-12-13
Unclassified MEDIUM 6.5
CVE-2024-12420

The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Mitigation only
Fix from $1,600 2024-12-13
Unclassified MEDIUM 6.5
CVE-2024-12421

The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…

Mitigation only
Fix from $1,600 2024-12-13
Unclassified MEDIUM 5.3
CVE-2024-55918

An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead …

Mitigation only
Fix from $1,600 2024-12-13
Xwiki HIGH 8.8
CVE-2024-55877

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account …

Fix: 15.10.11 / 16.4.1+
Fix from $1,950 2024-12-12
Xwiki HIGH 8.8
CVE-2024-55662

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extensio…

Fix: 15.10.9 / 16.3.0+
Fix from $1,950 2024-12-12
Unclassified CRITICAL 10.0
CVE-2024-21574

The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes wh…

Patch available
Fix from $2,300 2024-12-12
Unclassified MEDIUM 6.5
CVE-2024-12333

The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the softw…

Mitigation only
Fix from $1,600 2024-12-12
Unclassified HIGH 7.3
CVE-2024-10910

The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX act…

Mitigation only
Fix from $1,950 2024-12-12
macOS HIGH 7.8
CVE-2024-54529

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be…

Fix: 13.7.2 / 14.7.2+
Fix from $1,950 2024-12-12
Siyuan CRITICAL 9.8
CVE-2024-55660

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side…

Patch available
Fix from $2,300 2024-12-12
Advocate Office Management System MEDIUM 5.4
CVE-2024-12536

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by…

Mitigation only
Fix from $1,600 2024-12-12
Unclassified CRITICAL 9.9
CVE-2024-42448EPSS 20%

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code …

Mitigation only
Fix from $2,300 2024-12-12
Unclassified CRITICAL 9.3
CVE-2024-54152

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a mal…

Patch available
Fix from $2,300 2024-12-10
Unclassified HIGH 7.3
CVE-2024-10959

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution …

Mitigation only
Fix from $1,950 2024-12-10
Doctor Appointment CRITICAL 9.8
CVE-2022-38946

Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2024-12-09
Admin Dashboard MEDIUM 5.4
CVE-2024-12359

A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the f…

No fix yet
Fix from $1,600 2024-12-09
Unclassified HIGH 7.5
CVE-2024-55580

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute r…

Mitigation only
Fix from $1,950 2024-12-09
Jpress MEDIUM 6.1
CVE-2024-12348

A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.…

No fix yet
Fix from $1,600 2024-12-09
Jfinalcms HIGH 8.8
CVE-2024-12350

A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\c…

No fix yet
Fix from $1,950 2024-12-09
Unclassified CRITICAL 9.0
CVE-2024-51815

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member allows Code Injection.This issue affect…

Mitigation only
Fix from $2,300 2024-12-06
Unclassified HIGH 8.1
CVE-2024-21571

Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbit…

Mitigation only
Fix from $1,950 2024-12-06
Unclassified HIGH 8.8
CVE-2024-10771

Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network acce…

Mitigation only
Fix from $1,950 2024-12-06
Unclassified MEDIUM 6.3
CVE-2024-10909

The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX action in all versions up to, …

Mitigation only
Fix from $1,600 2024-12-06
Unclassified MEDIUM 6.3
CVE-2024-10681

The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to arbitrary …

Mitigation only
Fix from $1,600 2024-12-06
Robot Operating System HIGH 7.8
CVE-2024-30961

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local…

Patch available
Fix from $1,950 2024-12-05