Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Keras CRITICAL 9.8
CVE-2024-3660

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions…

Fix: 2.13.1+
Fix from $2,300 2024-04-16
Unclassified MEDIUM 6.3
CVE-2024-30567

An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting f…

Mitigation only
Fix from $1,600 2024-04-16
Insurance Management System MEDIUM 6.1
CVE-2024-31648

Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payloa…

No fix yet
Fix from $1,600 2024-04-15
Wbsairback MEDIUM 6.6
CVE-2024-3784

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts…

Mitigation only
Fix from $1,600 2024-04-15
Wbsairback MEDIUM 6.6
CVE-2024-3785

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin…

Mitigation only
Fix from $1,600 2024-04-15
Wbsairback MEDIUM 6.6
CVE-2024-3786

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/D…

Mitigation only
Fix from $1,600 2024-04-15
Rainbow External Link Network Disk MEDIUM 6.1
CVE-2024-30845

Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation …

No fix yet
Fix from $1,600 2024-04-12
Sailor 600 Vsat Ku Firmware HIGH 8.1
CVE-2023-44857

An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the…

No fix yet
Fix from $1,950 2024-04-12
Tusbaudio HIGH 7.8
CVE-2024-25376

An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbi…

Fix: 5.68.0+
Fix from $1,950 2024-04-11
Form Tools HIGH 7.2
CVE-2024-22722

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the…

No fix yet
Fix from $1,950 2024-04-11
Savane HIGH 7.6
CVE-2024-29399

An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted fil…

Fix: after 3.13
Fix from $1,950 2024-04-11
Unclassified CRITICAL 9.8
CVE-2024-21508

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of …

Patch available
Fix from $2,300 2024-04-11
Rageframe MEDIUM 6.1
CVE-2024-30878

A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensiti…

No fix yet
Fix from $1,600 2024-04-11
FreeBSD CRITICAL 9.8
CVE-2024-29937

NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via…

Fix: after 7.4
Fix from $2,300 2024-04-11
Xwiki CRITICAL 9.8
CVE-2024-31996

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…

Fix: 14.10.19 / 15.5.4+
Fix from $2,300 2024-04-10
Password Manager HIGH 8.8
CVE-2024-26362

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via cr…

No fix yet
Fix from $1,950 2024-04-10
Avideo CRITICAL 9.8
CVE-2024-31819EPSS 16%

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.…

Fix: after 14.2
Fix from $2,300 2024-04-10
Xwiki CRITICAL 9.8
CVE-2024-31982EPSS 34%

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…

Fix: 14.10.20 / 15.5.4+
Fix from $2,300 2024-04-10
Xwiki HIGH 8.8
CVE-2024-31984EPSS 83%

XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document…

Fix: 14.10.20 / 15.5.4+
Fix from $1,950 2024-04-10
Secure Lockdown CRITICAL 9.8
CVE-2024-29500

An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce …

No fix yet
Fix from $2,300 2024-04-10
Xwiki HIGH 8.8
CVE-2024-31465EPSS 76%

XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit rig…

Fix: 14.10.20 / 15.5.4+
Fix from $1,950 2024-04-10
Unclassified CRITICAL 9.8
CVE-2024-3098

A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for pro…

Patch available
Fix from $2,300 2024-04-10
Aim CRITICAL 9.8
CVE-2024-2195

A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endp…

No fix yet
Fix from $2,300 2024-04-10
Zeppelin CRITICAL 9.8
CVE-2024-31864

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malic…

Fix: 0.11.1+
Fix from $2,300 2024-04-09
Fortimanager MEDIUM 6.7
CVE-2023-47542

A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below…

Fix: 7.0.11 / 7.2.5+
Fix from $1,600 2024-04-09
Forticlient HIGH 8.8
CVE-2023-45590

An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4…

Fix: 7.0.11+
Fix from $1,950 2024-04-09
Ex200 Firmware CRITICAL 9.8
CVE-2024-31807

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSync…

No fix yet
Fix from $2,300 2024-04-08
Candycms CRITICAL 9.8
CVE-2024-31022

An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component.

Mitigation only
Fix from $2,300 2024-04-08
Portal For Arcgis MEDIUM 6.1
CVE-2024-25706

There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL wh…

Fix: after 11.0
Fix from $1,600 2024-04-04
Tradepro CRITICAL 9.8
CVE-2023-36645

SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

No fix yet
Fix from $2,300 2024-04-04