Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Cloudstack CRITICAL 9.8
CVE-2024-38346

The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and …

Fix: 4.18.2.1 / 4.19.0.2+
Fix from $2,300 2024-07-05
Gogs CRITICAL 9.9
CVE-2024-39932EPSS 17%

Gogs through 0.13.0 allows argument injection during the previewing of changes.

Fix: after 0.13.0
Fix from $2,300 2024-07-04
Unclassified CRITICAL 9.8
CVE-2024-39165

QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the da…

Mitigation only
Fix from $2,300 2024-07-04
Unclassified HIGH 8.1
CVE-2024-6507

Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API

Patch available
Fix from $1,950 2024-07-04
Ghostscript HIGH 8.8
CVE-2024-33871

An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, e…

Fix: 10.03.1+
Fix from $1,950 2024-07-03
Unclassified CRITICAL 9.8
CVE-2024-39844

In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

Mitigation only
Fix from $2,300 2024-07-03
Windriver HIGH 7.8
CVE-2024-25086

Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.

Fix: 12.2.0+
Fix from $1,950 2024-07-02
Gradio CRITICAL 9.8
CVE-2024-39236

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered …

No fix yet
Fix from $2,300 2024-07-01
Geoserver CRITICAL 9.8
CVE-2024-36401 KEVEPSS 100%

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multipl…

Fix: 2.22.6 / 2.23.6+
Fix from $2,300 2024-07-01
Compass CRITICAL 9.8
CVE-2024-6376

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass'…

Fix: 1.42.2+
Fix from $2,300 2024-07-01
Jsonic MEDIUM 6.3
CVE-2024-39002

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to exec…

No fix yet
Fix from $1,600 2024-07-01
Unclassified CRITICAL 9.8
CVE-2024-39015

cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbit…

Mitigation only
Fix from $2,300 2024-07-01
Unclassified CRITICAL 9.8
CVE-2024-39017

agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers t…

Mitigation only
Fix from $2,300 2024-07-01
Unclassified MEDIUM 6.3
CVE-2024-38990

Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute a…

Mitigation only
Fix from $1,600 2024-07-01
Jsonic CRITICAL 9.8
CVE-2024-38993

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute a…

No fix yet
Fix from $2,300 2024-07-01
Unclassified HIGH 7.2
CVE-2024-36074

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protec…

Mitigation only
Fix from $1,950 2024-06-27
Unclassified MEDIUM 6.5
CVE-2024-36075

The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way…

Mitigation only
Fix from $1,600 2024-06-27
Unclassified MEDIUM 6.3
CVE-2024-39209

luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.

Mitigation only
Fix from $1,600 2024-06-27
H2o HIGH 7.5
CVE-2024-5979

In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` names…

Patch available
Fix from $1,950 2024-06-27
Unclassified CRITICAL 9.8
CVE-2024-5826

In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is t…

Mitigation only
Fix from $2,300 2024-06-27
Litellm CRITICAL 9.8
CVE-2024-5751

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_de…

Mitigation only
Fix from $2,300 2024-06-27
Unclassified CRITICAL 9.8
CVE-2024-39669

In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrar…

Mitigation only
Fix from $2,300 2024-06-27
Unclassified MEDIUM 6.3
CVE-2023-26877

File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/ef…

Mitigation only
Fix from $1,600 2024-06-26
Unclassified HIGH 8.4
CVE-2024-37855

An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary …

Mitigation only
Fix from $1,950 2024-06-25
Unclassified HIGH 7.5
CVE-2024-6206

A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where …

Mitigation only
Fix from $1,950 2024-06-25
Whatsup Gold CRITICAL 9.8
CVE-2024-4883EPSS 65%

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauth…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Whatsup Gold CRITICAL 9.8
CVE-2024-4884EPSS 24%

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Unclassified CRITICAL 10.0
CVE-2023-50029

PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run ar…

Mitigation only
Fix from $2,300 2024-06-24
Wishlist Member HIGH 8.8
CVE-2024-37109

Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue aff…

Fix: after 3.26.7
Fix from $1,950 2024-06-24
Unclassified CRITICAL 9.8
CVE-2024-5683

Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Remo…

Mitigation only
Fix from $2,300 2024-06-24