Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Seacms HIGH 8.8
CVE-2024-30565

An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.

No fix yet
Fix from $1,950 2024-04-04
Leantime HIGH 7.6
CVE-2024-27705

Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse e…

No fix yet
Fix from $1,950 2024-04-03
Canto CRITICAL 9.8
CVE-2024-25096

Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a …

Fix: after 3.0.7
Fix from $2,300 2024-04-03
R6850 Firmware CRITICAL 9.8
CVE-2024-30568EPSS 47%

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.

No fix yet
Fix from $2,300 2024-04-03
Unclassified CRITICAL 9.9
CVE-2024-24707

Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly…

Mitigation only
Fix from $2,300 2024-04-03
Unclassified CRITICAL 9.9
CVE-2024-31390

: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance:…

Mitigation only
Fix from $2,300 2024-04-03
Dolibarr Erp\/crm HIGH 8.8
CVE-2024-29477

Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to e…

Fix: 19.0.1+
Fix from $1,950 2024-04-03
Unclassified CRITICAL 9.9
CVE-2024-31380

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, re…

No fix yet
Fix from $2,300 2024-04-03
Unclassified CRITICAL 9.9
CVE-2024-27972

Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lit…

Mitigation only
Fix from $2,300 2024-04-03
Unclassified HIGH 8.5
CVE-2024-27191

Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender allows Remote Code Inclusion…

Mitigation only
Fix from $1,950 2024-04-03
Instawp Connect HIGH 8.8
CVE-2024-25918

Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect…

Fix: 0.1.0.9+
Fix from $1,950 2024-04-03
Beescms CRITICAL 9.8
CVE-2024-31011

Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the…

No fix yet
Fix from $2,300 2024-04-03
Bento4 HIGH 8.1
CVE-2024-31005

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment

No fix yet
Fix from $1,950 2024-04-02
Bento4 CRITICAL 9.8
CVE-2024-31004

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragmen…

No fix yet
Fix from $2,300 2024-04-02
Bento4 HIGH 8.8
CVE-2024-31003

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WriteParti…

No fix yet
Fix from $1,950 2024-04-02
Unclassified CRITICAL 9.8
CVE-2024-29276EPSS 33%

An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerCont…

Mitigation only
Fix from $2,300 2024-04-02
Ns Asg Firmware CRITICAL 9.8
CVE-2024-30858

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

No fix yet
Fix from $2,300 2024-04-01
Ns Asg Firmware CRITICAL 9.8
CVE-2024-30868

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.

No fix yet
Fix from $2,300 2024-04-01
Standalone Sentry HIGH 8.8
CVE-2023-41724EPSS 13%

A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlyin…

Fix: 9.19.0+
Fix from $1,950 2024-03-31
Unclassified CRITICAL 9.8
CVE-2024-31032

An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code v…

Mitigation only
Fix from $2,300 2024-03-29
Jumpserver CRITICAL 9.9
CVE-2024-29202EPSS 6%

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection v…

Fix: 3.10.7+
Fix from $2,300 2024-03-29
Jumpserver CRITICAL 9.9
CVE-2024-29201EPSS 6%

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism…

Fix: 3.10.7+
Fix from $2,300 2024-03-29
Unclassified HIGH 8.4
CVE-2024-23727

The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScri…

Mitigation only
Fix from $1,950 2024-03-28
Unclassified HIGH 7.5
CVE-2024-2097

An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and exe…

Mitigation only
Fix from $1,950 2024-03-27
Unclassified HIGH 7.5
CVE-2024-0400

SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filt…

Mitigation only
Fix from $1,950 2024-03-27
26k70b Firmware MEDIUM 6.3
CVE-2024-2209

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update …

Fix: 2349c / 2349d+
Fix from $1,600 2024-03-27
Unclassified HIGH 8.1
CVE-2024-0866

The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_…

Mitigation only
Fix from $1,950 2024-03-26
Emacs HIGH 7.8
CVE-2024-30202

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

Fix: 9.6.23 / 29.3+
Fix from $1,950 2024-03-25
Fastmag Sync CRITICAL 9.8
CVE-2024-28386

An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.

Fix: after 1.7.51
Fix from $2,300 2024-03-25
Clickup HIGH 8.8
CVE-2024-23755

ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against c…

Fix: 3.3.77+
Fix from $1,950 2024-03-23