Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2023-26785 MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create funct… MariaDB No fix yet Fix from $2,3002024-10-17 MEDIUM 5.6 CVE-2023-39593 Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges.… MariaDB No fix yet Fix from $1,6002024-10-17 MEDIUM 5.7 CVE-2024-27766 An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the Mar… MariaDB No fix yet Fix from $1,6002024-10-17 HIGH 7.5 CVE-2024-10073 A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\mod… Flair No fix yet Fix from $1,9502024-10-17 HIGH 8.8 CVE-2024-45766 Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A lo… Openmanage Enterprise 4.2.0+ Fix from $1,9502024-10-17 MEDIUM 6.1 CVE-2024-48744 A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, wh… Teachers Record Management System No fix yet Fix from $1,6002024-10-16 CRITICAL 10.0 CVE-2024-49254 Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code Injection.This issue affects… Mitigation only Fix from $2,3002024-10-16 HIGH 7.2 CVE-2024-49271 Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-el… Unlimited Elements For Elementor 1.5.122+ Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2024-9061EPSS 52% The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_a… Wp Popup Builder 1.3.6+ Fix from $2,3002024-10-16 MEDIUM 6.6 CVE-2023-31493 RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a … Zoneminder after 1.36.33 Fix from $1,6002024-10-15 HIGH 7.6 CVE-2024-48279 A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerabi… User Registration \& Login And User Management System No fix yet Fix from $1,9502024-10-15 HIGH 7.8 CVE-2024-45271 An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. Mbnet.mini Firmware 2.3.1+ Fix from $1,9502024-10-15 HIGH 7.3 CVE-2024-9837 The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in… Mitigation only Fix from $1,9502024-10-15 MEDIUM 6.1 CVE-2024-47826 eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrar… Elabftw 5.1.5+ Fix from $1,6002024-10-14 CRITICAL 9.8 CVE-2024-48168 A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitra… Dcs 960l Firmware Mitigation only Fix from $2,3002024-10-14 MEDIUM 6.6 CVE-2024-41997 An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker… Mitigation only Fix from $1,6002024-10-14 MEDIUM 5.3 CVE-2024-8760 The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This … Mitigation only Fix from $1,6002024-10-12 HIGH 8.8 CVE-2024-44414 A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_in… Mitigation only Fix from $1,9502024-10-11 CRITICAL 9.8 CVE-2024-21534EPSS 9% All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute a… Mitigation only Fix from $2,3002024-10-11 HIGH 7.3 CVE-2024-9581 The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due … Shortcodes Anywhere after 1.0.1 Fix from $1,9502024-10-10 CRITICAL 9.8 CVE-2024-45874 A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL fil… No fix yet Fix from $2,3002024-10-07 CRITICAL 9.8 CVE-2024-45873 A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL … No fix yet Fix from $2,3002024-10-07 HIGH 7.2 CVE-2024-43363EPSS 36% Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code a… Cacti 1.2.28+ Fix from $1,9502024-10-07 CRITICAL 9.8 CVE-2024-46076 RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of maliciou… Ruoyi after 4.7.9 Fix from $2,3002024-10-07 MEDIUM 6.6 CVE-2024-45933 OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in … Mitigation only Fix from $1,6002024-10-07 MEDIUM 6.3 CVE-2024-8254 The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to… Email Subscribers \& Newsletters 5.7.35+ Fix from $1,6002024-10-02 CRITICAL 9.8 CVE-2024-45186 FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials. Mitigation only Fix from $2,3002024-10-02 HIGH 8.0 CVE-2024-46080 Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function. Scriptcase after 9.10.023 Fix from $1,9502024-10-01 MEDIUM 5.7 CVE-2024-44744 An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directo… Mitigation only Fix from $1,6002024-10-01 MEDIUM 6.3 CVE-2024-45200 In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer o… Mitigation only Fix from $1,6002024-09-30