Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MariaDB CRITICAL 9.8
CVE-2023-26785

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create funct…

No fix yet
Fix from $2,300 2024-10-17
MariaDB MEDIUM 5.6
CVE-2023-39593

Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges.…

No fix yet
Fix from $1,600 2024-10-17
MariaDB MEDIUM 5.7
CVE-2024-27766

An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the Mar…

No fix yet
Fix from $1,600 2024-10-17
Flair HIGH 7.5
CVE-2024-10073

A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\mod…

No fix yet
Fix from $1,950 2024-10-17
Openmanage Enterprise HIGH 8.8
CVE-2024-45766

Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A lo…

Fix: 4.2.0+
Fix from $1,950 2024-10-17
Teachers Record Management System MEDIUM 6.1
CVE-2024-48744

A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, wh…

No fix yet
Fix from $1,600 2024-10-16
Unclassified CRITICAL 10.0
CVE-2024-49254

Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code Injection.This issue affects…

Mitigation only
Fix from $2,300 2024-10-16
Unlimited Elements For Elementor HIGH 7.2
CVE-2024-49271

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-el…

Fix: 1.5.122+
Fix from $1,950 2024-10-16
Wp Popup Builder CRITICAL 9.8
CVE-2024-9061EPSS 52%

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_a…

Fix: 1.3.6+
Fix from $2,300 2024-10-16
Zoneminder MEDIUM 6.6
CVE-2023-31493

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a …

Fix: after 1.36.33
Fix from $1,600 2024-10-15
User Registration \& Login And User Management System HIGH 7.6
CVE-2024-48279

A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerabi…

No fix yet
Fix from $1,950 2024-10-15
Mbnet.mini Firmware HIGH 7.8
CVE-2024-45271

An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

Fix: 2.3.1+
Fix from $1,950 2024-10-15
Unclassified HIGH 7.3
CVE-2024-9837

The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in…

Mitigation only
Fix from $1,950 2024-10-15
Elabftw MEDIUM 6.1
CVE-2024-47826

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrar…

Fix: 5.1.5+
Fix from $1,600 2024-10-14
Dcs 960l Firmware CRITICAL 9.8
CVE-2024-48168

A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitra…

Mitigation only
Fix from $2,300 2024-10-14
Unclassified MEDIUM 6.6
CVE-2024-41997

An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker…

Mitigation only
Fix from $1,600 2024-10-14
Unclassified MEDIUM 5.3
CVE-2024-8760

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This …

Mitigation only
Fix from $1,600 2024-10-12
Unclassified HIGH 8.8
CVE-2024-44414

A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_in…

Mitigation only
Fix from $1,950 2024-10-11
Unclassified CRITICAL 9.8
CVE-2024-21534EPSS 9%

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute a…

Mitigation only
Fix from $2,300 2024-10-11
Shortcodes Anywhere HIGH 7.3
CVE-2024-9581

The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due …

Fix: after 1.0.1
Fix from $1,950 2024-10-10
Unclassified CRITICAL 9.8
CVE-2024-45874

A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL fil…

No fix yet
Fix from $2,300 2024-10-07
Unclassified CRITICAL 9.8
CVE-2024-45873

A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL …

No fix yet
Fix from $2,300 2024-10-07
Cacti HIGH 7.2
CVE-2024-43363EPSS 36%

Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code a…

Fix: 1.2.28+
Fix from $1,950 2024-10-07
Ruoyi CRITICAL 9.8
CVE-2024-46076

RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of maliciou…

Fix: after 4.7.9
Fix from $2,300 2024-10-07
Unclassified MEDIUM 6.6
CVE-2024-45933

OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in …

Mitigation only
Fix from $1,600 2024-10-07
Email Subscribers \& Newsletters MEDIUM 6.3
CVE-2024-8254

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to…

Fix: 5.7.35+
Fix from $1,600 2024-10-02
Unclassified CRITICAL 9.8
CVE-2024-45186

FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.

Mitigation only
Fix from $2,300 2024-10-02
Scriptcase HIGH 8.0
CVE-2024-46080

Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.

Fix: after 9.10.023
Fix from $1,950 2024-10-01
Unclassified MEDIUM 5.7
CVE-2024-44744

An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directo…

Mitigation only
Fix from $1,600 2024-10-01
Unclassified MEDIUM 6.3
CVE-2024-45200

In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer o…

Mitigation only
Fix from $1,600 2024-09-30