Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2023-29404 The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a… Go 1.19.10 / 1.20.5+ Fix from $2,3002023-06-08 CRITICAL 9.8 CVE-2023-29402 The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses… Go 1.19.10 / 1.20.5+ Fix from $2,3002023-06-08 CRITICAL 9.8 CVE-2023-34237 SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remote code execution. Manipulatin… Sabnzbd 4.0.2+ Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2020-36708EPSS 65% The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activell… Activello 1.0.6 / 1.1.2+ Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2023-32540 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file… Webaccess\/scada after 9.1.3 Fix from $2,3002023-06-06 HIGH 7.8 CVE-2023-33733 Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. Reportlab after 3.6.12 Fix from $1,9502023-06-05 HIGH 7.8 CVE-2023-27744 An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privilege escalation leading to remote code ex… Titan Ftp Server Nextgen 2.1.0.2174+ Fix from $1,9502023-06-02 HIGH 7.8 CVE-2022-35743 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.19387 / 10.0.14393.5291+ Fix from $1,9502023-05-31 CRITICAL 9.8 CVE-2023-25539 Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially … Networker 19.7.0.4+ Fix from $2,3002023-05-31 CRITICAL 9.8 CVE-2023-32692 CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. Th… Codeigniter 4.3.5+ Fix from $2,3002023-05-30 HIGH 8.8 CVE-2023-2943 Code Injection in GitHub repository openemr/openemr prior to 7.0.1. Openemr 7.0.1+ Fix from $1,9502023-05-27 HIGH 8.8 CVE-2023-2928EPSS 51% A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t… Dedecms after 5.7.106 Fix from $1,9502023-05-27 HIGH 7.2 CVE-2023-33440EPSS 15% Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. Faculty Evaluation System No fix yet Fix from $1,9502023-05-26 CRITICAL 9.8 CVE-2023-30145EPSS 46% Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. Camaleon Cms after 2.7.0 Fix from $2,3002023-05-26 CRITICAL 9.8 CVE-2023-33246 KEVEPSS 97% For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, inclu… Rocketmq 4.9.6 / 5.1.1+ Fix from $2,3002023-05-24 HIGH 8.8 CVE-2023-2859 Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Teampass 3.0.9+ Fix from $1,9502023-05-24 CRITICAL 9.8 CVE-2023-32697 SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JD… Sqlite Jdbc 3.41.2.2+ Fix from $2,3002023-05-23 CRITICAL 9.8 CVE-2023-25953 Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected… Drive Explorer after 3.5.4 Fix from $2,3002023-05-23 CRITICAL 9.8 CVE-2023-29861 An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of… Dvtel Camera Firmware No fix yet Fix from $2,3002023-05-15 CRITICAL 9.8 CVE-2023-29862 An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameter… Agasio Camera Firmware No fix yet Fix from $2,3002023-05-15 HIGH 7.5 CVE-2022-47879EPSS 6% A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the… Jedox No fix yet Fix from $1,9502023-05-12 HIGH 8.8 CVE-2023-30130 An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter. Craft Cms No fix yet Fix from $1,9502023-05-12 HIGH 7.3 CVE-2023-24539 Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/'… Go 1.19.9 / 1.20.4+ Fix from $1,9502023-05-11 HIGH 7.3 CVE-2023-29400 Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results w… Go 1.19.9 / 1.20.4+ Fix from $1,9502023-05-11 CRITICAL 9.8 CVE-2022-47129 PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability. Phpok No fix yet Fix from $2,3002023-05-11 HIGH 7.2 CVE-2023-24955 KEVEPSS 85% Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Enterprise Server Patch available Fix from $1,9502023-05-09 CRITICAL 10.0 CVE-2023-2583 Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3. Jsreport 3.11.3+ Fix from $2,3002023-05-08 HIGH 7.2 CVE-2023-29963 S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php. S Cms No fix yet Fix from $1,9502023-05-05 HIGH 8.8 CVE-2023-31414 Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could… Kibana after 8.7.0 Fix from $1,9502023-05-04 HIGH 8.8 CVE-2023-31415 Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request… Kibana Mitigation only Fix from $1,9502023-05-04