Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Zabbix Agent2 CRITICAL 9.8
CVE-2023-32728

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability f…

Fix: after 6.4.8
Fix from $2,300 2023-12-18
Dashmachine CRITICAL 9.8
CVE-2023-6899

A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of t…

No fix yet
Fix from $2,300 2023-12-17
Wangmarket CRITICAL 9.8
CVE-2023-6886

A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the componen…

Mitigation only
Fix from $2,300 2023-12-17
Kodexplorer CRITICAL 9.8
CVE-2023-6851

A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the function unzipList of the fil…

Fix: 4.52.01+
Fix from $2,300 2023-12-16
Xwiki HIGH 8.8
CVE-2023-50723

XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wi…

Fix: 14.10.5 / 15.5.2+
Fix from $1,950 2023-12-15
Xwiki HIGH 8.8
CVE-2023-50721EPSS 79%

XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration inte…

Fix: 14.10.5 / 15.5.2+
Fix from $1,950 2023-12-15
GitLab MEDIUM 5.7
CVE-2023-5512

An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versi…

Fix: 16.4.4 / 16.5.4+
Fix from $1,600 2023-12-15
GitLab MEDIUM 6.5
CVE-2023-6051

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starti…

Fix: 16.4.4 / 16.5.4+
Fix from $1,600 2023-12-15
Backup Migration CRITICAL 9.8
CVE-2023-6553EPSS 98%

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup…

Fix: after 1.3.7
Fix from $2,300 2023-12-15
Easylog Web\+ Firmware CRITICAL 9.8
CVE-2023-48390

Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject code and acce…

Mitigation only
Fix from $2,300 2023-12-15
Nagios Xi CRITICAL 9.8
CVE-2023-48085EPSS 76%

Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

Fix: 5.11.3+
Fix from $2,300 2023-12-14
Searchor CRITICAL 9.8
CVE-2023-43364

main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

Fix: 2.4.2+
Fix from $2,300 2023-12-12
Safari HIGH 8.8
CVE-2023-42890

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2,…

Fix: 10.2 / 14.2+
Fix from $1,950 2023-12-12
Frauscher Diagnostic System 102 HIGH 8.8
CVE-2023-5500

This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full con…

Fix: 2.10.2+
Fix from $1,950 2023-12-11
Line HIGH 8.2
CVE-2023-43301

An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access toke…

No fix yet
Fix from $1,950 2023-12-07
Remote Desktop Manager HIGH 7.8
CVE-2023-6288

Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environmen…

Fix: 2023.3.10.2+
Fix from $1,950 2023-12-06
Ofbiz CRITICAL 9.8
CVE-2023-49070EPSS 95%

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Us…

Fix: 18.12.10+
Fix from $2,300 2023-12-05
Filr HIGH 8.8
CVE-2023-5762

The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execut…

Fix: 1.2.3.6+
Fix from $1,950 2023-12-04
Htmlunit HIGH 8.8
CVE-2023-49093

HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpag…

Fix: 3.9.0+
Fix from $1,950 2023-12-04
October CRITICAL 9.1
CVE-2023-44382

October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms…

Fix: 3.4.15+
Fix from $2,300 2023-12-01
GitLab HIGH 7.5
CVE-2023-5226

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting fro…

Fix: 16.4.3 / 16.5.3+
Fix from $1,950 2023-12-01
Android CRITICAL 9.8
CVE-2022-42541

Remote code execution

No fix yet
Fix from $2,300 2023-11-29
Xmachoviewer CRITICAL 9.8
CVE-2023-49313

A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected …

No fix yet
Fix from $2,300 2023-11-28
Desktop HIGH 7.8
CVE-2023-49314

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through …

Mitigation only
Fix from $1,950 2023-11-28
Owncast CRITICAL 9.8
CVE-2023-46480

An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the ind…

Mitigation only
Fix from $2,300 2023-11-27
Asgaros Forum CRITICAL 9.8
CVE-2023-5604

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configu…

Fix: 2.7.1+
Fix from $2,300 2023-11-27
Kibana HIGH 7.2
CVE-2021-22150

It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, th…

Fix: 7.14.1+
Fix from $1,950 2023-11-22
Fastbots CRITICAL 9.8
CVE-2023-48699

fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker…

Fix: 0.1.5+
Fix from $2,300 2023-11-21
Syrus 4g Iot Telematics Gateway Firmware CRITICAL 9.8
CVE-2023-6248

The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex…

Mitigation only
Fix from $2,300 2023-11-21
A3700r Firmware HIGH 7.8
CVE-2023-48192

An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.

No fix yet
Fix from $1,950 2023-11-20