Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Phoniebox CRITICAL 9.8
CVE-2024-41367

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php

No fix yet
Fix from $2,300 2024-08-29
Phoniebox CRITICAL 9.8
CVE-2024-41368

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php

No fix yet
Fix from $2,300 2024-08-29
Phoniebox CRITICAL 9.8
CVE-2024-41369

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php

No fix yet
Fix from $2,300 2024-08-29
Phoniebox CRITICAL 9.8
CVE-2024-41361

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php

No fix yet
Fix from $2,300 2024-08-29
Nitropack CRITICAL 9.8
CVE-2024-43922

Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPac…

Fix: 1.16.8+
Fix from $2,300 2024-08-29
Getapps CRITICAL 9.8
CVE-2023-26322

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed…

Fix: 32.0.0.1+
Fix from $2,300 2024-08-28
Getapps CRITICAL 9.8
CVE-2023-26324

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed…

Fix: 30.6.0.2+
Fix from $2,300 2024-08-28
Security Manager CRITICAL 9.8
CVE-2024-7720

HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source li…

No fix yet
Fix from $2,300 2024-08-27
Unclassified HIGH 8.8
CVE-2024-7656

The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.5 via deserialization…

Mitigation only
Fix from $1,950 2024-08-24
Unclassified HIGH 8.0
CVE-2024-42845

An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arb…

Mitigation only
Fix from $1,950 2024-08-23
Dgn1000ww Firmware HIGH 8.8
CVE-2024-42756EPSS 14%

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

Mitigation only
Fix from $1,950 2024-08-23
Manageengine Opmanager HIGH 8.8
CVE-2024-5466EPSS 7%

Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execut…

Fix: after 12.7
Fix from $1,950 2024-08-23
File Manager Pro HIGH 8.8
CVE-2024-7559

The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk…

Fix: after 8.3.7
Fix from $1,950 2024-08-23
Llamaindex HIGH 8.8
CVE-2024-45201

An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}.

Fix: 0.10.38+
Fix from $1,950 2024-08-22
Seacms HIGH 8.8
CVE-2024-42599

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edi…

No fix yet
Fix from $1,950 2024-08-22
Wpml HIGH 8.8
CVE-2024-6386EPSS 26%

The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injec…

Fix: 4.6.13+
Fix from $1,950 2024-08-21
Squirrelly CRITICAL 9.8
CVE-2024-40453

squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.

Patch available
Fix from $2,300 2024-08-21
Seacms MEDIUM 6.7
CVE-2024-42598

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions o…

No fix yet
Fix from $1,600 2024-08-20
Megabot CRITICAL 9.8
CVE-2024-43404

MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote c…

Fix: 1.5.0+
Fix from $2,300 2024-08-20
Bamboo HIGH 8.0
CVE-2024-21689

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 …

Fix: 9.2.17 / 9.6.5+
Fix from $1,950 2024-08-20
Dolphinscheduler CRITICAL 9.8
CVE-2024-43202

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgr…

Fix: 3.2.2+
Fix from $2,300 2024-08-20
Innocms HIGH 7.2
CVE-2024-7899

A vulnerability, which was classified as critical, has been found in InnoCMS 0.3.1. This issue affects some unknown processing of the file /panel/pag…

No fix yet
Fix from $1,950 2024-08-17
Ac9 Firmware CRITICAL 9.8
CVE-2024-42634

A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS comma…

No fix yet
Fix from $2,300 2024-08-16
X5000r Firmware HIGH 8.8
CVE-2024-42739

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authe…

No fix yet
Fix from $1,950 2024-08-13
D8801 Firmware CRITICAL 9.8
CVE-2024-41623

An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload

No fix yet
Fix from $2,300 2024-08-13
Kibana HIGH 7.2
CVE-2024-37287

A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write ac…

Fix: 7.17.23 / 8.14.2+
Fix from $1,950 2024-08-13
Woocommerce Product Table HIGH 7.3
CVE-2024-43128

Improper Control of Generation of Code ('Code Injection') vulnerability in WC Product Table WooCommerce Product Table Lite allows Code Injection.This…

Fix: 3.8.6+
Fix from $1,950 2024-08-13
Unclassified CRITICAL 9.8
CVE-2024-7094EPSS 38%

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution …

Mitigation only
Fix from $2,300 2024-08-13
X5000r Firmware HIGH 8.8
CVE-2024-42745

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated…

No fix yet
Fix from $1,950 2024-08-12
Prestashop HIGH 8.1
CVE-2024-41651

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disp…

Fix: after 8.1.7
Fix from $1,950 2024-08-12