Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2023-31447 user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to m… Vigor2620 Firmware 3.9.8.4+ Fix from $2,3002023-08-21 HIGH 8.8 CVE-2023-39445 Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitr… Wrc 1467ghbk A Firmware Mitigation only Fix from $1,9502023-08-18 HIGH 8.0 CVE-2023-38576 Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbitrary OS… Lan Wh300n\/re Firmware Mitigation only Fix from $1,9502023-08-18 CRITICAL 9.8 CVE-2023-32626 Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the p… Lan W300n\/rs Firmware Mitigation only Fix from $2,3002023-08-18 HIGH 8.8 CVE-2023-40313 A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow… Horizon 32.0.2 / 2020.1.38+ Fix from $1,9502023-08-17 HIGH 8.8 CVE-2023-37914 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` c… Xwiki 14.4.8 / 14.10.6+ Fix from $1,9502023-08-17 CRITICAL 9.8 CVE-2023-40252 Improper Control of Generation of Code ('Code Injection') vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite… Genian Nac 4.0.156 / 5.0.55+ Fix from $2,3002023-08-17 HIGH 7.2 CVE-2023-20209EPSS 41% A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow … Telepresence Video Communication Server 14.3.1+ Fix from $1,9502023-08-16 CRITICAL 9.8 CVE-2023-38860 An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter. Langchain No fix yet Fix from $2,3002023-08-15 CRITICAL 9.8 CVE-2023-38889 An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.Com… Alluxio after 2.9.3 Fix from $2,3002023-08-15 HIGH 7.8 CVE-2023-33469 In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior… Via Go2 Firmware 4.0.1.1326+ Fix from $1,9502023-08-09 HIGH 7.8 CVE-2023-36923 SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious… Powerdesigner Mitigation only Fix from $1,9502023-08-08 CRITICAL 9.8 CVE-2023-36095 An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected funct… Langchain Mitigation only Fix from $2,3002023-08-05 HIGH 8.8 CVE-2023-38943 ShuiZe_0x727 v1.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /iniFile/config.ini. Shuize 0x727 No fix yet Fix from $1,9502023-08-05 CRITICAL 9.8 CVE-2023-37470 Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3… Metabase 0.43.7.3 / 0.44.7.3+ Fix from $2,3002023-08-04 HIGH 8.8 CVE-2023-4141 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' par… Wp Ultimate Csv Importer after 7.9.8 Fix from $1,9502023-08-04 HIGH 8.8 CVE-2023-4142 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' par… Wp Ultimate Csv Importer after 7.9.8 Fix from $1,9502023-08-04 HIGH 8.8 CVE-2023-36255EPSS 53% An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter… Eramba Mitigation only Fix from $1,9502023-08-03 MEDIUM 6.5 CVE-2023-3401 An issue has been discovered in GitLab affecting all versions before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting fro… GitLab 16.0.8 / 16.1.3+ Fix from $1,6002023-08-02 CRITICAL 9.8 CVE-2023-34644 Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series … Rg Ew1200r Firmware Patch available Fix from $2,3002023-07-31 CRITICAL 9.8 CVE-2023-34842 Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.ph… Dedecms after 5.7.109 Fix from $2,3002023-07-31 HIGH 8.8 CVE-2023-36542 Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an … Nifi after 1.22.0 Fix from $1,9502023-07-29 CRITICAL 9.8 CVE-2023-39016 bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLM… Bboss after 6.0.9 Fix from $2,3002023-07-28 CRITICAL 9.8 CVE-2023-39017 quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.exec… Quartz after 2.3.2 Fix from $2,3002023-07-28 CRITICAL 9.8 CVE-2023-39018 FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerab… Ffmpeg Cli Wrapper after 0.7.0 Fix from $2,3002023-07-28 CRITICAL 9.8 CVE-2023-39020 stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStre… Stanford Parser 4.5.5+ Fix from $2,3002023-07-28 CRITICAL 9.8 CVE-2023-39021 wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply.… Wix Embedded Mysql after 4.6.1 Fix from $2,3002023-07-28 CRITICAL 9.8 CVE-2023-39022 oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. Thi… Oscore after 2.2.6 Fix from $2,3002023-07-28 CRITICAL 9.8 CVE-2023-39023 university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecut… University Compass after 2.2.0 Fix from $2,3002023-07-28 CRITICAL 9.8 CVE-2023-39010 BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability i… Boofcv No fix yet Fix from $2,3002023-07-28