Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2024-55661EPSS 29% Laravel Pulse is a real-time application performance monitoring tool and dashboard for Laravel applications. A vulnerability has been discovered in L… Pulse 1.3.1+ Fix from $1,9502024-12-13 CRITICAL 10.0 CVE-2024-21576 ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and Fin… Mitigation only Fix from $2,3002024-12-13 CRITICAL 10.0 CVE-2024-21577 ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary u… Mitigation only Fix from $2,3002024-12-13 MEDIUM 6.3 CVE-2024-11012 The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via njt_nofi_text AJAX action in… Mitigation only Fix from $1,6002024-12-13 MEDIUM 6.5 CVE-2024-12417 The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This i… Mitigation only Fix from $1,6002024-12-13 MEDIUM 6.5 CVE-2024-12420 The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, … Mitigation only Fix from $1,6002024-12-13 MEDIUM 6.5 CVE-2024-12421 The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t… Mitigation only Fix from $1,6002024-12-13 MEDIUM 5.3 CVE-2024-55918 An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead … Mitigation only Fix from $1,6002024-12-13 HIGH 8.8 CVE-2024-55877 XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account … Xwiki 15.10.11 / 16.4.1+ Fix from $1,9502024-12-12 HIGH 8.8 CVE-2024-55662 XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extensio… Xwiki 15.10.9 / 16.3.0+ Fix from $1,9502024-12-12 CRITICAL 10.0 CVE-2024-21574 The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes wh… Patch available Fix from $2,3002024-12-12 MEDIUM 6.5 CVE-2024-12333 The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the softw… Mitigation only Fix from $1,6002024-12-12 HIGH 7.3 CVE-2024-10910 The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX act… Mitigation only Fix from $1,9502024-12-12 HIGH 7.8 CVE-2024-54529 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be… macOS 13.7.2 / 14.7.2+ Fix from $1,9502024-12-12 CRITICAL 9.8 CVE-2024-55660 SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side… Siyuan Patch available Fix from $2,3002024-12-12 MEDIUM 5.4 CVE-2024-12536 A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by… Advocate Office Management System Mitigation only Fix from $1,6002024-12-12 CRITICAL 9.9 CVE-2024-42448EPSS 20% From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code … Mitigation only Fix from $2,3002024-12-12 CRITICAL 9.3 CVE-2024-54152 Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a mal… Patch available Fix from $2,3002024-12-10 HIGH 7.3 CVE-2024-10959 The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution … Mitigation only Fix from $1,9502024-12-10 CRITICAL 9.8 CVE-2022-38946 Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code. Doctor Appointment No fix yet Fix from $2,3002024-12-09 MEDIUM 5.4 CVE-2024-12359 A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the f… Admin Dashboard No fix yet Fix from $1,6002024-12-09 HIGH 7.5 CVE-2024-55580 An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute r… Mitigation only Fix from $1,9502024-12-09 MEDIUM 6.1 CVE-2024-12348 A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.… Jpress No fix yet Fix from $1,6002024-12-09 HIGH 8.8 CVE-2024-12350 A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\c… Jfinalcms No fix yet Fix from $1,9502024-12-09 CRITICAL 9.0 CVE-2024-51815 Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member allows Code Injection.This issue affect… Mitigation only Fix from $2,3002024-12-06 HIGH 8.1 CVE-2024-21571 Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbit… Mitigation only Fix from $1,9502024-12-06 HIGH 8.8 CVE-2024-10771 Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network acce… Mitigation only Fix from $1,9502024-12-06 MEDIUM 6.3 CVE-2024-10909 The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX action in all versions up to, … Mitigation only Fix from $1,6002024-12-06 MEDIUM 6.3 CVE-2024-10681 The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to arbitrary … Mitigation only Fix from $1,6002024-12-06 HIGH 7.8 CVE-2024-30961 Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local… Robot Operating System Patch available Fix from $1,9502024-12-05