Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.8 CVE-2022-27537 Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation o… Dragonfly Folio G3 2 In 1 Firmware No fix yet Fix from $1,9502023-02-01 CRITICAL 9.8 CVE-2022-48175 Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/aja… Rukovoditel No fix yet Fix from $2,3002023-01-30 HIGH 8.8 CVE-2022-25967 Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with vi… Eta 2.0.0+ Fix from $1,9502023-01-30 HIGH 8.8 CVE-2021-4315 A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unknown code of the file psiturk/… Psiturk 3.2.1+ Fix from $1,9502023-01-28 HIGH 7.2 CVE-2022-48116 AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php. Ayacms No fix yet Fix from $1,9502023-01-27 HIGH 8.8 CVE-2023-23619 Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vul… Modelina 1.0.0+ Fix from $1,9502023-01-26 CRITICAL 9.8 CVE-2022-25860 Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() metho… Simple Git 3.16.0+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2022-25894 All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.create… Uflo No fix yet Fix from $2,3002023-01-26 HIGH 7.3 CVE-2023-24059 Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023. Grand Theft Auto V No fix yet Fix from $1,9502023-01-22 HIGH 8.8 CVE-2020-36655 Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbit… Gii 2.2.2+ Fix from $1,9502023-01-21 HIGH 8.0 CVE-2021-37774 An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code. Tl Wdr7660 Firmware No fix yet Fix from $1,9502023-01-19 HIGH 8.8 CVE-2022-45928 A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the… Opentext Extended Ecm after 22.3 Fix from $1,9502023-01-18 HIGH 8.8 CVE-2022-34456 Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially explo… Emc Metro Node 7.1+ Fix from $1,9502023-01-18 HIGH 8.1 CVE-2023-21886 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.… Vm Virtualbox 6.1.42 / 7.0.6+ Fix from $1,9502023-01-18 CRITICAL 9.8 CVE-2023-21890 Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that … Communications Converged Application Server Patch available Fix from $2,3002023-01-18 HIGH 8.8 CVE-2023-22731 Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is po… Shopware 6.4.18.1+ Fix from $1,9502023-01-17 HIGH 8.0 CVE-2022-46648 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con… Debian Linux 1.13.0+ Fix from $1,9502023-01-17 HIGH 8.0 CVE-2022-47318 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository con… Debian Linux 1.13.0+ Fix from $1,9502023-01-17 CRITICAL 9.8 CVE-2023-0297EPSS 96% Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. Pyload after 0.4.20 Fix from $2,3002023-01-14 HIGH 8.8 CVE-2023-22853 Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval. Tiki 24.1+ Fix from $1,9502023-01-14 HIGH 7.8 CVE-2022-42268 Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications all… Nvidia Isaac Sim 2022.2 / 2022.2.0+ Fix from $1,9502023-01-13 HIGH 8.8 CVE-2023-22952 KEVEPSS 80% In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. Sugarcrm 11.0.5 / 12.0.2+ Fix from $1,9502023-01-11 HIGH 8.8 CVE-2023-0022 SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502023-01-10 HIGH 7.8 CVE-2022-25926 Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization. Window Control 1.4.5+ Fix from $1,9502023-01-04 HIGH 8.8 CVE-2023-0048EPSS 32% Code Injection in GitHub repository lirantal/daloradius prior to master-branch. Daloradius 2023-01-04+ Fix from $1,9502023-01-04 CRITICAL 9.8 CVE-2015-10009 A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getContent of the file app/contro… Nterchange 4.1.1+ Fix from $2,3002023-01-02 HIGH 8.8 CVE-2022-46874 A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This cou… Firefox 102.6 / 108.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-22756 If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable s… Firefox 91.6 / 97.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-46101 AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious cod… Ayacms No fix yet Fix from $1,9502022-12-22 HIGH 7.8 CVE-2022-47896 In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. Intellij Idea 2022.3.1+ Fix from $1,9502022-12-22