Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Yealink Meeting Server CRITICAL 9.8
CVE-2024-24091

Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.

Fix: 26.0.0.66+
Fix from $2,300 2024-02-08
L206 F2g Firmware HIGH 8.0
CVE-2023-45735

A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the d…

No fix yet
Fix from $1,950 2024-02-06
Agent Dvr HIGH 8.8
CVE-2024-22514

An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

Mitigation only
Fix from $1,950 2024-02-06
Display Custom Fields In The Frontend Post And User Profile Fields HIGH 8.8
CVE-2023-6996

The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_dis…

Fix: 1.3.0+
Fix from $1,950 2024-02-05
File Manager HIGH 8.8
CVE-2023-6846EPSS 16%

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_fileman…

Fix: after 8.3.4
Fix from $1,950 2024-02-05
Dashboard.js MEDIUM 6.1
CVE-2024-24396

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code vi…

Fix: 2024.1.2+
Fix from $1,600 2024-02-05
Flusity HIGH 8.8
CVE-2024-24469

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.

No fix yet
Fix from $1,950 2024-02-05
M3024 Lve Firmware HIGH 8.8
CVE-2023-5677

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validatio…

Fix: 5.51.7.7+
Fix from $1,950 2024-02-05
Axis Os HIGH 8.8
CVE-2023-5800

Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowin…

Fix: 9.80.55 / 10.12.220+
Fix from $1,950 2024-02-05
Binisoft Windows Firewall Control CRITICAL 9.8
CVE-2024-25089

Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.

Fix: 6.9.9.2+
Fix from $2,300 2024-02-04
Lumi Security Camera A31c Firmware CRITICAL 9.8
CVE-2023-50488

An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2024-02-02
Lumi Security Camera A31c Firmware MEDIUM 6.8
CVE-2023-51820

An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

No fix yet
Fix from $1,600 2024-02-02
Automation Studio HIGH 7.8
CVE-2021-22282

Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code…

Fix: after 4.12
Fix from $1,950 2024-02-02
Beetl CRITICAL 9.8
CVE-2024-22533

Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, …

No fix yet
Fix from $2,300 2024-02-02
Vinchin Backup And Recovery HIGH 8.8
CVE-2024-22899

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

Fix: after 7.2
Fix from $1,950 2024-02-02
Miro CRITICAL 9.8
CVE-2024-23746

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a k…

No fix yet
Fix from $2,300 2024-02-02
Automate HIGH 8.1
CVE-2023-47257

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

Fix: 23.8.5+
Fix from $1,950 2024-02-01
Helix Sync HIGH 7.8
CVE-2024-0325

In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.  

Fix: 2024.1+
Fix from $1,950 2024-02-01
Openbi CRITICAL 9.8
CVE-2024-1117

A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the function index of the file /…

Fix: after 1.0.8
Fix from $2,300 2024-01-31
Vantage6 HIGH 8.8
CVE-2024-21649

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). P…

Fix: 4.2.0+
Fix from $1,950 2024-01-30
Bigfix Servicenow Data Flow HIGH 8.8
CVE-2023-37518

HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the …

Fix: 1.3+
Fix from $1,950 2024-01-30
E Ddc3.3 Firmware CRITICAL 9.8
CVE-2024-1015

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different comman…

Mitigation only
Fix from $2,300 2024-01-29
Hyper CRITICAL 9.8
CVE-2024-23741

An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArgu…

Fix: after 3.4.1
Fix from $2,300 2024-01-28
Loom CRITICAL 9.8
CVE-2024-23742

An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArg…

Fix: after 0.196.1
Fix from $2,300 2024-01-28
Ui HIGH 8.8
CVE-2023-52251EPSS 85%

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/…

Fix: after 0.7.1
Fix from $1,950 2024-01-25
Processwire HIGH 7.2
CVE-2023-24676

An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when …

No fix yet
Fix from $1,950 2024-01-24
Bluefield Bmc HIGH 7.2
CVE-2023-31037

NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A succ…

Mitigation only
Fix from $1,950 2024-01-24
Snapcast CRITICAL 9.8
CVE-2023-36177EPSS 27%

An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via craft…

Fix: after 0.27.0
Fix from $2,300 2024-01-23
Firefox HIGH 8.8
CVE-2024-0755

Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.7 / 122.0+
Fix from $1,950 2024-01-23
Ipados HIGH 7.8
CVE-2024-23208

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A…

Fix: 10.3 / 14.3+
Fix from $1,950 2024-01-23