Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2021-25003EPSS 56% The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on t… Wpcargo Track \& Trace 6.9.0+ Fix from $2,3002022-03-14 MEDIUM 6.7 CVE-2022-0921 Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12. Microweber 1.2.12+ Fix from $1,6002022-03-11 CRITICAL 9.8 CVE-2021-44618 A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header. Seomatic Patch available Fix from $2,3002022-03-11 HIGH 8.8 CVE-2022-24915 The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will… Ipdio Firmware Mitigation only Fix from $1,9502022-03-10 HIGH 8.8 CVE-2022-22985 The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will… Ipdio Firmware Mitigation only Fix from $1,9502022-03-10 HIGH 7.2 CVE-2022-24734EPSS 78% MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correct… Mybb 1.8.30+ Fix from $1,9502022-03-09 MEDIUM 6.3 CVE-2022-24512 .NET and Visual Studio Remote Code Execution Vulnerability Fedora 7.0.9 / 7.1.6+ Fix from $1,6002022-03-09 HIGH 8.8 CVE-2022-0896 Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3. Microweber 1.3+ Fix from $1,9502022-03-09 HIGH 7.2 CVE-2021-43944 This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected ve… Jira Data Center 8.13.15 / 8.20.3+ Fix from $1,9502022-03-08 CRITICAL 9.8 CVE-2022-0845 Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0. Pytorch Lightning 1.6.0+ Fix from $2,3002022-03-05 CRITICAL 10.0 CVE-2022-22947 KEVEPSS 98% In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi… Spring Cloud Gateway 3.0.7+ Fix from $2,3002022-03-03 HIGH 8.8 CVE-2022-22909EPSS 45% HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payloa… Hoteldruid No fix yet Fix from $1,9502022-03-03 HIGH 8.8 CVE-2022-0819EPSS 41% Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1. Dolibarr Erp\/crm 15.0.1+ Fix from $1,9502022-03-02 HIGH 7.2 CVE-2021-44238 AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php, Ayacms No fix yet Fix from $1,9502022-03-01 HIGH 8.8 CVE-2022-25018 Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages. Pluxml Mitigation only Fix from $1,9502022-03-01 CRITICAL 9.8 CVE-2022-24442 JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. Youtrack 2021.4.40426+ Fix from $2,3002022-02-25 HIGH 7.5 CVE-2021-22395 There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,9502022-02-25 MEDIUM 6.5 CVE-2022-23810 Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prio… A Blog Cms 2.8.75 / 2.9.40+ Fix from $1,6002022-02-24 HIGH 8.8 CVE-2022-24295EPSS 17% Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL. Advanced Server Access Client For Windows 1.57.0+ Fix from $1,9502022-02-21 HIGH 8.8 CVE-2022-23642EPSS 74% Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` servi… Sourcegraph 3.37+ Fix from $1,9502022-02-18 CRITICAL 9.1 CVE-2021-46063 MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module. Mcms No fix yet Fix from $2,3002022-02-18 HIGH 8.8 CVE-2022-24663 PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authent… Php Everywhere after 2.0.3 Fix from $1,9502022-02-16 HIGH 8.8 CVE-2022-24664 PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user a… Php Everywhere after 2.0.3 Fix from $1,9502022-02-16 HIGH 8.8 CVE-2022-24665 PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit p… Php Everywhere after 2.0.3 Fix from $1,9502022-02-16 CRITICAL 9.8 CVE-2021-46362 A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers … Magnolia Cms 6.2.4+ Fix from $2,3002022-02-11 MEDIUM 6.0 CVE-2022-23426 A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege. Android Mitigation only Fix from $1,6002022-02-11 CRITICAL 9.1 CVE-2021-44521EPSS 55% When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab… Cassandra 3.0.26 / 3.11.12+ Fix from $2,3002022-02-11 CRITICAL 9.8 CVE-2022-23631 superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to r… Blitz 0.45.3 / 1.8.1+ Fix from $2,3002022-02-09 CRITICAL 9.8 CVE-2022-23614EPSS 8% Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attac… Twig 2.14.11 / 3.3.8+ Fix from $2,3002022-02-04 CRITICAL 9.8 CVE-2021-44978 iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution. Icms after 8.0.0 Fix from $2,3002022-02-04