Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Emacs CRITICAL 9.8
CVE-2024-39331

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-comm…

Fix: 29.4+
Fix from $2,300 2024-06-23
Soar HIGH 8.8
CVE-2024-38319

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 2948…

Fix: after 51.0.2.0
Fix from $1,950 2024-06-22
Joplin CRITICAL 9.0
CVE-2023-45673

Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on …

Fix: 2.13.3+
Fix from $2,300 2024-06-21
Xwiki HIGH 8.0
CVE-2024-37899

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the u…

Fix: 14.10.21 / 15.5.5+
Fix from $1,950 2024-06-20
Unclassified MEDIUM 5.3
CVE-2024-28397

An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.

Mitigation only
Fix from $1,600 2024-06-20
Unclassified MEDIUM 6.3
CVE-2024-33335

SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.

Mitigation only
Fix from $1,600 2024-06-20
Custom Field Suite HIGH 8.8
CVE-2024-3562

The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field…

Fix: after 2.6.7
Fix from $1,950 2024-06-20
Unclassified CRITICAL 10.0
CVE-2024-36679

In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token…

Mitigation only
Fix from $2,300 2024-06-19
Unclassified HIGH 8.1
CVE-2024-32030EPSS 34%

Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their ne…

Patch available
Fix from $1,950 2024-06-19
Unclassified CRITICAL 9.8
CVE-2024-37124

Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an ar…

Mitigation only
Fix from $2,300 2024-06-19
Dolibarr Erp\/crm HIGH 8.8
CVE-2024-37821

An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code v…

Fix: 19.0.2+
Fix from $1,950 2024-06-18
Unclassified CRITICAL 9.8
CVE-2024-36575

A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.

Mitigation only
Fix from $2,300 2024-06-17
Unclassified HIGH 7.6
CVE-2024-36581

A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.

Mitigation only
Fix from $1,950 2024-06-17
Iterm2 CRITICAL 9.8
CVE-2024-38396

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in…

Fix: 3.5.2+
Fix from $2,300 2024-06-16
Xenforo HIGH 8.8
CVE-2024-38458

Xenforo before 2.2.16 allows code injection.

Fix: 2.2.16+
Fix from $1,950 2024-06-16
Unclassified CRITICAL 9.1
CVE-2024-38448

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

Mitigation only
Fix from $2,300 2024-06-16
Iterm2 CRITICAL 9.8
CVE-2024-38395

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivial…

Fix: 3.5.2+
Fix from $2,300 2024-06-16
Unclassified CRITICAL 9.9
CVE-2024-3105

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, a…

Mitigation only
Fix from $2,300 2024-06-15
Unclassified HIGH 8.1
CVE-2024-36598

An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

Mitigation only
Fix from $1,950 2024-06-14
Desktop HIGH 7.8
CVE-2024-37885

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client fo…

Fix: 3.12.0+
Fix from $1,950 2024-06-14
Android HIGH 8.8
CVE-2024-32925

In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e…

Mitigation only
Fix from $1,950 2024-06-13
Billing System CRITICAL 9.8
CVE-2024-37849

A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username pa…

No fix yet
Fix from $2,300 2024-06-13
Megabip CRITICAL 9.8
CVE-2024-1577

Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving cra…

Fix: after 5.11.2
Fix from $2,300 2024-06-12
Chrome HIGH 8.8
CVE-2024-5834

Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML p…

Fix: 126.0.6478.54+
Fix from $1,950 2024-06-11
Unclassified CRITICAL 9.1
CVE-2024-34405

Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within th…

Mitigation only
Fix from $2,300 2024-06-11
Ipados HIGH 7.8
CVE-2024-27857

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 1…

Fix: 1.2 / 14.5+
Fix from $1,950 2024-06-10
Langflow CRITICAL 9.8
CVE-2024-37014EPSS 57%

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a …

Fix: after 0.6.19
Fix from $2,300 2024-06-10
macOS HIGH 7.8
CVE-2022-32897

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff f…

Fix: 12.5+
Fix from $1,950 2024-06-10
Unclassified HIGH 8.5
CVE-2024-34761

Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE …

Mitigation only
Fix from $1,950 2024-06-10
Egovernment MEDIUM 5.7
CVE-2024-36531

nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php compo…

Fix: after 4.5.05
Fix from $1,600 2024-06-10