Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Moodle MEDIUM 5.4
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a per…

Mitigation only
Fix from $1,600 2024-03-22
Grav HIGH 8.8
CVE-2024-28118

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Gra…

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-28119

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from gra…

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-28116EPSS 6%

Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI…

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-28117

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDanger…

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Oscommerce MEDIUM 6.6
CVE-2024-22724

An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator prof…

No fix yet
Fix from $1,600 2024-03-21
Zhicms HIGH 8.8
CVE-2024-2016

A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontr…

No fix yet
Fix from $1,950 2024-03-21
Lagom MEDIUM 6.6
CVE-2024-25359

An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file.

Mitigation only
Fix from $1,600 2024-03-21
Leptoncms HIGH 7.8
CVE-2024-24520

An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

No fix yet
Fix from $1,950 2024-03-21
Orders \(csv\, Excel\) Export Pro HIGH 7.5
CVE-2024-28396

An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.

Fix: after 6.0.2
Fix from $1,950 2024-03-20
Firefox MEDIUM 6.1
CVE-2024-2610

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulne…

Fix: 115.9.0 / 124.0+
Fix from $1,600 2024-03-19
Unclassified HIGH 7.5
CVE-2024-24230

Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to exec…

Mitigation only
Fix from $1,950 2024-03-18
Openmetadata HIGH 8.8
CVE-2024-28847

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…

Fix: 1.2.4+
Fix from $1,950 2024-03-15
Openmetadata HIGH 8.8
CVE-2024-28848EPSS 8%

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…

Fix: 1.2.4+
Fix from $1,950 2024-03-15
Openmetadata HIGH 8.8
CVE-2024-28253EPSS 13%

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml…

Fix: 1.3.1+
Fix from $1,950 2024-03-15
Raspap HIGH 7.2
CVE-2024-2497

A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/p…

No fix yet
Fix from $1,950 2024-03-15
Glpi HIGH 8.8
CVE-2024-27756

GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

Fix: after 10.0.12
Fix from $1,950 2024-03-15
Zenml HIGH 8.8
CVE-2024-28424

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. Th…

No fix yet
Fix from $1,950 2024-03-14
Gv Asmanager HIGH 7.5
CVE-2022-46070

GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.

Mitigation only
Fix from $1,950 2024-03-11
Ipados HIGH 8.6
CVE-2024-23278

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS…

Fix: 10.4 / 13.6.5+
Fix from $1,950 2024-03-08
Student Enrollment CRITICAL 9.8
CVE-2023-41503

Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.

Mitigation only
Fix from $2,300 2024-03-07
Paddlepaddle CRITICAL 9.8
CVE-2024-0917

remote code execution in paddlepaddle/paddle 2.6.0

No fix yet
Fix from $2,300 2024-03-07
Teamwire HIGH 7.5
CVE-2024-24278

An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to…

Fix: after 2.4.0
Fix from $1,950 2024-03-05
Cms Made Simple HIGH 7.2
CVE-2024-27622

A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerabil…

No fix yet
Fix from $1,950 2024-03-05
Unclassified MEDIUM 6.1
CVE-2024-27627

A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript cod…

No fix yet
Fix from $1,600 2024-03-05
TYPO3 HIGH 7.2
CVE-2024-22188

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges o…

Fix: 8.7.57 / 9.5.46+
Fix from $1,950 2024-03-05
Mjml App CRITICAL 9.3
CVE-2024-25293

mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.

No fix yet
Fix from $2,300 2024-03-01
Pdfmake CRITICAL 9.8
CVE-2024-25180

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is dispu…

No fix yet
Fix from $2,300 2024-02-29
Deskfiler CRITICAL 9.8
CVE-2024-25291

Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.

No fix yet
Fix from $2,300 2024-02-29
Epointwebbuilder CRITICAL 9.8
CVE-2024-24525

An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the…

Mitigation only
Fix from $2,300 2024-02-29