Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified MEDIUM 6.5
CVE-2024-3734

The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and…

Mitigation only
Fix from $1,600 2024-05-02
Unclassified HIGH 7.7
CVE-2024-29309

An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.

Mitigation only
Fix from $1,950 2024-05-02
Unclassified CRITICAL 9.8
CVE-2024-3955

URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subsequently passed to the "os.sy…

Mitigation only
Fix from $2,300 2024-05-02
Phiola HIGH 8.8
CVE-2024-33430

An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.

No fix yet
Fix from $1,950 2024-05-01
Softpaqs HIGH 7.7
CVE-2024-28893

Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified …

Mitigation only
Fix from $1,950 2024-05-01
Onethink HIGH 7.1
CVE-2024-33443

An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.

No fix yet
Fix from $1,950 2024-04-29
Ecommerce Codeigniter Bootstrap CRITICAL 9.8
CVE-2024-31822

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via…

Fix: 2024-01-02+
Fix from $2,300 2024-04-29
Ecommerce Codeigniter Bootstrap HIGH 8.8
CVE-2024-31823

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via…

Patch available
Fix from $1,950 2024-04-29
Flowise HIGH 7.6
CVE-2024-31621EPSS 60%

An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.

Fix: after 1.6.5
Fix from $1,950 2024-04-29
Znuny CRITICAL 9.8
CVE-2024-32491

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a ma…

Fix: after 7.0.16
Fix from $2,300 2024-04-29
Znuny HIGH 7.1
CVE-2024-32492

An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript.

Fix: after 7.0.16
Fix from $1,950 2024-04-29
Hisiphp CRITICAL 9.8
CVE-2024-33445

An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the Sy…

No fix yet
Fix from $2,300 2024-04-29
Relate MEDIUM 6.0
CVE-2024-32404

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafte…

Fix: 2024.1+
Fix from $1,600 2024-04-26
Unclassified CRITICAL 9.8
CVE-2024-22632

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hm…

No fix yet
Fix from $2,300 2024-04-26
Unclassified CRITICAL 9.8
CVE-2024-22633

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hp…

Mitigation only
Fix from $2,300 2024-04-26
Jpress HIGH 7.5
CVE-2024-32358

An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different…

Mitigation only
Fix from $1,950 2024-04-25
Iris MEDIUM 6.8
CVE-2024-25624

Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of …

Fix: 2.4.6+
Fix from $1,600 2024-04-25
Unclassified CRITICAL 9.0
CVE-2024-22144

Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows C…

No fix yet
Fix from $2,300 2024-04-25
Unclassified CRITICAL 9.1
CVE-2024-31266

Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommerce allows Code Injection.This…

Mitigation only
Fix from $2,300 2024-04-25
Adaptive Security Appliance Software MEDIUM 6.0
CVE-2024-20359 KEVEPSS 19%

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secu…

Mitigation only
Fix from $1,600 2024-04-24
Unclassified CRITICAL 9.8
CVE-2024-21511

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the …

Patch available
Fix from $2,300 2024-04-23
Crushftp CRITICAL 10.0
CVE-2024-4040 KEVEPSS 100%

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote at…

Fix: 10.7.1 / 11.1.0+
Fix from $2,300 2024-04-22
Flusity CRITICAL 9.8
CVE-2024-31666

An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.

No fix yet
Fix from $2,300 2024-04-22
Unclassified HIGH 7.8
CVE-2024-28699

A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutp…

No fix yet
Fix from $1,950 2024-04-22
Edge Chromium MEDIUM 5.0
CVE-2024-29991

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Fix: 124.0.2478.51+
Fix from $1,600 2024-04-19
Fedora MEDIUM 6.7
CVE-2023-51797

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:7…

Mitigation only
Fix from $1,600 2024-04-19
Wazuh HIGH 8.8
CVE-2023-50260EPSS 41%

Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to …

Fix: 4.7.2+
Fix from $1,950 2024-04-19
Derbynet CRITICAL 9.8
CVE-2024-30923

SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rend…

Fix: after 9.0
Fix from $2,300 2024-04-18
Unclassified CRITICAL 10.0
CVE-2024-32599

Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator.This is…

Mitigation only
Fix from $2,300 2024-04-18
Totara MEDIUM 5.4
CVE-2024-3931

A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the fil…

Fix: 13.46 / 14.38+
Fix from $1,600 2024-04-18