Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2023-4291 Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability vi… Frauscher Diagnostic System 101 after 1.4.24 Fix from $2,3002023-09-21 CRITICAL 9.1 CVE-2023-0462 An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste… Satellite 3.8.0+ Fix from $2,3002023-09-20 HIGH 8.8 CVE-2023-22513EPSS 14% This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Co… Bitbucket Data Center 8.9.5 / 8.10.5+ Fix from $1,9502023-09-19 HIGH 7.2 CVE-2023-41179 KEV A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-F… Apex One Mitigation only Fix from $1,9502023-09-19 HIGH 8.8 CVE-2023-40221 The absence of filters when loading some sections in the web application of the vulnerable device allows potential attackers to inject malicious code… Modulys Gp Firmware Mitigation only Fix from $1,9502023-09-18 HIGH 7.8 CVE-2023-34195 An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage met… Insydeh2o 5.2.05.28.22 / 5.3.05.37.22+ Fix from $1,9502023-09-18 HIGH 7.2 CVE-2023-34999 A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perfo… Rts Vlink Virtual Matrix 5.7.6 / 6.5.0+ Fix from $1,9502023-09-18 MEDIUM 6.4 CVE-2023-4994 The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' sh… Allow Php In Posts And Pages after 3.0.4 Fix from $1,6002023-09-16 MEDIUM 5.4 CVE-2023-4977 Code Injection in GitHub repository librenms/librenms prior to 23.9.0. Librenms 23.9.0+ Fix from $1,6002023-09-15 CRITICAL 9.8 CVE-2023-41892EPSS 93% Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations befo… Craft Cms 4.4.15+ Fix from $2,3002023-09-13 MEDIUM 6.3 CVE-2023-40621 SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecti… Powerdesigner Mitigation only Fix from $1,6002023-09-12 CRITICAL 9.8 CVE-2023-42470 The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported comp… Life after 6.8.0 Fix from $2,3002023-09-11 CRITICAL 9.8 CVE-2023-42471 The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It con… Wave after 1.0.35 Fix from $2,3002023-09-11 CRITICAL 9.8 CVE-2023-39320 The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "… Go 1.21.1+ Fix from $2,3002023-09-08 MEDIUM 6.6 CVE-2023-39956 Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as c… Electron 22.3.9 / 23.3.13+ Fix from $1,6002023-09-06 MEDIUM 6.4 CVE-2023-38484 Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbit… Arubaos 8.6.0.22 / 8.10.0.7+ Fix from $1,6002023-09-06 HIGH 7.2 CVE-2023-41319 Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcem… Fides 2.19.0+ Fix from $1,9502023-09-06 CRITICAL 9.8 CVE-2023-39681 Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vul… Cuppacms No fix yet Fix from $2,3002023-09-05 HIGH 8.8 CVE-2022-41763 An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to… Access Management System No fix yet Fix from $1,9502023-09-05 CRITICAL 9.8 CVE-2023-39631 An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library. Langchain Patch available Fix from $2,3002023-09-01 CRITICAL 9.8 CVE-2020-22612 Installer RCE on settings file write in MyBB before 1.8.22. Mybb 1.8.22+ Fix from $2,3002023-09-01 HIGH 7.5 CVE-2023-39685 An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string. Hjson after 3.0.0 Fix from $1,9502023-09-01 HIGH 7.2 CVE-2023-41362 MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some vali… Mybb 1.8.36+ Fix from $1,9502023-08-29 HIGH 7.8 CVE-2023-41005 An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateCont… Pagekit No fix yet Fix from $1,9502023-08-28 HIGH 8.8 CVE-2023-39059 An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter. Ansible Semaphore No fix yet Fix from $1,9502023-08-28 HIGH 8.8 CVE-2023-40177 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content fiel… Xwiki 14.10.5+ Fix from $1,9502023-08-23 HIGH 7.2 CVE-2023-37427 A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrar… Edgeconnect Sd Wan Orchestrator after 9.2.5 Fix from $1,9502023-08-22 CRITICAL 9.8 CVE-2023-36281 An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ … Langchain No fix yet Fix from $2,3002023-08-22 HIGH 8.1 CVE-2023-37424 A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitr… Edgeconnect Sd Wan Orchestrator after 9.2.5 Fix from $1,9502023-08-22 CRITICAL 9.8 CVE-2023-39660 An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt func… Pandasai after 0.8.0 Fix from $2,3002023-08-21