Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Cf Xr11 Firmware CRITICAL 9.8
CVE-2024-44466EPSS 11%

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and…

No fix yet
Fix from $2,300 2024-09-11
Azure Cyclecloud HIGH 8.8
CVE-2024-43469

Azure CycleCloud Remote Code Execution Vulnerability

Fix: 8.6.4+
Fix from $1,950 2024-09-10
Logi Options\+ HIGH 7.8
CVE-2024-8258

Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to…

Fix: 1.70.551909+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43392

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43393

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43389

A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY e…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43390

A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43391

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-43388

A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Echo Curve Viewer CRITICAL 9.8
CVE-2024-6596

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.

Fix: 1.40.1 / 6.0.0+
Fix from $2,300 2024-09-10
Frontend Dashboard HIGH 8.8
CVE-2024-8268

The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions …

Fix: 2.2.5+
Fix from $1,950 2024-09-10
Affiliate Super Assistent HIGH 7.3
CVE-2024-8478

The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. Th…

Fix: 1.5.4+
Fix from $1,950 2024-09-10
Di 8300 Firmware CRITICAL 9.8
CVE-2024-44410

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

No fix yet
Fix from $2,300 2024-09-09
Di 8300 Firmware CRITICAL 9.8
CVE-2024-44411

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

No fix yet
Fix from $2,300 2024-09-09
Autocms HIGH 7.2
CVE-2024-44724

AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability al…

No fix yet
Fix from $1,950 2024-09-09
Unclassified HIGH 8.5
CVE-2024-38651

A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSP…

Mitigation only
Fix from $1,950 2024-09-07
Unclassified CRITICAL 9.9
CVE-2024-39714

A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC s…

Mitigation only
Fix from $2,300 2024-09-07
Unclassified HIGH 8.5
CVE-2024-39715

A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server u…

Mitigation only
Fix from $1,950 2024-09-07
Unclassified MEDIUM 5.3
CVE-2023-39333

Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and funct…

Mitigation only
Fix from $1,600 2024-09-07
Lmxcms HIGH 7.2
CVE-2024-8523

A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=…

Fix: after 1.4
Fix from $1,950 2024-09-07
File Manager HIGH 8.1
CVE-2024-7627

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due…

Fix: 6.5.6+
Fix from $1,950 2024-09-05
Fides HIGH 7.2
CVE-2024-45053

Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja…

Fix: 2.44.0+
Fix from $1,950 2024-09-04
Ofbiz CRITICAL 9.8
CVE-2024-45507EPSS 93%

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac…

Fix: 18.12.16+
Fix from $2,300 2024-09-04
Template CRITICAL 9.8
CVE-2024-45390

@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker…

Fix: 1.2.0+
Fix from $2,300 2024-09-03
Limesurvey HIGH 8.8
CVE-2024-42902

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload i…

Fix: after 6.6.2
Fix from $1,950 2024-09-03
Openedge CRITICAL 9.6
CVE-2024-7345

Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents o…

Fix: after 12.2.13
Fix from $2,300 2024-09-03
Ultimaker Cura HIGH 7.8
CVE-2024-8374

UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The…

Patch available
Fix from $1,950 2024-09-03
Unclassified CRITICAL 9.8
CVE-2024-45623

D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary t…

Mitigation only
Fix from $2,300 2024-09-02
Phoniebox CRITICAL 9.8
CVE-2024-41364

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php

No fix yet
Fix from $2,300 2024-08-29
Phoniebox CRITICAL 9.8
CVE-2024-41366

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php

No fix yet
Fix from $2,300 2024-08-29