Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-44466EPSS 11% COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and… Cf Xr11 Firmware No fix yet Fix from $2,3002024-09-11 HIGH 8.8 CVE-2024-43469 Azure CycleCloud Remote Code Execution Vulnerability Azure Cyclecloud 8.6.4+ Fix from $1,9502024-09-10 HIGH 7.8 CVE-2024-8258 Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to… Logi Options\+ 1.70.551909+ Fix from $1,9502024-09-10 HIGH 8.1 CVE-2024-43392 A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce… Tc Mguard Rs4000 4g Vzw Vpn Firmware 8.9.3+ Fix from $1,9502024-09-10 HIGH 8.1 CVE-2024-43393 A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce… Tc Mguard Rs4000 4g Vzw Vpn Firmware 8.9.3+ Fix from $1,9502024-09-10 HIGH 8.1 CVE-2024-43389 A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY e… Tc Mguard Rs4000 4g Vzw Vpn Firmware 8.9.3+ Fix from $1,9502024-09-10 HIGH 8.1 CVE-2024-43390 A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN… Tc Mguard Rs4000 4g Vzw Vpn Firmware 8.9.3+ Fix from $1,9502024-09-10 HIGH 8.1 CVE-2024-43391 A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce… Tc Mguard Rs4000 4g Vzw Vpn Firmware 8.9.3+ Fix from $1,9502024-09-10 HIGH 8.8 CVE-2024-43388 A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation. Tc Mguard Rs4000 4g Vzw Vpn Firmware 8.9.3+ Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2024-6596 An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. Echo Curve Viewer 1.40.1 / 6.0.0+ Fix from $2,3002024-09-10 HIGH 8.8 CVE-2024-8268 The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions … Frontend Dashboard 2.2.5+ Fix from $1,9502024-09-10 HIGH 7.3 CVE-2024-8478 The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. Th… Affiliate Super Assistent 1.5.4+ Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2024-44410 D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. Di 8300 Firmware No fix yet Fix from $2,3002024-09-09 CRITICAL 9.8 CVE-2024-44411 D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function. Di 8300 Firmware No fix yet Fix from $2,3002024-09-09 HIGH 7.2 CVE-2024-44724 AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability al… Autocms No fix yet Fix from $1,9502024-09-09 HIGH 8.5 CVE-2024-38651 A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSP… Mitigation only Fix from $1,9502024-09-07 CRITICAL 9.9 CVE-2024-39714 A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC s… Mitigation only Fix from $2,3002024-09-07 HIGH 8.5 CVE-2024-39715 A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server u… Mitigation only Fix from $1,9502024-09-07 MEDIUM 5.3 CVE-2023-39333 Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and funct… Mitigation only Fix from $1,6002024-09-07 HIGH 7.2 CVE-2024-8523 A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=… Lmxcms after 1.4 Fix from $1,9502024-09-07 HIGH 8.1 CVE-2024-7627 The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due… File Manager 6.5.6+ Fix from $1,9502024-09-05 HIGH 7.2 CVE-2024-45053 Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja… Fides 2.44.0+ Fix from $1,9502024-09-04 CRITICAL 9.8 CVE-2024-45507EPSS 93% Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apac… Ofbiz 18.12.16+ Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-45390 @blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker… Template 1.2.0+ Fix from $2,3002024-09-03 HIGH 8.8 CVE-2024-42902 An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload i… Limesurvey after 6.6.2 Fix from $1,9502024-09-03 CRITICAL 9.6 CVE-2024-7345 Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents o… Openedge after 12.2.13 Fix from $2,3002024-09-03 HIGH 7.8 CVE-2024-8374 UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The… Ultimaker Cura Patch available Fix from $1,9502024-09-03 CRITICAL 9.8 CVE-2024-45623 D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary t… Mitigation only Fix from $2,3002024-09-02 CRITICAL 9.8 CVE-2024-41364 RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php Phoniebox No fix yet Fix from $2,3002024-08-29 CRITICAL 9.8 CVE-2024-41366 RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php Phoniebox No fix yet Fix from $2,3002024-08-29