Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Incontrol Web HIGH 8.8
CVE-2024-9324

A vulnerability was found in Intelbras InControl up to 2.21.57. It has been rated as critical. Affected by this issue is some unknown functionality o…

Fix: 2.21.58+
Fix from $1,950 2024-09-29
Localai HIGH 8.8
CVE-2024-6983

mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only f…

Patch available
Fix from $1,950 2024-09-27
Promptr HIGH 8.8
CVE-2024-46489

A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.

No fix yet
Fix from $1,950 2024-09-25
Special Text Boxes HIGH 7.3
CVE-2024-8481

The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.4. This is d…

Fix: after 6.2.2
Fix from $1,950 2024-09-25
Wordpress Meta Data And Taxonomies Filter HIGH 7.3
CVE-2024-8623

The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi…

Fix: 1.3.3.4+
Fix from $1,950 2024-09-24
Unclassified HIGH 7.6
CVE-2024-46639

A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inject…

Mitigation only
Fix from $1,950 2024-09-23
Unclassified HIGH 8.8
CVE-2024-37779

WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script function…

Mitigation only
Fix from $1,950 2024-09-23
Purity\/\/fa HIGH 7.2
CVE-2024-0004

A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the ar…

Fix: after 6.4.10
Fix from $1,950 2024-09-23
Unclassified HIGH 7.2
CVE-2024-40442

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a d…

Mitigation only
Fix from $1,950 2024-09-23
Nebulagraph Database CRITICAL 9.8
CVE-2024-47219

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

Fix: after 3.8.0
Fix from $2,300 2024-09-22
Semcms CRITICAL 9.8
CVE-2024-46103

SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.

No fix yet
Fix from $2,300 2024-09-20
Seacms CRITICAL 9.8
CVE-2024-46640

SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function…

No fix yet
Fix from $2,300 2024-09-20
123solar HIGH 8.8
CVE-2024-9006

A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Patch available
Fix from $1,950 2024-09-19
Unclassified CRITICAL 9.8
CVE-2024-35515

Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.

Mitigation only
Fix from $2,300 2024-09-18
Unclassified CRITICAL 9.9
CVE-2024-45798

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulne…

Mitigation only
Fix from $2,300 2024-09-17
Spx Graphics Controller CRITICAL 9.8
CVE-2024-44623

An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.

Fix: after 1.3.0
Fix from $2,300 2024-09-16
Winsure CRITICAL 9.8
CVE-2024-7104

Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection. This issue affects ww.Wi…

Fix: 4.6.2+
Fix from $2,300 2024-09-16
Playsms CRITICAL 9.8
CVE-2024-8880

A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.…

No fix yet
Fix from $2,300 2024-09-16
Composio HIGH 8.8
CVE-2024-8864

A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculat…

Fix: after 0.5.6
Fix from $1,950 2024-09-15
Simple Spoiler HIGH 7.3
CVE-2024-8479

The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding t…

Fix: 1.4+
Fix from $1,950 2024-09-14
Fox Currency Switcher Professional For Woocommerce HIGH 7.3
CVE-2024-8271

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…

Fix: 1.4.2.2+
Fix from $1,950 2024-09-14
Best Free Law Office Management CRITICAL 9.8
CVE-2024-44430

SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive inform…

No fix yet
Fix from $2,300 2024-09-13
Desktop CRITICAL 9.8
CVE-2024-8695

A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop be…

Fix: 4.34.2+
Fix from $2,300 2024-09-12
Desktop CRITICAL 9.8
CVE-2024-8696

A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker De…

Fix: 4.34.2+
Fix from $2,300 2024-09-12
Mindsdb HIGH 8.8
CVE-2024-45851

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat…

Fix: 24.7.4.1+
Fix from $1,950 2024-09-12
Mindsdb HIGH 8.8
CVE-2024-45847

An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is in…

Fix: 24.7.4.1+
Fix from $1,950 2024-09-12
Mindsdb HIGH 8.8
CVE-2024-45848

An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is insta…

Fix: 24.7.4.1+
Fix from $1,950 2024-09-12
Mindsdb HIGH 8.8
CVE-2024-45849

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat…

Fix: 24.7.4.1+
Fix from $1,950 2024-09-12
Mindsdb HIGH 8.8
CVE-2024-45850

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat…

Fix: 24.7.4.1+
Fix from $1,950 2024-09-12
Mindsdb HIGH 8.8
CVE-2024-45846

An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is insta…

Fix: 24.7.4.1+
Fix from $1,950 2024-09-12