Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Simple Student Attendance System CRITICAL 9.8
CVE-2023-51801

SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to…

No fix yet
Fix from $2,300 2024-02-29
Fedora HIGH 8.6
CVE-2024-25713

yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free …

Fix: after 0.8.0
Fix from $1,950 2024-02-29
Zoo Management System CRITICAL 9.8
CVE-2024-25350

SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.

No fix yet
Fix from $2,300 2024-02-28
User Registration \& Login And User Management System MEDIUM 6.1
CVE-2024-25202

Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via …

No fix yet
Fix from $1,600 2024-02-28
Ambari HIGH 8.8
CVE-2023-50379

Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cl…

Fix: 2.7.8+
Fix from $1,950 2024-02-27
Webos Signage CRITICAL 9.8
CVE-2024-1885

This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.

No fix yet
Fix from $2,300 2024-02-26
Zkbio Wdms CRITICAL 9.8
CVE-2024-22988

ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename …

Mitigation only
Fix from $2,300 2024-02-23
Automation Studio HIGH 8.1
CVE-2024-0220

B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing se…

Fix: 1.4.0 / 4.6+
Fix from $1,950 2024-02-22
Kirby HIGH 8.8
CVE-2024-26483

An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF f…

Fix: 3.6.6.5 / 3.7.5.4+
Fix from $1,950 2024-02-22
Ac21 Firmware HIGH 8.8
CVE-2023-24333

A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via…

No fix yet
Fix from $1,950 2024-02-21
He3 App CRITICAL 9.8
CVE-2024-25249

An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments s…

Mitigation only
Fix from $2,300 2024-02-21
Zkbio Access Ivs MEDIUM 5.4
CVE-2024-1706

A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. …

Fix: after 3.3.2
Fix from $1,600 2024-02-21
Shopwind HIGH 8.1
CVE-2024-1705

A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/inst…

Fix: after 4.6
Fix from $1,950 2024-02-21
Vdesk HIGH 7.5
CVE-2022-45177

An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/…

Fix: after 031
Fix from $1,950 2024-02-21
Assets Discovery Data Center HIGH 7.2
CVE-2024-21682

This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded…

Fix: 6.2.1+
Fix from $1,950 2024-02-20
Dolphinscheduler HIGH 7.5
CVE-2023-51770

Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr…

Fix: 3.2.1+
Fix from $1,950 2024-02-20
Dolphinscheduler CRITICAL 9.8
CVE-2023-49109

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr…

Fix: 3.2.1+
Fix from $2,300 2024-02-20
Node.js HIGH 7.8
CVE-2024-21892

On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated…

Fix: 18.19.1 / 20.11.1+
Fix from $1,950 2024-02-20
Emui CRITICAL 9.8
CVE-2023-52381

Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and a…

No fix yet
Fix from $2,300 2024-02-18
Redaxo HIGH 7.2
CVE-2024-25298

An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.

No fix yet
Fix from $1,950 2024-02-17
Ce Phoenix Cart HIGH 7.2
CVE-2024-25415EPSS 27%

A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via …

No fix yet
Fix from $1,950 2024-02-16
Flusity CRITICAL 9.8
CVE-2024-25502

Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the do…

No fix yet
Fix from $2,300 2024-02-15
FreeBSD CRITICAL 9.8
CVE-2022-23088

The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a Fr…

Fix: 12.3 / 13.0+
Fix from $2,300 2024-02-15
Redaxo HIGH 7.2
CVE-2024-25301

Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

No fix yet
Fix from $1,950 2024-02-14
365 Apps HIGH 8.8
CVE-2024-21378EPSS 11%

Microsoft Outlook Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-02-13
Windows 10 1507 HIGH 7.6
CVE-2024-21351 KEVEPSS 30%

Windows SmartScreen Security Feature Bypass Vulnerability

Fix: 10.0.10240.20469 / 10.0.14393.6709+
Fix from $1,950 2024-02-13
Collaboration MEDIUM 6.1
CVE-2023-50808

Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.

Fix: 9.0.0+
Fix from $1,600 2024-02-13
Abap Platform HIGH 7.2
CVE-2024-22131

In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi…

Mitigation only
Fix from $1,950 2024-02-13
Sui CRITICAL 9.8
CVE-2023-42374

An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted co…

Fix: 1.6.3+
Fix from $2,300 2024-02-13
Azure Uamqp HIGH 8.1
CVE-2024-25110EPSS 7%

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-aft…

Fix: 2024-02-01+
Fix from $1,950 2024-02-12