Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Metagpt HIGH 8.8
CVE-2024-23750

MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Pop…

Fix: after 0.6.4
Fix from $1,950 2024-01-22
Paddle HIGH 7.8
CVE-2024-0521

Code Injection in paddlepaddle/paddle

Patch available
Fix from $1,950 2024-01-20
Mldong CRITICAL 9.8
CVE-2024-0738

A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the fil…

No fix yet
Fix from $2,300 2024-01-19
Pillow HIGH 8.1
CVE-2023-50447

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817…

Fix: after 10.1.0
Fix from $1,950 2024-01-19
Netscaler Application Delivery Controller HIGH 8.8
CVE-2023-6548 KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP…

Fix: 12.1-55.302 / 13.0-92.21+
Fix from $1,950 2024-01-17
Social Warfare CRITICAL 9.8
CVE-2021-4434

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. T…

Fix: 3.5.3+
Fix from $2,300 2024-01-17
Sourcetree HIGH 7.8
CVE-2023-22514

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. …

Fix: 3.4.15 / 4.2.5+
Fix from $1,950 2024-01-16
School Management CRITICAL 9.8
CVE-2022-1609EPSS 64%

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API …

Fix: 9.9.7+
Fix from $2,300 2024-01-16
Fedora CRITICAL 9.8
CVE-2023-6395

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary co…

Patch available
Fix from $2,300 2024-01-16
Confluence Data Center HIGH 8.8
CVE-2024-21672

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execu…

Fix: 7.19.18 / 8.5.5+
Fix from $1,950 2024-01-16
Confluence Data Center HIGH 8.8
CVE-2024-21673

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Exe…

Fix: 7.19.18 / 8.5.5+
Fix from $1,950 2024-01-16
Confluence Data Center HIGH 7.5
CVE-2024-21674

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Exec…

Fix: 7.19.18 / 8.5.5+
Fix from $1,950 2024-01-16
Confluence Data Center HIGH 8.8
CVE-2023-22526

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Exe…

Fix: 7.19.17 / 8.5.5+
Fix from $1,950 2024-01-16
Hummerrisk HIGH 8.8
CVE-2023-43449

An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/L…

Fix: after 1.4.1
Fix from $1,950 2024-01-16
Mcms HIGH 7.5
CVE-2023-51282

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

No fix yet
Fix from $1,950 2024-01-16
Iotdb CRITICAL 9.8
CVE-2023-46226

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to v…

Fix: 1.3.0+
Fix from $2,300 2024-01-15
Archive Storage Manager HIGH 8.8
CVE-2023-51066

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily e…

No fix yet
Fix from $1,950 2024-01-13
Scada Lts HIGH 8.8
CVE-2023-33472

An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileg…

Fix: after 2.7.5.2
Fix from $1,950 2024-01-13
Manageengine Adselfservice Plus HIGH 8.8
CVE-2024-0252EPSS 8%

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer…

Fix: 6.4+
Fix from $1,950 2024-01-11
Safari HIGH 8.8
CVE-2023-42833

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web conte…

Fix: 14.0 / 17.0+
Fix from $1,950 2024-01-10
macOS HIGH 7.8
CVE-2023-32383

This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed in macOS Monterey 12.6.6, macO…

Fix: 11.7.7 / 12.6.6+
Fix from $1,950 2024-01-10
Identitymodel Extensions HIGH 8.8
CVE-2024-21643

IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's i…

Fix: 6.34.0 / 7.1.2+
Fix from $1,950 2024-01-10
Application Interface Framework CRITICAL 9.1
CVE-2024-21737

In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers…

Mitigation only
Fix from $2,300 2024-01-09
Azure Uamqp CRITICAL 9.8
CVE-2024-21646EPSS 5%

Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When…

Fix: 2024-01-01+
Fix from $2,300 2024-01-09
Xwiki CRITICAL 9.8
CVE-2024-21650EPSS 93%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code executi…

Fix: 14.10.17 / 15.5.3+
Fix from $2,300 2024-01-08
Connect HIGH 7.8
CVE-2023-7224

OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARI…

Fix: after 3.4.6
Fix from $1,950 2024-01-08
Browser Hd HIGH 7.5
CVE-2023-6540

A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that…

Fix: 2.1.4.1 / 9.1.3.1+
Fix from $1,950 2024-01-03
Inlong CRITICAL 9.8
CVE-2023-51784

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, …

Fix: 1.10.0+
Fix from $2,300 2024-01-03
Zxcloud Irai HIGH 7.8
CVE-2023-41783

There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker co…

Fix: 7.23.32+
Fix from $1,950 2024-01-03
Magic Api HIGH 8.8
CVE-2024-0196

A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the…

Fix: after 2.0.1
Fix from $1,950 2024-01-02