Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-50636 PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. At… Mitigation only Fix from $2,3002024-11-11 CRITICAL 9.1 CVE-2024-46962 The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScrip… Mitigation only Fix from $2,3002024-11-11 HIGH 8.1 CVE-2024-46963 The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to ex… Mitigation only Fix from $1,9502024-11-11 HIGH 8.1 CVE-2024-46964 The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code… Mitigation only Fix from $1,9502024-11-11 HIGH 8.1 CVE-2024-46966 The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary Java… Mitigation only Fix from $1,9502024-11-11 MEDIUM 5.4 CVE-2024-11078 A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown funct… Job Recruitment No fix yet Fix from $1,6002024-11-11 MEDIUM 5.4 CVE-2024-46965 The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitra… Mitigation only Fix from $1,6002024-11-11 MEDIUM 5.4 CVE-2024-11070 A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of t… Publiccms No fix yet Fix from $1,6002024-11-11 HIGH 7.3 CVE-2024-10958 The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all… Wp Photo Album Plus 8.9.01.001+ Fix from $1,9502024-11-10 MEDIUM 5.4 CVE-2024-11050 A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown … Hibos after 3.0.3.151204 Fix from $1,6002024-11-10 HIGH 7.3 CVE-2024-10640 The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t… Mitigation only Fix from $1,9502024-11-09 HIGH 7.3 CVE-2024-10261 The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitr… Membership \& Content Restriction Paid Member Subscriptions 2.13.1+ Fix from $1,9502024-11-09 HIGH 8.8 CVE-2024-50808 SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to u… Seacms No fix yet Fix from $1,9502024-11-08 HIGH 8.8 CVE-2024-46960 The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitra… Mitigation only Fix from $1,9502024-11-07 HIGH 8.1 CVE-2024-46961 The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arb… Mitigation only Fix from $1,9502024-11-07 HIGH 8.1 CVE-2024-43425EPSS 83% A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requi… Moodle 4.1.12 / 4.2.9+ Fix from $1,9502024-11-07 CRITICAL 9.3 CVE-2024-51757 happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute co… Patch available Fix from $2,3002024-11-06 HIGH 7.3 CVE-2024-10263 The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5… Tickera 3.5.4.6+ Fix from $1,9502024-11-05 CRITICAL 9.8 CVE-2024-48050 In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line… Agentscope after 0.0.4 Fix from $2,3002024-11-04 CRITICAL 9.8 CVE-2024-48061 langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local m… Langflow after 1.0.18 Fix from $2,3002024-11-04 HIGH 8.8 CVE-2024-51329 A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted pass… Agile Board No fix yet Fix from $1,9502024-11-04 CRITICAL 9.8 CVE-2024-10035 Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Impro… Coslat after 3.1069 Fix from $2,3002024-11-04 CRITICAL 9.8 CVE-2024-48359 Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter. Qualitor No fix yet Fix from $2,3002024-10-31 HIGH 8.8 CVE-2024-21537 Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dyn… Patch available Fix from $1,9502024-10-31 CRITICAL 9.8 CVE-2024-51427 An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the m… Mitigation only Fix from $2,3002024-10-30 HIGH 7.2 CVE-2024-51243 The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this manageme… Eladmin after 2.7 Fix from $1,9502024-10-30 CRITICAL 9.8 CVE-2024-51424 An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the O… Mitigation only Fix from $2,3002024-10-30 HIGH 8.1 CVE-2024-42041 The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker… Mitigation only Fix from $1,9502024-10-30 CRITICAL 9.8 CVE-2024-51298 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-30 HIGH 7.3 CVE-2024-9846 The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up … Enable Shortcodes Inside Widgets\,comments And Experts after 1.0.0 Fix from $1,9502024-10-30