Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.8 CVE-2022-36036 mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 a… Mdx Mermaid 1.3.0+ Fix from $1,9502022-08-29 CRITICAL 9.8 CVE-2022-36756 DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php. Dir 845l Firmware after 1.0.3 Fix from $2,3002022-08-28 CRITICAL 9.8 CVE-2022-37053 TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php. Tew733gr Firmware Mitigation only Fix from $2,3002022-08-28 CRITICAL 9.8 CVE-2022-38078 Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to … Movable Type 1.53 / 6.8.7+ Fix from $2,3002022-08-24 HIGH 7.2 CVE-2022-25812 The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege use… Transposh Wordpress Translation 1.0.8+ Fix from $1,9502022-08-22 CRITICAL 9.8 CVE-2022-35516 DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php. Dedecms after 5.7.96 Fix from $2,3002022-08-17 HIGH 7.2 CVE-2022-36216 DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php. Dedecms after 5.7.97 Fix from $1,9502022-08-17 CRITICAL 9.6 CVE-2022-38193 There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass… Portal For Arcgis after 10.8.1 Fix from $2,3002022-08-16 CRITICAL 9.8 CVE-2022-36262 An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php. Taocms Mitigation only Fix from $2,3002022-08-15 HIGH 8.8 CVE-2022-36006 Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execut… Arvados 2.4.2+ Fix from $1,9502022-08-15 HIGH 7.8 CVE-2022-30580 Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com"… Go 1.17.11 / 1.18.3+ Fix from $1,9502022-08-10 HIGH 8.1 CVE-2022-35766 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows 10 No fix yet Fix from $1,9502022-08-09 HIGH 8.1 CVE-2022-35767 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows 10 Mitigation only Fix from $1,9502022-08-09 HIGH 7.2 CVE-2022-35772 Azure Site Recovery Remote Code Execution Vulnerability Azure Site Recovery Vmware To Azure 9.50.6419.1+ Fix from $1,9502022-08-09 HIGH 8.8 CVE-2022-35777 Visual Studio Remote Code Execution Vulnerability Visual Studio after 16.11 Fix from $1,9502022-08-09 HIGH 7.8 CVE-2022-35779 Azure RTOS GUIX Studio Remote Code Execution Vulnerability Azure Real Time Operating System Guix Studio No fix yet Fix from $1,9502022-08-09 HIGH 8.1 CVE-2022-34714 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows 10 Mitigation only Fix from $1,9502022-08-09 CRITICAL 9.8 CVE-2022-34715EPSS 80% Windows Network File System Remote Code Execution Vulnerability Windows Server 2022 Mitigation only Fix from $2,3002022-08-09 HIGH 7.8 CVE-2022-30175 Azure RTOS GUIX Studio Remote Code Execution Vulnerability Azure Real Time Operating System Guix Studio No fix yet Fix from $1,9502022-08-09 HIGH 7.5 CVE-2022-30194 Windows WebBrowser Control Remote Code Execution Vulnerability Windows 10 Mitigation only Fix from $1,9502022-08-09 MEDIUM 5.5 CVE-2022-33721 A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege. Android Mitigation only Fix from $1,6002022-08-05 HIGH 8.8 CVE-2022-2636 Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. Control Panel 1.6.6+ Fix from $1,9502022-08-05 HIGH 7.8 CVE-2022-37396 In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution Rider 2022.2+ Fix from $1,9502022-08-03 HIGH 7.2 CVE-2022-34625 Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a cra… Mealie No fix yet Fix from $1,9502022-08-02 HIGH 7.2 CVE-2022-36799EPSS 45% This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected ve… Jira Data Center 8.13.19 / 8.20.7+ Fix from $1,9502022-08-01 CRITICAL 9.8 CVE-2022-30083 EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user input as code (remote). Elliegrid No fix yet Fix from $2,3002022-07-30 CRITICAL 9.8 CVE-2021-22646 The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code e… Twinsoft 1.46 / 12.4+ Fix from $2,3002022-07-28 HIGH 7.8 CVE-2022-37009 In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible Intellij Idea 2022.2+ Fix from $1,9502022-07-28 CRITICAL 9.8 CVE-2022-35649EPSS 8% The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results i… Moodle 3.9.15 / 3.11.8+ Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2022-25759EPSS 11% The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload. Convert Svg Core 0.6.2+ Fix from $2,3002022-07-22