Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
D Tale CRITICAL 9.8
CVE-2024-3408EPSS 78%

man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulner…

Patch available
Fix from $2,300 2024-06-06
Litellm HIGH 7.2
CVE-2024-4889

A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated input in the eval function wi…

Fix: 1.44.16+
Fix from $1,950 2024-06-06
Album And Image Gallery Plus Lightbox HIGH 7.3
CVE-2024-4194

The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includin…

Fix: 2.1+
Fix from $1,950 2024-06-06
Jan CRITICAL 9.8
CVE-2024-37273

An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2024-06-04
Unclassified CRITICAL 10.0
CVE-2024-25600EPSS 88%

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bri…

Mitigation only
Fix from $2,300 2024-06-04
Mlflow HIGH 8.8
CVE-2024-37061

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execu…

No fix yet
Fix from $1,950 2024-06-04
Gas Agency Management System CRITICAL 9.8
CVE-2024-36568

Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.

No fix yet
Fix from $2,300 2024-06-03
Javascript Deobfuscator HIGH 7.8
CVE-2024-36120

javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification c…

Fix: 1.1.0+
Fix from $1,950 2024-05-31
Unclassified HIGH 8.1
CVE-2024-5565EPSS 15%

The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and r…

Mitigation only
Fix from $1,950 2024-05-31
Http File Server CRITICAL 9.8
CVE-2024-23692 KEVEPSS 99%

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, …

Fix: after 2.4
Fix from $2,300 2024-05-31
Unlimited Elements For Elementor HIGH 8.8
CVE-2023-6743

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up…

Fix: after 1.5.89
Fix from $1,950 2024-05-29
Unclassified HIGH 7.3
CVE-2024-35226

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template aut…

Patch available
Fix from $1,950 2024-05-28
Computer Laboratory Management System MEDIUM 6.1
CVE-2024-35581

A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or H…

No fix yet
Fix from $1,600 2024-05-28
P3 550e Firmware CRITICAL 9.8
CVE-2024-23601

A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can le…

Mitigation only
Fix from $2,300 2024-05-28
Unclassified HIGH 8.4
CVE-2024-28886

OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), …

Mitigation only
Fix from $1,950 2024-05-28
Rhinos CRITICAL 9.8
CVE-2024-5407

A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allo…

Mitigation only
Fix from $2,300 2024-05-27
Fh1206 Firmware CRITICAL 9.8
CVE-2024-35339

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.

No fix yet
Fix from $2,300 2024-05-24
Wp Photo Album Plus HIGH 7.3
CVE-2024-4037

The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is…

Fix: 8.7.00.004+
Fix from $1,950 2024-05-24
Unclassified HIGH 8.1
CVE-2024-0867

The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce fu…

Mitigation only
Fix from $1,950 2024-05-24
Unclassified MEDIUM 6.8
CVE-2024-36361

Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileCli…

Patch available
Fix from $1,600 2024-05-24
Unclassified HIGH 8.8
CVE-2024-4662

The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is…

Mitigation only
Fix from $1,950 2024-05-23
Unclassified HIGH 7.8
CVE-2024-33225

An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to…

Mitigation only
Fix from $1,950 2024-05-22
Unclassified HIGH 8.4
CVE-2024-33228

An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execu…

Mitigation only
Fix from $1,950 2024-05-22
Unclassified MEDIUM 5.4
CVE-2024-4261

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…

Mitigation only
Fix from $1,600 2024-05-22
A Blog Cms MEDIUM 6.6
CVE-2024-31396

Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If…

Fix: 3.0.32 / 3.1.12+
Fix from $1,600 2024-05-22
Confluence Data Center HIGH 8.8
CVE-2024-21683EPSS 88%

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Co…

Fix: 4.8.15 / 5.4.21+
Fix from $1,950 2024-05-21
Cloud Foundation HIGH 7.2
CVE-2024-22274

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter app…

Fix: 5.1.1+
Fix from $1,950 2024-05-21
Unclassified CRITICAL 9.8
CVE-2024-24294

A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty func…

Mitigation only
Fix from $2,300 2024-05-20
Zammad MEDIUM 6.7
CVE-2024-36078

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server t…

Mitigation only
Fix from $1,600 2024-05-19
Unclassified CRITICAL 9.8
CVE-2024-4264

A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `e…

Mitigation only
Fix from $2,300 2024-05-18