Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2023-33570 Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI). Bagisto No fix yet Fix from $1,9502023-06-28 CRITICAL 9.8 CVE-2023-27866 IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using th… Informix Jdbc Driver 4.50.10+ Fix from $2,3002023-06-28 HIGH 8.8 CVE-2023-36467 AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1… Aws Dataall after 1.5.1 Fix from $1,9502023-06-28 HIGH 8.8 CVE-2023-32527 Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affec… Mobile Security Patch available Fix from $1,9502023-06-26 HIGH 8.8 CVE-2023-32528 Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affec… Mobile Security Patch available Fix from $1,9502023-06-26 CRITICAL 9.8 CVE-2021-31635 Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function. Jfinal Mitigation only Fix from $2,3002023-06-26 HIGH 7.2 CVE-2023-3393 Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1. Fossbilling 0.5.1+ Fix from $1,9502023-06-23 HIGH 8.0 CVE-2023-35150EPSS 78% XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to ver… Xwiki 14.4.8 / 14.10.4+ Fix from $1,9502023-06-23 HIGH 8.8 CVE-2023-35152 XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add … Xwiki 14.4.8 / 14.10.6+ Fix from $1,9502023-06-23 CRITICAL 9.9 CVE-2023-35926 Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox… Backstage 1.15.0+ Fix from $2,3002023-06-22 HIGH 7.2 CVE-2020-20918 An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when edit… Pluck Patch available Fix from $1,9502023-06-20 HIGH 8.8 CVE-2023-26436 Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserializa… Open Xchange Appsuite Backend 7.10.6+ Fix from $1,9502023-06-20 HIGH 8.8 CVE-2023-2359 The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may… Slider Revolution after 6.6.12 Fix from $1,9502023-06-19 CRITICAL 9.8 CVE-2023-35853 In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by … Suricata 6.0.13+ Fix from $2,3002023-06-19 CRITICAL 9.8 CVE-2023-35813EPSS 87% Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. Experience Commerce after 10.3 Fix from $2,3002023-06-17 HIGH 8.8 CVE-2023-35809 An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the RES… Sugarcrm 11.0.6 / 12.0.3+ Fix from $1,9502023-06-17 HIGH 7.2 CVE-2023-34253 Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from … Grav 1.7.42+ Fix from $1,9502023-06-14 HIGH 7.2 CVE-2023-34448 Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability i… Grav 1.7.42+ Fix from $1,9502023-06-14 HIGH 7.2 CVE-2023-34251 Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is po… Grav 1.7.42+ Fix from $1,9502023-06-14 HIGH 7.2 CVE-2023-34252 Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby … Grav 1.7.42+ Fix from $1,9502023-06-14 HIGH 7.8 CVE-2023-1049 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspi… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502023-06-14 HIGH 8.8 CVE-2023-33131EPSS 6% Microsoft Outlook Remote Code Execution Vulnerability Office Patch available Fix from $1,9502023-06-14 MEDIUM 5.5 CVE-2023-21569 Azure DevOps Server Spoofing Vulnerability Azure Devops Server Patch available Fix from $1,6002023-06-14 CRITICAL 9.8 CVE-2023-3224EPSS 59% Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3. Nuxt 3.4.3+ Fix from $2,3002023-06-13 HIGH 7.2 CVE-2023-30179 CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Loca… Craft Cms Patch available Fix from $1,9502023-06-13 HIGH 8.8 CVE-2023-25910 A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All … Simatic Pcs 7 5.7+ Fix from $1,9502023-06-13 HIGH 8.8 CVE-2023-34468EPSS 64% The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user … Nifi 1.22.0+ Fix from $1,9502023-06-12 CRITICAL 9.8 CVE-2023-35034 Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code… Unify Openscape 4000 Assistant Mitigation only Fix from $2,3002023-06-12 HIGH 7.8 CVE-2019-16283 A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution. Softpaq Installer No fix yet Fix from $1,9502023-06-09 HIGH 8.8 CVE-2023-34112 JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/javacpp-presets` use the `github.… Javacpp Presets 1.5.9+ Fix from $1,9502023-06-09