Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2024-9324 A vulnerability was found in Intelbras InControl up to 2.21.57. It has been rated as critical. Affected by this issue is some unknown functionality o… Incontrol Web 2.21.58+ Fix from $1,9502024-09-29 HIGH 8.8 CVE-2024-6983 mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only f… Localai Patch available Fix from $1,9502024-09-27 HIGH 8.8 CVE-2024-46489 A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL. Promptr No fix yet Fix from $1,9502024-09-25 HIGH 7.3 CVE-2024-8481 The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.4. This is d… Special Text Boxes after 6.2.2 Fix from $1,9502024-09-25 HIGH 7.3 CVE-2024-8623 The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi… Wordpress Meta Data And Taxonomies Filter 1.3.3.4+ Fix from $1,9502024-09-24 HIGH 7.6 CVE-2024-46639 A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inject… Mitigation only Fix from $1,9502024-09-23 HIGH 8.8 CVE-2024-37779 WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script function… Mitigation only Fix from $1,9502024-09-23 HIGH 7.2 CVE-2024-0004 A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the ar… Purity\/\/fa after 6.4.10 Fix from $1,9502024-09-23 HIGH 7.2 CVE-2024-40442 An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a d… Mitigation only Fix from $1,9502024-09-23 CRITICAL 9.8 CVE-2024-47219 An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection. Nebulagraph Database after 3.8.0 Fix from $2,3002024-09-22 CRITICAL 9.8 CVE-2024-46103 SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php. Semcms No fix yet Fix from $2,3002024-09-20 CRITICAL 9.8 CVE-2024-46640 SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function… Seacms No fix yet Fix from $2,3002024-09-20 HIGH 8.8 CVE-2024-9006 A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the … 123solar Patch available Fix from $1,9502024-09-19 CRITICAL 9.8 CVE-2024-35515 Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code. Mitigation only Fix from $2,3002024-09-18 CRITICAL 9.9 CVE-2024-45798 arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulne… Mitigation only Fix from $2,3002024-09-17 CRITICAL 9.8 CVE-2024-44623 An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function. Spx Graphics Controller after 1.3.0 Fix from $2,3002024-09-16 CRITICAL 9.8 CVE-2024-7104 Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection. This issue affects ww.Wi… Winsure 4.6.2+ Fix from $2,3002024-09-16 CRITICAL 9.8 CVE-2024-8880 A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.… Playsms No fix yet Fix from $2,3002024-09-16 HIGH 8.8 CVE-2024-8864 A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculat… Composio after 0.5.6 Fix from $1,9502024-09-15 HIGH 7.3 CVE-2024-8479 The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding t… Simple Spoiler 1.4+ Fix from $1,9502024-09-14 HIGH 7.3 CVE-2024-8271 The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t… Fox Currency Switcher Professional For Woocommerce 1.4.2.2+ Fix from $1,9502024-09-14 CRITICAL 9.8 CVE-2024-44430 SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive inform… Best Free Law Office Management No fix yet Fix from $2,3002024-09-13 CRITICAL 9.8 CVE-2024-8695 A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop be… Desktop 4.34.2+ Fix from $2,3002024-09-12 CRITICAL 9.8 CVE-2024-8696 A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker De… Desktop 4.34.2+ Fix from $2,3002024-09-12 HIGH 8.8 CVE-2024-45851 An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat… Mindsdb 24.7.4.1+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-45847 An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is in… Mindsdb 24.7.4.1+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-45848 An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is insta… Mindsdb 24.7.4.1+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-45849 An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat… Mindsdb 24.7.4.1+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-45850 An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integrat… Mindsdb 24.7.4.1+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-45846 An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is insta… Mindsdb 24.7.4.1+ Fix from $1,9502024-09-12