Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.2 CVE-2024-10505 A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/cont… Wuzhicms No fix yet Fix from $1,9502024-10-30 CRITICAL 9.8 CVE-2024-48138 A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers t… Mitigation only Fix from $2,3002024-10-29 CRITICAL 10.0 CVE-2024-8923 ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticate… Servicenow Mitigation only Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-50498EPSS 53% Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This is… Wp Query Console after 1.0 Fix from $2,3002024-10-28 CRITICAL 9.8 CVE-2024-50492 Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affect… Scottcart after 1.1 Fix from $2,3002024-10-28 CRITICAL 9.8 CVE-2024-50450 Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Inject… Wordpress Meta Data And Taxonomies Filter 1.3.3.5+ Fix from $2,3002024-10-28 HIGH 7.2 CVE-2024-9162 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during … Mitigation only Fix from $1,9502024-10-28 HIGH 7.2 CVE-2024-50611 CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.… Mitigation only Fix from $1,9502024-10-27 HIGH 7.3 CVE-2024-9772 The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc… Uix Shortcodes after 1.9.9 Fix from $1,9502024-10-26 MEDIUM 6.5 CVE-2024-48235 An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file. Ofcms No fix yet Fix from $1,6002024-10-25 MEDIUM 6.5 CVE-2024-48236 An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-… Ofcms No fix yet Fix from $1,6002024-10-25 HIGH 7.2 CVE-2024-37845 MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature. Mango 5.2.0+ Fix from $1,9502024-10-25 HIGH 7.2 CVE-2024-48700 Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php … Kliqqi Cms after 3.5.2 Fix from $1,9502024-10-25 HIGH 8.8 CVE-2024-48655 An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file. Total.js No fix yet Fix from $1,9502024-10-25 CRITICAL 9.8 CVE-2024-48581 File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php c… Best Courier Management System No fix yet Fix from $2,3002024-10-25 CRITICAL 9.8 CVE-2024-48204 SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script. Mitigation only Fix from $2,3002024-10-25 CRITICAL 9.8 CVE-2024-48579 SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the us… Best House Rental Management System No fix yet Fix from $2,3002024-10-25 MEDIUM 5.4 CVE-2024-47158 N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the ins… N Line after 2.0.6 Fix from $1,6002024-10-25 HIGH 8.8 CVE-2024-47879 OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `pre… Openrefine 3.8.3+ Fix from $1,9502024-10-24 CRITICAL 9.8 CVE-2024-48514 php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remo… Mitigation only Fix from $2,3002024-10-24 HIGH 8.8 CVE-2024-48964 The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if… Snyk Cli 1.1294.0+ Fix from $1,9502024-10-23 MEDIUM 6.7 CVE-2024-20485 A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could all… Adaptive Security Appliance Software Mitigation only Fix from $1,6002024-10-23 HIGH 7.8 CVE-2024-9050 A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configura… Mitigation only Fix from $1,9502024-10-22 MEDIUM 6.6 CVE-2024-41712 A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command inject… Micollab after 9.8.1.5 Fix from $1,6002024-10-21 HIGH 8.8 CVE-2024-41714 A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) … Micollab after 9.8.1.5 Fix from $1,9502024-10-21 CRITICAL 9.8 CVE-2024-35314 A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could … Micollab after 9.7.1.110 Fix from $2,3002024-10-21 MEDIUM 5.6 CVE-2024-35315 A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could … Micollab after 9.7.1.110 Fix from $1,6002024-10-21 HIGH 8.8 CVE-2024-10131 The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses u… Ragflow No fix yet Fix from $1,9502024-10-19 HIGH 8.3 CVE-2024-9593EPSS 12% The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Ti… Time Clock after 1.2.2 Fix from $1,9502024-10-18 HIGH 8.8 CVE-2024-9264EPSS 95% The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie… Grafana Mitigation only Fix from $1,9502024-10-18