Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 8.8
CVE-2024-5651

A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbit…

Mitigation only
Fix from $1,950 2024-08-12
Live Membership System HIGH 7.6
CVE-2024-40487

A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attacke…

No fix yet
Fix from $1,950 2024-08-12
Zabbix HIGH 7.2
CVE-2024-22116

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default …

Fix: after 6.4.15
Fix from $1,950 2024-08-12
Unclassified MEDIUM 6.0
CVE-2023-50810

In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allo…

Mitigation only
Fix from $1,600 2024-08-12
Unclassified HIGH 7.5
CVE-2023-31315

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock i…

Mitigation only
Fix from $1,950 2024-08-12
Authorization Gateway HIGH 7.2
CVE-2024-37382

An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code …

Fix: 4.1.4.9+
Fix from $1,950 2024-08-08
Vynamic Security Suite MEDIUM 6.8
CVE-2023-33206

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during …

Fix: 3.3.0sr16 / 4.0.0sr06+
Fix from $1,600 2024-08-08
Shopware CRITICAL 9.8
CVE-2024-42355

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Pr…

Fix: 6.5.8.13 / 6.6.5.1+
Fix from $2,300 2024-08-08
Shopware HIGH 7.2
CVE-2024-42356

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and a…

Fix: 6.5.8.13 / 6.6.5.1+
Fix from $1,950 2024-08-08
GitLab MEDIUM 6.5
CVE-2024-3958

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found…

Fix: 17.0.6 / 17.1.4+
Fix from $1,600 2024-08-08
Journyx HIGH 8.8
CVE-2024-6891

Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

No fix yet
Fix from $1,950 2024-08-08
Arubaos CRITICAL 9.8
CVE-2024-42393

There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploit…

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $2,300 2024-08-06
Firefox HIGH 8.8
CVE-2024-7520

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129…

Fix: 128.1.0 / 129.0+
Fix from $1,950 2024-08-06
Nuxt HIGH 8.8
CVE-2024-34344

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `p…

Fix: 3.12.4+
Fix from $1,950 2024-08-05
Unclassified HIGH 7.1
CVE-2024-22169

WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing th…

Mitigation only
Fix from $1,950 2024-08-02
Monkeytype CRITICAL 9.6
CVE-2024-41127

Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-f…

Fix: 24.30.0+
Fix from $2,300 2024-08-02
Inlong CRITICAL 9.8
CVE-2024-36268

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12…

Fix: 1.13.0+
Fix from $2,300 2024-08-02
Unclassified CRITICAL 9.4
CVE-2024-7093

Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither pr…

Mitigation only
Fix from $2,300 2024-08-01
Unclassified CRITICAL 9.6
CVE-2024-41961

Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live…

Patch available
Fix from $2,300 2024-08-01
Unclassified MEDIUM 5.5
CVE-2024-6923

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an …

Patch available
Fix from $1,600 2024-08-01
Xwiki HIGH 8.8
CVE-2024-37901

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can per…

Fix: 14.10.21 / 15.5.5+
Fix from $1,950 2024-07-31
Wondercms MEDIUM 5.4
CVE-2024-41304

An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafte…

No fix yet
Fix from $1,600 2024-07-30
School Log Management System MEDIUM 6.1
CVE-2024-7218

A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?actio…

No fix yet
Fix from $1,600 2024-07-30
Unclassified HIGH 8.8
CVE-2024-6726

Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).

No fix yet
Fix from $1,950 2024-07-29
Fh1201 Firmware CRITICAL 9.8
CVE-2024-41468

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand

Mitigation only
Fix from $2,300 2024-07-25
Spring Cloud Data Flow HIGH 8.8
CVE-2024-37084EPSS 35%

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to wr…

Fix: 2.11.4+
Fix from $1,950 2024-07-25
E2500 Firmware HIGH 8.0
CVE-2024-40495

A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_par…

Mitigation only
Fix from $1,950 2024-07-24
Unclassified HIGH 8.8
CVE-2024-41667

OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.jav…

Patch available
Fix from $1,950 2024-07-24
Unclassified CRITICAL 9.8
CVE-2024-38944

An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?fo…

Mitigation only
Fix from $2,300 2024-07-22
Unclassified CRITICAL 9.8
CVE-2024-21552

All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM outp…

Mitigation only
Fix from $2,300 2024-07-22