Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.3 CVE-2023-36592 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Windows 10 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 HIGH 7.3 CVE-2023-36570 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 HIGH 7.3 CVE-2023-36571 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 HIGH 7.3 CVE-2023-36572 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 HIGH 7.3 CVE-2023-36573 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 HIGH 7.3 CVE-2023-36574 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 HIGH 7.3 CVE-2023-36575 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 CRITICAL 9.8 CVE-2023-43625 A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow … Simcenter Amesim 2021.1+ Fix from $2,3002023-10-10 HIGH 8.8 CVE-2023-44846 An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component. Seacms after 12.8 Fix from $1,9502023-10-10 HIGH 7.2 CVE-2023-44847 An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component. Seacms after 12.8 Fix from $1,9502023-10-10 CRITICAL 9.0 CVE-2023-44392 Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library… Garden 0.12.65 / 0.13.17+ Fix from $2,3002023-10-09 CRITICAL 9.8 CVE-2023-45311 fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary c… Fsevents 1.2.11+ Fix from $2,3002023-10-06 HIGH 7.8 CVE-2023-35897 IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary c… Storage Protect after 8.1.19.0 Fix from $1,9502023-10-06 HIGH 7.8 CVE-2023-3665 A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via envir… Endpoint Security after 10.7.0 Fix from $1,9502023-10-04 CRITICAL 9.8 CVE-2023-3656 cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticat… Cashit\! after 03.a06rks_2023.02.37 Fix from $2,3002023-10-03 CRITICAL 9.8 CVE-2023-44011 An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin m… Mojoportal No fix yet Fix from $2,3002023-10-02 HIGH 8.8 CVE-2023-5201 The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows… Openhook after 4.3.0 Fix from $1,9502023-09-30 HIGH 8.1 CVE-2023-26145 This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_ma… Pydash 6.0.0+ Fix from $1,9502023-09-28 HIGH 8.8 CVE-2023-38877 A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host… Economizzer No fix yet Fix from $1,9502023-09-28 HIGH 7.8 CVE-2023-41444 An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 fun… Irec after 3.11.0 Fix from $1,9502023-09-28 HIGH 8.8 CVE-2023-41450 An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. Ajaxnewsticker Mitigation only Fix from $1,9502023-09-28 CRITICAL 9.9 CVE-2023-43651 JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leadi… Jumpserver 2.28.20 / 3.7.1+ Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-5221 A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/index.php. The manipulation of t… Foru Cms No fix yet Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-43222 SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. Seacms 12.8+ Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-43234 DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath … Dedebiz Mitigation only Fix from $2,3002023-09-27 HIGH 7.8 CVE-2023-41984 The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 1… Ipados 10.0 / 12.7+ Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2021-38243 xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to ex… Xunruicms after 4.5.1 Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-0625 Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0. Docker Desktop 4.12.0+ Fix from $2,3002023-09-25 CRITICAL 9.8 CVE-2023-0626 Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0. Docker Desktop 4.12.0+ Fix from $2,3002023-09-25 CRITICAL 9.8 CVE-2023-43270 dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate. Dst Admin No fix yet Fix from $2,3002023-09-22