Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified MEDIUM 6.3
CVE-2024-31974

The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary…

Mitigation only
Fix from $1,600 2024-05-17
Unclassified CRITICAL 9.9
CVE-2024-33644

Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affect…

Mitigation only
Fix from $2,300 2024-05-17
Husky Products Filter Professional For Woocommerce HIGH 8.8
CVE-2024-32680

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerabili…

Fix: 1.3.5.3+
Fix from $1,950 2024-05-17
Code Snippets Extension CRITICAL 9.9
CVE-2023-23645

Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue aff…

Fix: 4.0.3+
Fix from $2,300 2024-05-17
Unclassified CRITICAL 9.8
CVE-2023-48643

Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authori…

Mitigation only
Fix from $2,300 2024-05-16
Llamaindex HIGH 8.8
CVE-2024-4181

A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI …

Fix: 0.10.13+
Fix from $1,950 2024-05-16
Telerik Reporting HIGH 8.6
CVE-2024-4202

In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulner…

Fix: 18.1.24.514+
Fix from $1,950 2024-05-15
Telerik Ui For Winforms MEDIUM 6.7
CVE-2024-3892

A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability cou…

Fix: 2024.2.514+
Fix from $1,600 2024-05-15
Unclassified CRITICAL 9.1
CVE-2024-3319

An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticate…

Mitigation only
Fix from $2,300 2024-05-15
Fedora MEDIUM 6.5
CVE-2024-3044

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt …

Fix: 7.6.7.1 / 24.2.3.1+
Fix from $1,600 2024-05-14
Unclassified MEDIUM 6.5
CVE-2024-4144

The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,…

Mitigation only
Fix from $1,600 2024-05-14
X5000r Firmware HIGH 8.8
CVE-2024-32352

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEna…

No fix yet
Fix from $1,950 2024-05-14
X5000r Firmware HIGH 8.8
CVE-2024-32350

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" pa…

No fix yet
Fix from $1,950 2024-05-14
Unclassified HIGH 8.8
CVE-2024-4605

The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is du…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified MEDIUM 6.5
CVE-2024-4038

The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerable to arbitrary shortcode exe…

Mitigation only
Fix from $1,600 2024-05-14
Unclassified MEDIUM 6.5
CVE-2024-4039

The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and …

Mitigation only
Fix from $1,600 2024-05-14
Wbsairback MEDIUM 6.6
CVE-2024-3787

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Explo…

Mitigation only
Fix from $1,600 2024-05-14
Wbsairback MEDIUM 6.6
CVE-2024-3788

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploi…

Mitigation only
Fix from $1,600 2024-05-14
Computer Laboratory Management System MEDIUM 6.1
CVE-2024-34225

Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote a…

No fix yet
Fix from $1,600 2024-05-14
Unclassified HIGH 7.8
CVE-2024-29513

An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the dr…

Mitigation only
Fix from $1,950 2024-05-14
Itunes HIGH 7.8
CVE-2024-27793

The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termina…

Fix: 12.13.2+
Fix from $1,950 2024-05-14
Unclassified MEDIUM 5.4
CVE-2024-4135

The WP Latest Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to t…

Mitigation only
Fix from $1,600 2024-05-08
Unclassified MEDIUM 6.0
CVE-2024-29209

A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to r…

Mitigation only
Fix from $1,600 2024-05-07
Unclassified HIGH 8.8
CVE-2024-30973

An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive informa…

Mitigation only
Fix from $1,950 2024-05-06
Unclassified CRITICAL 9.1
CVE-2024-33294

An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the s…

Mitigation only
Fix from $2,300 2024-05-06
Unclassified CRITICAL 9.8
CVE-2024-34461

Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code executio…

Mitigation only
Fix from $2,300 2024-05-04
Hive MEDIUM 6.6
CVE-2023-35701

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and…

Mitigation only
Fix from $1,600 2024-05-03
Papercut Mf HIGH 7.2
CVE-2023-39469EPSS 58%

PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary …

Fix: 22.1.1+
Fix from $1,950 2024-05-03
Kubevirt MEDIUM 5.9
CVE-2024-33394

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

Fix: after 1.2.0
Fix from $1,600 2024-05-02
Booster For Woocommerce HIGH 7.3
CVE-2024-3957

The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allow…

Fix: 7.1.9+
Fix from $1,950 2024-05-02