Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-26785
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create funct…
MariaDB
No fix yet
MEDIUM 5.6
CVE-2023-39593
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges.…
MariaDB
No fix yet
MEDIUM 5.7
CVE-2024-27766
An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the Mar…
MariaDB
No fix yet
HIGH 7.5
CVE-2024-10073
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\mod…
Flair
No fix yet
HIGH 8.8
CVE-2024-45766
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A lo…
Openmanage Enterprise
4.2.0+
MEDIUM 6.1
CVE-2024-48744
A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, wh…
Teachers Record Management System
No fix yet
CRITICAL 10.0
CVE-2024-49254
Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code Injection.This issue affects…
Mitigation only
HIGH 7.2
CVE-2024-49271
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-el…
Unlimited Elements For Elementor
1.5.122+
CRITICAL 9.8
CVE-2024-9061EPSS 52%
The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_a…
Wp Popup Builder
1.3.6+
MEDIUM 6.6
CVE-2023-31493
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a …
Zoneminder
after 1.36.33
HIGH 7.6
CVE-2024-48279
A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerabi…
User Registration \& Login And User Management System
No fix yet
HIGH 7.8
CVE-2024-45271
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
Mbnet.mini Firmware
2.3.1+
HIGH 7.3
CVE-2024-9837
The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in…
Mitigation only
MEDIUM 6.1
CVE-2024-47826
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrar…
Elabftw
5.1.5+
CRITICAL 9.8
CVE-2024-48168
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitra…
Dcs 960l Firmware
Mitigation only
MEDIUM 6.6
CVE-2024-41997
An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker…
Mitigation only
MEDIUM 5.3
CVE-2024-8760
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This …
Mitigation only
HIGH 8.8
CVE-2024-44414
A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_in…
Mitigation only
CRITICAL 9.8
CVE-2024-21534EPSS 9%
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute a…
Mitigation only
HIGH 7.3
CVE-2024-9581
The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due …
Shortcodes Anywhere
after 1.0.1
CRITICAL 9.8
CVE-2024-45874
A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL fil…
No fix yet
CRITICAL 9.8
CVE-2024-45873
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL …
No fix yet
HIGH 7.2
CVE-2024-43363EPSS 36%
Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code a…
Cacti
1.2.28+
CRITICAL 9.8
CVE-2024-46076
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of maliciou…
Ruoyi
after 4.7.9
MEDIUM 6.6
CVE-2024-45933
OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in …
Mitigation only
MEDIUM 6.3
CVE-2024-8254
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to…
Email Subscribers \& Newsletters
5.7.35+
CRITICAL 9.8
CVE-2024-45186
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
Mitigation only
HIGH 8.0
CVE-2024-46080
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
Scriptcase
after 9.10.023
MEDIUM 5.7
CVE-2024-44744
An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directo…
Mitigation only
MEDIUM 6.3
CVE-2024-45200
In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer o…
Mitigation only