Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2024-5651 A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbit… Mitigation only Fix from $1,9502024-08-12 HIGH 7.6 CVE-2024-40487 A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attacke… Live Membership System No fix yet Fix from $1,9502024-08-12 HIGH 7.2 CVE-2024-22116 An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default … Zabbix after 6.4.15 Fix from $1,9502024-08-12 MEDIUM 6.0 CVE-2023-50810 In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allo… Mitigation only Fix from $1,6002024-08-12 HIGH 7.5 CVE-2023-31315 Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock i… Mitigation only Fix from $1,9502024-08-12 HIGH 7.2 CVE-2024-37382 An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code … Authorization Gateway 4.1.4.9+ Fix from $1,9502024-08-08 MEDIUM 6.8 CVE-2023-33206 Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during … Vynamic Security Suite 3.3.0sr16 / 4.0.0sr06+ Fix from $1,6002024-08-08 CRITICAL 9.8 CVE-2024-42355 Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Pr… Shopware 6.5.8.13 / 6.6.5.1+ Fix from $2,3002024-08-08 HIGH 7.2 CVE-2024-42356 Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and a… Shopware 6.5.8.13 / 6.6.5.1+ Fix from $1,9502024-08-08 MEDIUM 6.5 CVE-2024-3958 An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found… GitLab 17.0.6 / 17.1.4+ Fix from $1,6002024-08-08 HIGH 8.8 CVE-2024-6891 Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow. Journyx No fix yet Fix from $1,9502024-08-08 CRITICAL 9.8 CVE-2024-42393 There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploit… Arubaos 8.10.0.13 / 8.12.0.2+ Fix from $2,3002024-08-06 HIGH 8.8 CVE-2024-7520 A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129… Firefox 128.1.0 / 129.0+ Fix from $1,9502024-08-06 HIGH 8.8 CVE-2024-34344 Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `p… Nuxt 3.12.4+ Fix from $1,9502024-08-05 HIGH 7.1 CVE-2024-22169 WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing th… Mitigation only Fix from $1,9502024-08-02 CRITICAL 9.6 CVE-2024-41127 Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-f… Monkeytype 24.30.0+ Fix from $2,3002024-08-02 CRITICAL 9.8 CVE-2024-36268 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12… Inlong 1.13.0+ Fix from $2,3002024-08-02 CRITICAL 9.4 CVE-2024-7093 Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither pr… Mitigation only Fix from $2,3002024-08-01 CRITICAL 9.6 CVE-2024-41961 Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live… Patch available Fix from $2,3002024-08-01 MEDIUM 5.5 CVE-2024-6923 There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an … Patch available Fix from $1,6002024-08-01 HIGH 8.8 CVE-2024-37901 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can per… Xwiki 14.10.21 / 15.5.5+ Fix from $1,9502024-07-31 MEDIUM 5.4 CVE-2024-41304 An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafte… Wondercms No fix yet Fix from $1,6002024-07-30 MEDIUM 6.1 CVE-2024-7218 A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?actio… School Log Management System No fix yet Fix from $1,6002024-07-30 HIGH 8.8 CVE-2024-6726 Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE). No fix yet Fix from $1,9502024-07-29 CRITICAL 9.8 CVE-2024-41468 Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand Fh1201 Firmware Mitigation only Fix from $2,3002024-07-25 HIGH 8.8 CVE-2024-37084EPSS 35% In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to wr… Spring Cloud Data Flow 2.11.4+ Fix from $1,9502024-07-25 HIGH 8.0 CVE-2024-40495 A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_par… E2500 Firmware Mitigation only Fix from $1,9502024-07-24 HIGH 8.8 CVE-2024-41667 OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.jav… Patch available Fix from $1,9502024-07-24 CRITICAL 9.8 CVE-2024-38944 An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?fo… Mitigation only Fix from $2,3002024-07-22 CRITICAL 9.8 CVE-2024-21552 All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM outp… Mitigation only Fix from $2,3002024-07-22