Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Spider Flow CRITICAL 9.8
CVE-2024-0195EPSS 19%

A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file …

No fix yet
Fix from $2,300 2024-01-02
Jetelements HIGH 8.8
CVE-2023-39157

Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For El…

Fix: after 2.6.10
Fix from $1,950 2023-12-31
Jeecg Boot CRITICAL 9.8
CVE-2023-41544

SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport…

Fix: after 3.5.3
Fix from $2,300 2023-12-30
Verge3d HIGH 8.8
CVE-2023-51420

Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D…

Fix: after 4.5.2
Fix from $1,950 2023-12-29
Astra HIGH 8.8
CVE-2023-49830

Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through …

Fix: after 4.3.1
Fix from $1,950 2023-12-29
Nexter Extension HIGH 7.2
CVE-2023-45751

Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a th…

Fix: after 2.0.3
Fix from $1,950 2023-12-29
Wp Extra HIGH 8.8
CVE-2023-46623

Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra: from n/a through 6.2.

Fix: after 6.2
Fix from $1,950 2023-12-29
Qode Essential Addons HIGH 8.8
CVE-2023-47840

Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential A…

Fix: after 1.5.2
Fix from $1,950 2023-12-29
Wp Booklet HIGH 8.8
CVE-2023-22677

Improper Control of Generation of Code ('Code Injection') vulnerability in BinaryStash WP Booklet.This issue affects WP Booklet: from n/a through 2.1…

Fix: after 2.1.8
Fix from $1,950 2023-12-29
Rsvpmaker CRITICAL 9.8
CVE-2023-25054

Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.…

Fix: after 10.6.6
Fix from $2,300 2023-12-29
Rename Media Files HIGH 8.8
CVE-2023-32095

Improper Control of Generation of Code ('Code Injection') vulnerability in Milan Dinić Rename Media Files.This issue affects Rename Media Files: from…

Fix: after 1.0.1
Fix from $1,950 2023-12-29
Kanban Boards For Wordpress HIGH 7.2
CVE-2023-40606

Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban…

Fix: after 2.5.21
Fix from $1,950 2023-12-29
Cash Point \& Transport Optimizer MEDIUM 5.3
CVE-2023-31296

CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive informatio…

Mitigation only
Fix from $1,600 2023-12-29
Shifu HIGH 8.1
CVE-2023-7148

A vulnerability has been found in ShifuML shifu 0.12.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

No fix yet
Fix from $1,950 2023-12-29
Seacms HIGH 8.8
CVE-2023-46987

SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.

Mitigation only
Fix from $1,950 2023-12-28
Artisbrowser CRITICAL 9.8
CVE-2023-49000

An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis…

Fix: after 34.1.5
Fix from $2,300 2023-12-27
Indi Browser CRITICAL 9.8
CVE-2023-49001

An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the com.example.gu…

Mitigation only
Fix from $2,300 2023-12-27
Tv Bro CRITICAL 9.8
CVE-2023-43955

The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. This allows attackers to execute…

Fix: after 2.0.0
Fix from $2,300 2023-12-27
Tv Browser CRITICAL 9.8
CVE-2023-47883

The com.altamirano.fabricio.tvbrowser TV browser application through 4.5.1 for Android is vulnerable to JavaScript code execution via an explicit int…

Fix: after 4.5.1
Fix from $2,300 2023-12-27
Browser Tv Web Browsehere CRITICAL 9.8
CVE-2023-43481

An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbitrary Ja…

No fix yet
Fix from $2,300 2023-12-27
Debian Linux HIGH 7.8
CVE-2023-7101 KEVEPSS 17%

Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut…

Fix: after 0.65
Fix from $1,950 2023-12-24
Hertzbeat HIGH 8.8
CVE-2023-51387

Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are suppo…

Fix: 1.4.1+
Fix from $1,950 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51015

TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cst…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51018

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig i…

No fix yet
Fix from $2,300 2023-12-22
Ex1800t Firmware CRITICAL 9.8
CVE-2023-51026

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg in…

No fix yet
Fix from $2,300 2023-12-22
Free5gc HIGH 7.5
CVE-2023-49391

An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF compon…

No fix yet
Fix from $1,950 2023-12-22
Automad MEDIUM 5.4
CVE-2023-7035

A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file pac…

Fix: after 1.10.9
Fix from $1,600 2023-12-21
Self Service Password CRITICAL 9.8
CVE-2023-49032

An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack o…

Fix: 1.5.4+
Fix from $2,300 2023-12-21
Dir 850l Firmware CRITICAL 9.8
CVE-2023-49004

An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.

Mitigation only
Fix from $2,300 2023-12-19
Epmp Force 300 25 Firmware HIGH 7.8
CVE-2023-6691

Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code executi…

Mitigation only
Fix from $1,950 2023-12-18