Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-33570
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
Bagisto
No fix yet
CRITICAL 9.8
CVE-2023-27866
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using th…
Informix Jdbc Driver
4.50.10+
HIGH 8.8
CVE-2023-36467
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1…
Aws Dataall
after 1.5.1
HIGH 8.8
CVE-2023-32527
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affec…
Mobile Security
Patch available
HIGH 8.8
CVE-2023-32528
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affec…
Mobile Security
Patch available
CRITICAL 9.8
CVE-2021-31635
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Jfinal
Mitigation only
HIGH 7.2
CVE-2023-3393
Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.
Fossbilling
0.5.1+
HIGH 8.0
CVE-2023-35150EPSS 78%
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to ver…
Xwiki
14.4.8 / 14.10.4+
HIGH 8.8
CVE-2023-35152
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add …
Xwiki
14.4.8 / 14.10.6+
CRITICAL 9.9
CVE-2023-35926
Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox…
Backstage
1.15.0+
HIGH 7.2
CVE-2020-20918
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when edit…
Pluck
Patch available
HIGH 8.8
CVE-2023-26436
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserializa…
Open Xchange Appsuite Backend
7.10.6+
HIGH 8.8
CVE-2023-2359
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may…
Slider Revolution
after 6.6.12
CRITICAL 9.8
CVE-2023-35853
In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by …
Suricata
6.0.13+
CRITICAL 9.8
CVE-2023-35813EPSS 87%
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.
Experience Commerce
after 10.3
HIGH 8.8
CVE-2023-35809
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the RES…
Sugarcrm
11.0.6 / 12.0.3+
HIGH 7.2
CVE-2023-34253
Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from …
Grav
1.7.42+
HIGH 7.2
CVE-2023-34448
Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability i…
Grav
1.7.42+
HIGH 7.2
CVE-2023-34251
Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is po…
Grav
1.7.42+
HIGH 7.2
CVE-2023-34252
Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby …
Grav
1.7.42+
HIGH 7.8
CVE-2023-1049
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause execution of malicious code when an unsuspi…
Ecostruxure Operator Terminal Expert
3.3+
HIGH 8.8
CVE-2023-33131EPSS 6%
Microsoft Outlook Remote Code Execution Vulnerability
Office
Patch available
MEDIUM 5.5
CVE-2023-21569
Azure DevOps Server Spoofing Vulnerability
Azure Devops Server
Patch available
CRITICAL 9.8
CVE-2023-3224EPSS 59%
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
Nuxt
3.4.3+
HIGH 7.2
CVE-2023-30179
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Loca…
Craft Cms
Patch available
HIGH 8.8
CVE-2023-25910
A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All …
Simatic Pcs 7
5.7+
HIGH 8.8
CVE-2023-34468EPSS 64%
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user …
Nifi
1.22.0+
CRITICAL 9.8
CVE-2023-35034
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code…
Unify Openscape 4000 Assistant
Mitigation only
HIGH 7.8
CVE-2019-16283
A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.
Softpaq Installer
No fix yet
HIGH 8.8
CVE-2023-34112
JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/javacpp-presets` use the `github.…
Javacpp Presets
1.5.9+