Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Inpost Gallery MEDIUM 6.3
CVE-2024-11002

The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action …

Fix: 2.1.4.3+
Fix from $1,600 2024-11-26
Hospital Management System MEDIUM 5.4
CVE-2024-11678

A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code o…

No fix yet
Fix from $1,600 2024-11-26
Hospital Management System MEDIUM 5.4
CVE-2024-11677

A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the fil…

No fix yet
Fix from $1,600 2024-11-26
Data Virtualization Manager For Z\/os HIGH 8.8
CVE-2024-52899

IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on th…

Mitigation only
Fix from $1,950 2024-11-26
Hospital Management System MEDIUM 5.4
CVE-2024-11676

A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functiona…

No fix yet
Fix from $1,600 2024-11-26
Hospital Management System MEDIUM 5.4
CVE-2024-11675

A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknow…

No fix yet
Fix from $1,600 2024-11-26
Unclassified HIGH 8.0
CVE-2024-53554

A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2024-11-25
Joplin HIGH 8.8
CVE-2024-53268

Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions att…

Fix: 3.0.3+
Fix from $1,950 2024-11-25
Farmacia MEDIUM 5.4
CVE-2024-11660

A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown part of the file usuario.php.…

No fix yet
Fix from $1,600 2024-11-25
Unclassified HIGH 7.3
CVE-2024-11034

The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is v…

Mitigation only
Fix from $1,950 2024-11-23
Imanager CRITICAL 9.8
CVE-2021-38117

Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Fix: 3.2.5+
Fix from $2,300 2024-11-22
Unclassified CRITICAL 9.8
CVE-2024-51367

An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2024-11-21
Idccms MEDIUM 6.1
CVE-2024-11587

A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOptionJs of the file /inc/classProv…

No fix yet
Fix from $1,600 2024-11-21
Gr 1800ax Firmware CRITICAL 9.8
CVE-2024-52765EPSS 11%

H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.

No fix yet
Fix from $2,300 2024-11-20
115cms MEDIUM 6.1
CVE-2024-11492

A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the file /index.php/admin/web/appu…

Fix: after 2024-08-07
Fix from $1,600 2024-11-20
115cms MEDIUM 6.1
CVE-2024-11493

A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of the file /index.php/setpage/…

Fix: after 2024-08-07
Fix from $1,600 2024-11-20
115cms MEDIUM 5.4
CVE-2024-11491

A vulnerability was found in 115cms up to 20240807. It has been rated as problematic. Affected by this issue is some unknown functionality of the fil…

Fix: after 2024-08-07
Fix from $1,600 2024-11-20
115cms MEDIUM 6.1
CVE-2024-11490

A vulnerability was found in 115cms up to 20240807. It has been declared as problematic. Affected by this vulnerability is an unknown functionality o…

Fix: after 2024-08-07
Fix from $1,600 2024-11-20
115cms MEDIUM 6.1
CVE-2024-11488

A vulnerability was found in 115cms up to 20240807 and classified as problematic. This issue affects some unknown processing of the file /app/admin/v…

Fix: after 2024-08-07
Fix from $1,600 2024-11-20
115cms MEDIUM 6.1
CVE-2024-11489

A vulnerability was found in 115cms up to 20240807. It has been classified as problematic. Affected is an unknown function of the file /index.php/adm…

Fix: after 2024-08-07
Fix from $1,600 2024-11-20
Infinity CRITICAL 9.8
CVE-2024-10094

Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

Fix: 8.1.9 / 8.2.8+
Fix from $2,300 2024-11-20
Androidx.car.app HIGH 7.5
CVE-2024-10382

There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction…

Fix: after 1.4.0
Fix from $1,950 2024-11-20
Woocommerce Product Table HIGH 7.3
CVE-2024-10899

The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.…

Fix: 3.8.7+
Fix from $1,950 2024-11-20
Unclassified CRITICAL 9.8
CVE-2024-48694

File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary co…

Mitigation only
Fix from $2,300 2024-11-19
E Cology CRITICAL 9.8
CVE-2024-48070

An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and cont…

Mitigation only
Fix from $2,300 2024-11-19
Wpb Popup For Contact Form 7 HIGH 7.3
CVE-2024-11038

The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary s…

Fix: 1.7.6+
Fix from $1,950 2024-11-19
Gamipress CRITICAL 9.8
CVE-2024-11036

The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbi…

Fix: 7.1.6+
Fix from $2,300 2024-11-19
Unclassified HIGH 7.8
CVE-2024-50804

Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Devi…

Mitigation only
Fix from $1,950 2024-11-18
Jpress CRITICAL 9.8
CVE-2024-50919

Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to a…

Fix: after 5.1.1
Fix from $2,300 2024-11-18
Nus M9 Erp HIGH 7.5
CVE-2024-44757

An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to downlo…

Mitigation only
Fix from $1,950 2024-11-18