Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2024-5651
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbit…
Mitigation only
HIGH 7.6
CVE-2024-40487
A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attacke…
Live Membership System
No fix yet
HIGH 7.2
CVE-2024-22116
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default …
Zabbix
after 6.4.15
MEDIUM 6.0
CVE-2023-50810
In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allo…
Mitigation only
HIGH 7.5
CVE-2023-31315
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock i…
Mitigation only
HIGH 7.2
CVE-2024-37382
An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code …
Authorization Gateway
4.1.4.9+
MEDIUM 6.8
CVE-2023-33206
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during …
Vynamic Security Suite
3.3.0sr16 / 4.0.0sr06+
CRITICAL 9.8
CVE-2024-42355
Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Pr…
Shopware
6.5.8.13 / 6.6.5.1+
HIGH 7.2
CVE-2024-42356
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and a…
Shopware
6.5.8.13 / 6.6.5.1+
MEDIUM 6.5
CVE-2024-3958
An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found…
GitLab
17.0.6 / 17.1.4+
HIGH 8.8
CVE-2024-6891
Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.
Journyx
No fix yet
CRITICAL 9.8
CVE-2024-42393
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploit…
Arubaos
8.10.0.13 / 8.12.0.2+
HIGH 8.8
CVE-2024-7520
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129…
Firefox
128.1.0 / 129.0+
HIGH 8.8
CVE-2024-34344
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `p…
Nuxt
3.12.4+
HIGH 7.1
CVE-2024-22169
WD Discovery
versions prior to 5.0.589 contain a misconfiguration in the Node.js environment
settings that could allow code execution by utilizing th…
Mitigation only
CRITICAL 9.6
CVE-2024-41127
Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-f…
Monkeytype
24.30.0+
CRITICAL 9.8
CVE-2024-36268
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.10.0 through 1.12…
Inlong
1.13.0+
CRITICAL 9.4
CVE-2024-7093
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither pr…
Mitigation only
CRITICAL 9.6
CVE-2024-41961
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live…
Patch available
MEDIUM 5.5
CVE-2024-6923
There is a MEDIUM severity vulnerability affecting CPython.
The
email module didn’t properly quote newlines for email headers when
serializing an …
Patch available
HIGH 8.8
CVE-2024-37901
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can per…
Xwiki
14.10.21 / 15.5.5+
MEDIUM 5.4
CVE-2024-41304
An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafte…
Wondercms
No fix yet
MEDIUM 6.1
CVE-2024-7218
A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?actio…
School Log Management System
No fix yet
HIGH 8.8
CVE-2024-6726
Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).
No fix yet
CRITICAL 9.8
CVE-2024-41468
Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand
Fh1201 Firmware
Mitigation only
HIGH 8.8
CVE-2024-37084EPSS 35%
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to wr…
Spring Cloud Data Flow
2.11.4+
HIGH 8.0
CVE-2024-40495
A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_par…
E2500 Firmware
Mitigation only
HIGH 8.8
CVE-2024-41667
OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.jav…
Patch available
CRITICAL 9.8
CVE-2024-38944
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?fo…
Mitigation only
CRITICAL 9.8
CVE-2024-21552
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM outp…
Mitigation only