Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.3 CVE-2024-11002 The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action … Inpost Gallery 2.1.4.3+ Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-11678 A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code o… Hospital Management System No fix yet Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-11677 A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the fil… Hospital Management System No fix yet Fix from $1,6002024-11-26 HIGH 8.8 CVE-2024-52899 IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on th… Data Virtualization Manager For Z\/os Mitigation only Fix from $1,9502024-11-26 MEDIUM 5.4 CVE-2024-11676 A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functiona… Hospital Management System No fix yet Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-11675 A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknow… Hospital Management System No fix yet Fix from $1,6002024-11-26 HIGH 8.0 CVE-2024-53554 A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitra… Mitigation only Fix from $1,9502024-11-25 HIGH 8.8 CVE-2024-53268 Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions att… Joplin 3.0.3+ Fix from $1,9502024-11-25 MEDIUM 5.4 CVE-2024-11660 A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown part of the file usuario.php.… Farmacia No fix yet Fix from $1,6002024-11-25 HIGH 7.3 CVE-2024-11034 The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is v… Mitigation only Fix from $1,9502024-11-23 CRITICAL 9.8 CVE-2021-38117 Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. Imanager 3.2.5+ Fix from $2,3002024-11-22 CRITICAL 9.8 CVE-2024-51367 An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code … Mitigation only Fix from $2,3002024-11-21 MEDIUM 6.1 CVE-2024-11587 A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOptionJs of the file /inc/classProv… Idccms No fix yet Fix from $1,6002024-11-21 CRITICAL 9.8 CVE-2024-52765EPSS 11% H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter. Gr 1800ax Firmware No fix yet Fix from $2,3002024-11-20 MEDIUM 6.1 CVE-2024-11492 A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the file /index.php/admin/web/appu… 115cms after 2024-08-07 Fix from $1,6002024-11-20 MEDIUM 6.1 CVE-2024-11493 A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of the file /index.php/setpage/… 115cms after 2024-08-07 Fix from $1,6002024-11-20 MEDIUM 5.4 CVE-2024-11491 A vulnerability was found in 115cms up to 20240807. It has been rated as problematic. Affected by this issue is some unknown functionality of the fil… 115cms after 2024-08-07 Fix from $1,6002024-11-20 MEDIUM 6.1 CVE-2024-11490 A vulnerability was found in 115cms up to 20240807. It has been declared as problematic. Affected by this vulnerability is an unknown functionality o… 115cms after 2024-08-07 Fix from $1,6002024-11-20 MEDIUM 6.1 CVE-2024-11488 A vulnerability was found in 115cms up to 20240807 and classified as problematic. This issue affects some unknown processing of the file /app/admin/v… 115cms after 2024-08-07 Fix from $1,6002024-11-20 MEDIUM 6.1 CVE-2024-11489 A vulnerability was found in 115cms up to 20240807. It has been classified as problematic. Affected is an unknown function of the file /index.php/adm… 115cms after 2024-08-07 Fix from $1,6002024-11-20 CRITICAL 9.8 CVE-2024-10094 Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code Infinity 8.1.9 / 8.2.8+ Fix from $2,3002024-11-20 HIGH 7.5 CVE-2024-10382 There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction… Androidx.car.app after 1.4.0 Fix from $1,9502024-11-20 HIGH 7.3 CVE-2024-10899 The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.… Woocommerce Product Table 3.8.7+ Fix from $1,9502024-11-20 CRITICAL 9.8 CVE-2024-48694 File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary co… Mitigation only Fix from $2,3002024-11-19 CRITICAL 9.8 CVE-2024-48070 An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and cont… E Cology Mitigation only Fix from $2,3002024-11-19 HIGH 7.3 CVE-2024-11038 The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary s… Wpb Popup For Contact Form 7 1.7.6+ Fix from $1,9502024-11-19 CRITICAL 9.8 CVE-2024-11036 The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbi… Gamipress 7.1.6+ Fix from $2,3002024-11-19 HIGH 7.8 CVE-2024-50804 Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Devi… Mitigation only Fix from $1,9502024-11-18 CRITICAL 9.8 CVE-2024-50919 Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to a… Jpress after 5.1.1 Fix from $2,3002024-11-18 HIGH 7.5 CVE-2024-44757 An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to downlo… Nus M9 Erp Mitigation only Fix from $1,9502024-11-18