Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2022-45553 An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connectio… We1626 Firmware Mitigation only Fix from $2,3002023-03-03 HIGH 8.8 CVE-2023-22381 A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environm… Enterprise Server 3.4.15 / 3.5.12+ Fix from $1,9502023-03-02 CRITICAL 9.8 CVE-2023-26477EPSS 75% XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, P… Xwiki 13.10.10 / 14.4.6+ Fix from $2,3002023-03-02 CRITICAL 9.8 CVE-2023-1097 Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Comman… Eg7035 M11 Firmware Mitigation only Fix from $2,3002023-03-01 HIGH 8.8 CVE-2023-23496 The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS… Safari 9.3 / 13.2+ Fix from $1,9502023-02-27 MEDIUM 6.1 CVE-2023-1030 A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vul… Online Boat Reservation System No fix yet Fix from $1,6002023-02-24 HIGH 7.8 CVE-2023-1005 A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown functionality. The manipulat… Markdown Electron No fix yet Fix from $1,9502023-02-24 HIGH 7.8 CVE-2023-1004 A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functiona… Marktext after 0.17.1 Fix from $1,9502023-02-24 CRITICAL 9.8 CVE-2023-24114 typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. Typecho 1.2.0+ Fix from $2,3002023-02-22 CRITICAL 9.8 CVE-2023-24107 hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package … Hour Of Code Python 2015 No fix yet Fix from $2,3002023-02-22 CRITICAL 9.8 CVE-2023-25657 Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions earlier than 1.5.7 are impacted by a remote cod… Nautobot 1.5.7+ Fix from $2,3002023-02-21 HIGH 8.8 CVE-2022-46836 PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an atta… Checkmk No fix yet Fix from $1,9502023-02-20 CRITICAL 9.8 CVE-2021-26277 The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions. Frame Service 2021.6.30+ Fix from $2,3002023-02-17 CRITICAL 9.8 CVE-2021-33949 An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function. Wms No fix yet Fix from $2,3002023-02-17 HIGH 8.8 CVE-2023-24078EPSS 53% Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. Fuguhub after 8.1 Fix from $1,9502023-02-17 HIGH 8.8 CVE-2023-0877 Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11. Froxlor 2.0.11+ Fix from $1,9502023-02-17 CRITICAL 9.8 CVE-2023-22855EPSS 15% Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path i… Kardex Control Center No fix yet Fix from $2,3002023-02-15 HIGH 7.5 CVE-2023-21553 Azure DevOps Server Remote Code Execution Vulnerability Azure Devops Server Patch available Fix from $1,9502023-02-14 CRITICAL 9.8 CVE-2023-25717 KEVEPSS 98% Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_us… Ruckus Wireless Admin 3.6.2.0.795 / 5.2.1.3+ Fix from $2,3002023-02-13 CRITICAL 9.8 CVE-2023-23551 Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code. X 600m Firmware 1.16.00+ Fix from $2,3002023-02-13 CRITICAL 9.8 CVE-2023-0788 Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. Phpmyfaq 3.1.11+ Fix from $2,3002023-02-12 MEDIUM 5.4 CVE-2023-0792 Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. Phpmyfaq 3.1.11+ Fix from $1,6002023-02-12 CRITICAL 9.8 CVE-2022-45699EPSS 77% Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary comma… Ecu R Firmware No fix yet Fix from $2,3002023-02-10 HIGH 8.8 CVE-2023-23912 A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCP… Usg Firmware 2.0.9 / 4.4.57+ Fix from $1,9502023-02-09 CRITICAL 9.8 CVE-2023-0575 External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Win… Yugabytedb 2.2.0.0+ Fix from $2,3002023-02-09 HIGH 8.8 CVE-2023-0671 Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10. Froxlor 2.0.10+ Fix from $1,9502023-02-04 CRITICAL 9.8 CVE-2023-24576 EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsre… Emc Networker after 19.8 Fix from $2,3002023-02-03 CRITICAL 9.8 CVE-2023-23477 IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially craft… Websphere Application Server Mitigation only Fix from $2,3002023-02-03 CRITICAL 9.8 CVE-2021-36424 An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation. Phpwcms 1.9.26+ Fix from $2,3002023-02-03 HIGH 7.2 CVE-2022-48093 Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php. Seacms No fix yet Fix from $1,9502023-02-01