Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.7 CVE-2023-1178 An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all vers… GitLab 15.9.6 / 15.10.5+ Fix from $1,6002023-05-03 HIGH 8.8 CVE-2023-26546 European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) … Iuclid 6.27.6+ Fix from $1,9502023-05-02 MEDIUM 6.5 CVE-2023-26782 An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cach… Mccms No fix yet Fix from $1,6002023-04-28 CRITICAL 9.8 CVE-2023-30349 JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function. Jfinal Cms No fix yet Fix from $2,3002023-04-27 CRITICAL 9.8 CVE-2023-30404 Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in t… Wireless N Repeater Mini Router Firmware Mitigation only Fix from $2,3002023-04-26 HIGH 7.2 CVE-2023-2259 Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. Alf 2.0-m4-2304+ Fix from $1,9502023-04-24 CRITICAL 9.8 CVE-2023-29566 huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the ch… Dawnsparks Node Tesseract Patch available Fix from $2,3002023-04-24 HIGH 8.8 CVE-2023-26060 An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a clie… Netact 20.1+ Fix from $1,9502023-04-24 HIGH 7.2 CVE-2022-36963EPSS 8% The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds … Orion Platform 2023.2+ Fix from $1,9502023-04-21 CRITICAL 9.8 CVE-2023-25549 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter… Struxureware Data Center Expert after 7.9.2 Fix from $2,3002023-04-18 CRITICAL 9.8 CVE-2023-25550 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” paramet… Struxureware Data Center Expert after 7.9.2 Fix from $2,3002023-04-18 HIGH 8.8 CVE-2023-2017 Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform … Shopware after 6.4.20.0 Fix from $1,9502023-04-17 HIGH 8.8 CVE-2023-29509EPSS 76% XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents ca… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-04-16 HIGH 8.8 CVE-2023-30537 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on … Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-04-16 HIGH 8.8 CVE-2023-29212 XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Pytho… Xwiki 14.4.7+ Fix from $1,9502023-04-16 HIGH 8.8 CVE-2023-29214 XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Pytho… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-04-16 HIGH 8.8 CVE-2023-29211 XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execut… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-04-16 CRITICAL 9.8 CVE-2020-29007 The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. … Score after 0.3.0 Fix from $2,3002023-04-15 HIGH 8.8 CVE-2023-29209 XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents in… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-04-15 HIGH 8.8 CVE-2023-29210 XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents in… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-04-15 CRITICAL 9.8 CVE-2023-2056 A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.p… Dedecms after 5.7.87 Fix from $2,3002023-04-14 HIGH 7.2 CVE-2023-30638 Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated ad… Unify Openscape Bcf 10r3.1.2 / 10r3.1.3+ Fix from $1,9502023-04-14 CRITICAL 9.8 CVE-2023-29492 KEV Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not pro… Novi Survey 8.9.43676+ Fix from $2,3002023-04-11 MEDIUM 6.3 CVE-2023-27897 In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authoriz… Customer Relationship Management Mitigation only Fix from $1,6002023-04-11 CRITICAL 9.8 CVE-2023-27650 An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter. Launcher No fix yet Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-1947 A vulnerability was found in taoCMS 3.0.2. It has been classified as critical. Affected is an unknown function of the file /admin/admin.php. The mani… Taocms No fix yet Fix from $2,3002023-04-07 CRITICAL 9.8 CVE-2023-28706 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects… Airflow Hive Provider 6.0.0+ Fix from $2,3002023-04-07 HIGH 8.8 CVE-2023-26817 codefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the component /controllers/api/use… Codefever 2023-02-07+ Fix from $1,9502023-04-07 CRITICAL 9.8 CVE-2023-24538 Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, … Go 1.19.8 / 1.20.3+ Fix from $2,3002023-04-06 CRITICAL 9.8 CVE-2023-1708 An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-p… GitLab 15.8.5 / 15.9.4+ Fix from $2,3002023-04-05