Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Opencrx MEDIUM 6.1
CVE-2023-40809

OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.

No fix yet
Fix from $1,600 2023-11-18
Getsimplecms CRITICAL 9.8
CVE-2023-6188

A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin…

No fix yet
Fix from $2,300 2023-11-17
H2o CRITICAL 9.8
CVE-2023-6016EPSS 31%

An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.

No fix yet
Fix from $2,300 2023-11-16
Redisgraph CRITICAL 9.8
CVE-2023-47003

An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsD…

No fix yet
Fix from $2,300 2023-11-16
Opencart HIGH 8.8
CVE-2023-47444

An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untr…

Fix: after 4.0.2.3
Fix from $1,950 2023-11-15
Statamic HIGH 8.8
CVE-2023-48217

Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look…

Fix: 3.4.14 / 4.34.0+
Fix from $1,950 2023-11-14
Azure Pipelines Agent HIGH 8.8
CVE-2023-36437

Azure DevOps Server Remote Code Execution Vulnerability

Fix: 2.39.1+
Fix from $1,950 2023-11-14
Suitecrm HIGH 8.8
CVE-2023-6131

Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $1,950 2023-11-14
Suitecrm HIGH 8.8
CVE-2023-6125

Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $1,950 2023-11-14
Suitecrm CRITICAL 9.8
CVE-2023-6126

Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $2,300 2023-11-14
Memberscard HIGH 7.5
CVE-2023-45560

An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

No fix yet
Fix from $1,950 2023-11-14
Edge Chromium HIGH 7.3
CVE-2023-36014

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 119.0.2151.58+
Fix from $1,950 2023-11-10
Moodle CRITICAL 9.8
CVE-2023-5550

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the …

Fix: 3.9.24 / 3.11.17+
Fix from $2,300 2023-11-09
Moodle HIGH 8.8
CVE-2023-5540

A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

Fix: 3.9.24 / 3.11.17+
Fix from $1,950 2023-11-09
Moodle HIGH 8.8
CVE-2023-5539

A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

Fix: 3.9.24 / 3.11.17+
Fix from $1,950 2023-11-09
Webid CRITICAL 9.8
CVE-2023-47397

WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.

Fix: after 1.2.2
Fix from $2,300 2023-11-08
Helix Core CRITICAL 9.8
CVE-2023-45849

An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.

Fix: 2023.2+
Fix from $2,300 2023-11-08
Xwiki HIGH 8.8
CVE-2023-46243

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a use…

Fix: 14.10.6 / 15.2+
Fix from $1,950 2023-11-07
Xwiki HIGH 8.8
CVE-2023-46242

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execut…

Fix: 14.10.7 / 15.2+
Fix from $1,950 2023-11-07
Ec Cube HIGH 7.2
CVE-2023-46845

EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vul…

Fix: 4.2.3+
Fix from $1,950 2023-11-07
Xwiki CRITICAL 9.8
CVE-2023-46731EPSS 89%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section UR…

Fix: 14.10.14 / 15.5.1+
Fix from $2,300 2023-11-06
Pcrs CRITICAL 9.9
CVE-2023-46404

PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.

Fix: after 3.11
Fix from $2,300 2023-11-03
Best Courier Management System CRITICAL 9.8
CVE-2023-46980

An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to t…

No fix yet
Fix from $2,300 2023-11-03
Subrion HIGH 8.8
CVE-2023-46947

Subrion 4.2.1 has a remote command execution vulnerability in the backend.

No fix yet
Fix from $1,950 2023-11-03
Edge Chromium MEDIUM 6.6
CVE-2023-36022

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 118.0.2088.88 / 119.0.2151.44+
Fix from $1,600 2023-11-03
Lmxcms CRITICAL 9.8
CVE-2023-46958

An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.

Mitigation only
Fix from $2,300 2023-11-02
Secure Firewall Management Center HIGH 8.2
CVE-2023-20063

A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devic…

Fix: after 7.3.1.1
Fix from $1,950 2023-11-01
Automate HIGH 8.8
CVE-2023-40050

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with malicious…

Fix: after 4.10.29
Fix from $1,950 2023-10-31
Inspec HIGH 7.8
CVE-2023-42658

Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

Fix: 4.56.58 / 5.22.29+
Fix from $1,950 2023-10-31
Basercms CRITICAL 9.8
CVE-2023-43792

baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. A…

Fix: after 4.7.6
Fix from $2,300 2023-10-30