Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.8 CVE-2023-27770 An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_fu… Edraw Max No fix yet Fix from $1,9502023-04-04 HIGH 8.8 CVE-2022-43938EPSS 26% Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disab… Vantara Pentaho Business Analytics Server 9.3.0.2+ Fix from $1,9502023-04-03 MEDIUM 6.3 CVE-2022-3960 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disab… Vantara Pentaho Business Analytics Server 9.3.0.2+ Fix from $1,6002023-04-03 HIGH 7.2 CVE-2022-43769 KEVEPSS 98% Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property v… Vantara Pentaho Business Analytics Server 9.3.0.2+ Fix from $1,9502023-04-03 CRITICAL 9.8 CVE-2023-26119 Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsi… Htmlunit 3.0.0+ Fix from $2,3002023-04-03 CRITICAL 9.8 CVE-2023-1773 A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of… Rockoa Mitigation only Fix from $2,3002023-03-31 CRITICAL 9.8 CVE-2023-25261 Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer … Designer Mitigation only Fix from $2,3002023-03-27 HIGH 7.2 CVE-2023-24835 Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with admi… Spam Sqr 2.221231+ Fix from $1,9502023-03-27 HIGH 7.8 CVE-2022-38745 Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code fro… Openoffice 4.1.14+ Fix from $1,9502023-03-24 CRITICAL 9.8 CVE-2023-28333 The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploi… Moodle 3.9.20 / 3.11.13+ Fix from $2,3002023-03-23 HIGH 7.5 CVE-2023-24709EPSS 44% An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters. Ipr512 Firmware No fix yet Fix from $1,9502023-03-21 HIGH 8.8 CVE-2023-1304 An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are nor… Insightappsec 23.2.1 / 2023.02.01+ Fix from $1,9502023-03-21 HIGH 8.8 CVE-2023-1306 An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead t… Insightappsec 23.2.1 / 2023.02.01+ Fix from $1,9502023-03-21 HIGH 7.8 CVE-2023-1250 Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Cod… Otrs 7.0.42 / 8.0.31+ Fix from $1,9502023-03-20 HIGH 8.8 CVE-2023-1482 A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. This affects an unknown part of the file /admin.php/appcenter/… Hkcms No fix yet Fix from $1,9502023-03-18 CRITICAL 9.8 CVE-2023-0598 GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an att… Ifix Mitigation only Fix from $2,3002023-03-16 CRITICAL 9.8 CVE-2023-24795 Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483. Jhr N916r Firmware after 21.11.1.1483 Fix from $2,3002023-03-16 CRITICAL 9.8 CVE-2023-25344 An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype ano… Swig Templates after 2.0.4 Fix from $2,3002023-03-15 HIGH 8.8 CVE-2023-27893 An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP manag… Solution Manager Mitigation only Fix from $1,9502023-03-14 HIGH 7.2 CVE-2023-0888 An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and … Battery Pack Sp With Wifi Firmware after 054u000092 Fix from $1,9502023-03-13 CRITICAL 9.8 CVE-2023-1287 An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution. Enovia Live Collaboration No fix yet Fix from $2,3002023-03-09 HIGH 7.8 CVE-2023-27986 emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-q… Emacs after 28.2 Fix from $1,9502023-03-09 CRITICAL 9.8 CVE-2023-1283 Code Injection in GitHub repository builderio/qwik prior to 0.21.0. Qwik 0.21.0+ Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-22889 SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauth… Zephyr Enterprise after 7.15 Fix from $2,3002023-03-08 HIGH 8.8 CVE-2023-0089 The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through '… Enterprise Protection 8.13.22 / 8.18.4+ Fix from $1,9502023-03-08 CRITICAL 9.8 CVE-2023-0090 The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code throug… Enterprise Protection 8.13.22 / 8.18.4+ Fix from $2,3002023-03-08 HIGH 7.8 CVE-2023-1003 A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH J… Typora after 1.5.5 Fix from $1,9502023-03-07 CRITICAL 9.8 CVE-2021-36394EPSS 7% In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. Moodle 3.9.8 / 3.10.5+ Fix from $2,3002023-03-06 CRITICAL 9.8 CVE-2023-24776 Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php. Funadmin No fix yet Fix from $2,3002023-03-06 HIGH 7.8 CVE-2023-26107 All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization wh… Sketchsvg No fix yet Fix from $1,9502023-03-06