Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Wuzhicms HIGH 7.2
CVE-2024-10505

A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/cont…

No fix yet
Fix from $1,950 2024-10-30
Unclassified CRITICAL 9.8
CVE-2024-48138

A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers t…

Mitigation only
Fix from $2,300 2024-10-29
Servicenow CRITICAL 10.0
CVE-2024-8923

ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticate…

Mitigation only
Fix from $2,300 2024-10-29
Wp Query Console CRITICAL 9.8
CVE-2024-50498EPSS 53%

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This is…

Fix: after 1.0
Fix from $2,300 2024-10-28
Scottcart CRITICAL 9.8
CVE-2024-50492

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affect…

Fix: after 1.1
Fix from $2,300 2024-10-28
Wordpress Meta Data And Taxonomies Filter CRITICAL 9.8
CVE-2024-50450

Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Inject…

Fix: 1.3.3.5+
Fix from $2,300 2024-10-28
Unclassified HIGH 7.2
CVE-2024-9162

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during …

Mitigation only
Fix from $1,950 2024-10-28
Unclassified HIGH 7.2
CVE-2024-50611

CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.…

Mitigation only
Fix from $1,950 2024-10-27
Uix Shortcodes HIGH 7.3
CVE-2024-9772

The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc…

Fix: after 1.9.9
Fix from $1,950 2024-10-26
Ofcms MEDIUM 6.5
CVE-2024-48235

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.

No fix yet
Fix from $1,600 2024-10-25
Ofcms MEDIUM 6.5
CVE-2024-48236

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-…

No fix yet
Fix from $1,600 2024-10-25
Mango HIGH 7.2
CVE-2024-37845

MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.

Fix: 5.2.0+
Fix from $1,950 2024-10-25
Kliqqi Cms HIGH 7.2
CVE-2024-48700

Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php …

Fix: after 3.5.2
Fix from $1,950 2024-10-25
Total.js HIGH 8.8
CVE-2024-48655

An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.

No fix yet
Fix from $1,950 2024-10-25
Best Courier Management System CRITICAL 9.8
CVE-2024-48581

File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php c…

No fix yet
Fix from $2,300 2024-10-25
Unclassified CRITICAL 9.8
CVE-2024-48204

SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.

Mitigation only
Fix from $2,300 2024-10-25
Best House Rental Management System CRITICAL 9.8
CVE-2024-48579

SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the us…

No fix yet
Fix from $2,300 2024-10-25
N Line MEDIUM 5.4
CVE-2024-47158

N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the ins…

Fix: after 2.0.6
Fix from $1,600 2024-10-25
Openrefine HIGH 8.8
CVE-2024-47879

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `pre…

Fix: 3.8.3+
Fix from $1,950 2024-10-24
Unclassified CRITICAL 9.8
CVE-2024-48514

php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remo…

Mitigation only
Fix from $2,300 2024-10-24
Snyk Cli HIGH 8.8
CVE-2024-48964

The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if…

Fix: 1.1294.0+
Fix from $1,950 2024-10-23
Adaptive Security Appliance Software MEDIUM 6.7
CVE-2024-20485

A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could all…

Mitigation only
Fix from $1,600 2024-10-23
Unclassified HIGH 7.8
CVE-2024-9050

A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configura…

Mitigation only
Fix from $1,950 2024-10-22
Micollab MEDIUM 6.6
CVE-2024-41712

A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command inject…

Fix: after 9.8.1.5
Fix from $1,600 2024-10-21
Micollab HIGH 8.8
CVE-2024-41714

A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) …

Fix: after 9.8.1.5
Fix from $1,950 2024-10-21
Micollab CRITICAL 9.8
CVE-2024-35314

A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could …

Fix: after 9.7.1.110
Fix from $2,300 2024-10-21
Micollab MEDIUM 5.6
CVE-2024-35315

A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could …

Fix: after 9.7.1.110
Fix from $1,600 2024-10-21
Ragflow HIGH 8.8
CVE-2024-10131

The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses u…

No fix yet
Fix from $1,950 2024-10-19
Time Clock HIGH 8.3
CVE-2024-9593EPSS 12%

The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Ti…

Fix: after 1.2.2
Fix from $1,950 2024-10-18
Grafana HIGH 8.8
CVE-2024-9264EPSS 95%

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie…

Mitigation only
Fix from $1,950 2024-10-18