Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Hibos MEDIUM 5.4
CVE-2024-11050

A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown …

Fix: after 3.0.3.151204
Fix from $1,600 2024-11-10
Unclassified HIGH 7.3
CVE-2024-10640

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…

Mitigation only
Fix from $1,950 2024-11-09
Membership \& Content Restriction Paid Member Subscriptions HIGH 7.3
CVE-2024-10261

The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitr…

Fix: 2.13.1+
Fix from $1,950 2024-11-09
Seacms HIGH 8.8
CVE-2024-50808

SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to u…

No fix yet
Fix from $1,950 2024-11-08
Unclassified HIGH 8.8
CVE-2024-46960

The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitra…

Mitigation only
Fix from $1,950 2024-11-07
Unclassified HIGH 8.1
CVE-2024-46961

The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arb…

Mitigation only
Fix from $1,950 2024-11-07
Moodle HIGH 8.1
CVE-2024-43425EPSS 83%

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requi…

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Unclassified CRITICAL 9.3
CVE-2024-51757

happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute co…

Patch available
Fix from $2,300 2024-11-06
Tickera HIGH 7.3
CVE-2024-10263

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5…

Fix: 3.5.4.6+
Fix from $1,950 2024-11-05
Agentscope CRITICAL 9.8
CVE-2024-48050

In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line…

Fix: after 0.0.4
Fix from $2,300 2024-11-04
Langflow CRITICAL 9.8
CVE-2024-48061

langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local m…

Fix: after 1.0.18
Fix from $2,300 2024-11-04
Agile Board HIGH 8.8
CVE-2024-51329

A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted pass…

No fix yet
Fix from $1,950 2024-11-04
Coslat CRITICAL 9.8
CVE-2024-10035

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Impro…

Fix: after 3.1069
Fix from $2,300 2024-11-04
Qualitor CRITICAL 9.8
CVE-2024-48359

Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

No fix yet
Fix from $2,300 2024-10-31
Unclassified HIGH 8.8
CVE-2024-21537

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dyn…

Patch available
Fix from $1,950 2024-10-31
Unclassified CRITICAL 9.8
CVE-2024-51427

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the m…

Mitigation only
Fix from $2,300 2024-10-30
Eladmin HIGH 7.2
CVE-2024-51243

The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this manageme…

Fix: after 2.7
Fix from $1,950 2024-10-30
Unclassified CRITICAL 9.8
CVE-2024-51424

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the O…

Mitigation only
Fix from $2,300 2024-10-30
Unclassified HIGH 8.1
CVE-2024-42041

The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51298

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel…

Mitigation only
Fix from $2,300 2024-10-30
Enable Shortcodes Inside Widgets\,comments And Experts HIGH 7.3
CVE-2024-9846

The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up …

Fix: after 1.0.0
Fix from $1,950 2024-10-30
Wuzhicms HIGH 7.2
CVE-2024-10505

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/cont…

No fix yet
Fix from $1,950 2024-10-30
Unclassified CRITICAL 9.8
CVE-2024-48138

A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers t…

Mitigation only
Fix from $2,300 2024-10-29
Servicenow CRITICAL 10.0
CVE-2024-8923

ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticate…

Mitigation only
Fix from $2,300 2024-10-29
Wp Query Console CRITICAL 9.8
CVE-2024-50498EPSS 53%

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This is…

Fix: after 1.0
Fix from $2,300 2024-10-28
Scottcart CRITICAL 9.8
CVE-2024-50492

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affect…

Fix: after 1.1
Fix from $2,300 2024-10-28
Wordpress Meta Data And Taxonomies Filter CRITICAL 9.8
CVE-2024-50450

Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Inject…

Fix: 1.3.3.5+
Fix from $2,300 2024-10-28
Unclassified HIGH 7.2
CVE-2024-9162

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during …

Mitigation only
Fix from $1,950 2024-10-28
Unclassified HIGH 7.2
CVE-2024-50611

CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.…

Mitigation only
Fix from $1,950 2024-10-27
Uix Shortcodes HIGH 7.3
CVE-2024-9772

The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc…

Fix: after 1.9.9
Fix from $1,950 2024-10-26