Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified MEDIUM 6.3
CVE-2024-6950

A vulnerability, which was classified as critical, has been found in Prain up to 1.3.0. Affected by this issue is some unknown functionality of the f…

Mitigation only
Fix from $1,600 2024-07-21
Flute HIGH 8.8
CVE-2024-6947

A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been rated as critical. This issue affects the function replaceContent of the file app/C…

Mitigation only
Fix from $1,950 2024-07-21
Flute HIGH 8.8
CVE-2024-6946

A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been declared as critical. This vulnerability affects unknown code of the file /admin/pa…

Mitigation only
Fix from $1,950 2024-07-21
Dedecms HIGH 7.2
CVE-2024-6940

A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php.…

No fix yet
Fix from $1,950 2024-07-21
Dir 823x Firmware CRITICAL 9.8
CVE-2024-39962

D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp…

No fix yet
Fix from $2,300 2024-07-19
Streampark HIGH 8.8
CVE-2024-29178

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …

Fix: 2.1.4+
Fix from $1,950 2024-07-18
Netextender HIGH 8.8
CVE-2024-29014

Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execu…

Fix: 10.2.341+
Fix from $1,950 2024-07-18
Airflow HIGH 8.8
CVE-2024-39877

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that …

Fix: 2.9.3+
Fix from $1,950 2024-07-17
Jupyterlab CRITICAL 9.8
CVE-2024-39700

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include …

Fix: 4.3.0+
Fix from $2,300 2024-07-16
Unclassified HIGH 7.0
CVE-2024-6655

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current wo…

Mitigation only
Fix from $1,950 2024-07-16
Unclassified CRITICAL 9.9
CVE-2024-39915

Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allo…

Patch available
Fix from $2,300 2024-07-15
Unclassified CRITICAL 9.4
CVE-2024-36456

This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted…

Mitigation only
Fix from $2,300 2024-07-15
Langchain Experimental HIGH 8.5
CVE-2024-21513

Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving values from t…

Fix: 0.0.21+
Fix from $1,950 2024-07-15
Unclassified HIGH 8.8
CVE-2024-6345

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. The…

Patch available
Fix from $1,950 2024-07-15
Seacms HIGH 8.8
CVE-2024-40521

SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrict…

No fix yet
Fix from $1,950 2024-07-12
Seacms HIGH 8.8
CVE-2024-40522

There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in with…

No fix yet
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40546

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code …

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40552

PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Unclassified MEDIUM 6.5
CVE-2024-37405

Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.

Mitigation only
Fix from $1,600 2024-07-12
Unclassified CRITICAL 9.8
CVE-2024-25077

An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images…

Mitigation only
Fix from $2,300 2024-07-10
Glpi HIGH 8.8
CVE-2024-37149EPSS 21%

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An…

Fix: 10.0.16+
Fix from $1,950 2024-07-10
14finger CRITICAL 9.1
CVE-2024-37770

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attacke…

No fix yet
Fix from $2,300 2024-07-10
Unclassified CRITICAL 9.8
CVE-2024-39071

Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.

Mitigation only
Fix from $2,300 2024-07-09
Netbox MEDIUM 6.1
CVE-2024-40726

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

No fix yet
Fix from $1,600 2024-07-09
Netbox MEDIUM 6.1
CVE-2024-40735

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

No fix yet
Fix from $1,600 2024-07-09
Firefox CRITICAL 9.8
CVE-2024-6602

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thu…

Fix: 115.13 / 128.0+
Fix from $2,300 2024-07-09
Ninja Forms CRITICAL 9.8
CVE-2024-37934

Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja …

Fix: 3.8.5+
Fix from $2,300 2024-07-09
Unclassified CRITICAL 9.8
CVE-2024-6365

The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomT…

Mitigation only
Fix from $2,300 2024-07-09
Unclassified MEDIUM 6.5
CVE-2024-22020

A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute ar…

Mitigation only
Fix from $1,600 2024-07-09
Cloudstack CRITICAL 9.8
CVE-2024-39864

The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio…

Fix: 4.18.2.1 / 4.19.0.2+
Fix from $2,300 2024-07-05