Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Popup CRITICAL 9.1
CVE-2024-52434

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup …

Fix: after 1.10.29
Fix from $2,300 2024-11-18
Event Tickets With Ticket Scanner HIGH 8.8
CVE-2024-52427

Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side I…

Fix: 2.3.12+
Fix from $1,950 2024-11-18
Ofbiz CRITICAL 9.8
CVE-2024-47208

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.17+
Fix from $2,300 2024-11-18
Ofbiz HIGH 8.8
CVE-2024-48962

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a…

Fix: 18.12.17+
Fix from $1,950 2024-11-18
Netbackup HIGH 7.8
CVE-2024-52945

An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user …

Fix: 10.5+
Fix from $1,950 2024-11-18
Gnome Maps CRITICAL 9.8
CVE-2023-43091

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is …

Fix: 43.7 / 44.4+
Fix from $2,300 2024-11-17
Unclassified HIGH 7.3
CVE-2024-9839

The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to…

Mitigation only
Fix from $1,950 2024-11-16
Unclassified MEDIUM 6.3
CVE-2024-10262

The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is d…

Mitigation only
Fix from $1,600 2024-11-16
Nus M9 Erp CRITICAL 9.8
CVE-2024-44758

An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute a…

Mitigation only
Fix from $2,300 2024-11-15
Farmacia MEDIUM 6.1
CVE-2024-11259

A vulnerability, which was classified as problematic, has been found in code-projects Farmacia 1.0. This issue affects some unknown processing of the…

No fix yet
Fix from $1,600 2024-11-15
Ultimaker Cura MEDIUM 5.1
CVE-2024-51330

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechan…

Fix: after 5.8.1
Fix from $1,600 2024-11-15
Online Eyewear Shop MEDIUM 5.4
CVE-2024-11247

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown …

No fix yet
Fix from $1,600 2024-11-15
Farmacia MEDIUM 5.4
CVE-2024-11246

A vulnerability, which was classified as problematic, was found in code-projects Farmacia 1.0. Affected is an unknown function of the file /adicionar…

No fix yet
Fix from $1,600 2024-11-15
Online Shop Store MEDIUM 6.1
CVE-2024-11243

A vulnerability classified as problematic has been found in code-projects Online Shop Store 1.0. This affects an unknown part of the file /signup.php…

No fix yet
Fix from $1,600 2024-11-15
Ibwebadmin MEDIUM 6.1
CVE-2024-11240

A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /…

Fix: after 1.0.2
Fix from $1,600 2024-11-15
Podlove Podcast Publisher HIGH 7.2
CVE-2024-52393

Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects …

Fix: after 4.1.15
Fix from $1,950 2024-11-14
Joplin CRITICAL 9.6
CVE-2024-49362

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a …

Fix: 3.1+
Fix from $2,300 2024-11-14
Unclassified HIGH 7.1
CVE-2024-5082

A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up…

Mitigation only
Fix from $1,950 2024-11-14
Android HIGH 7.8
CVE-2024-40671

In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This …

Mitigation only
Fix from $1,950 2024-11-13
Dom Iterator CRITICAL 9.8
CVE-2024-21541

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete …

Fix: after 1.0.0
Fix from $2,300 2024-11-13
Torchgeo HIGH 8.1
CVE-2024-49048

TorchGeo Remote Code Execution Vulnerability

Fix: 0.6.1+
Fix from $1,950 2024-11-12
Unclassified CRITICAL 9.8
CVE-2024-50636

PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. At…

Mitigation only
Fix from $2,300 2024-11-11
Unclassified CRITICAL 9.1
CVE-2024-46962

The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScrip…

Mitigation only
Fix from $2,300 2024-11-11
Unclassified HIGH 8.1
CVE-2024-46963

The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to ex…

Mitigation only
Fix from $1,950 2024-11-11
Unclassified HIGH 8.1
CVE-2024-46964

The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code…

Mitigation only
Fix from $1,950 2024-11-11
Unclassified HIGH 8.1
CVE-2024-46966

The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary Java…

Mitigation only
Fix from $1,950 2024-11-11
Job Recruitment MEDIUM 5.4
CVE-2024-11078

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown funct…

No fix yet
Fix from $1,600 2024-11-11
Unclassified MEDIUM 5.4
CVE-2024-46965

The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitra…

Mitigation only
Fix from $1,600 2024-11-11
Publiccms MEDIUM 5.4
CVE-2024-11070

A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of t…

No fix yet
Fix from $1,600 2024-11-11
Wp Photo Album Plus HIGH 7.3
CVE-2024-10958

The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all…

Fix: 8.9.01.001+
Fix from $1,950 2024-11-10