Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.3 CVE-2024-6950 A vulnerability, which was classified as critical, has been found in Prain up to 1.3.0. Affected by this issue is some unknown functionality of the f… Mitigation only Fix from $1,6002024-07-21 HIGH 8.8 CVE-2024-6947 A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been rated as critical. This issue affects the function replaceContent of the file app/C… Flute Mitigation only Fix from $1,9502024-07-21 HIGH 8.8 CVE-2024-6946 A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been declared as critical. This vulnerability affects unknown code of the file /admin/pa… Flute Mitigation only Fix from $1,9502024-07-21 HIGH 7.2 CVE-2024-6940 A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php.… Dedecms No fix yet Fix from $1,9502024-07-21 CRITICAL 9.8 CVE-2024-39962 D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp… Dir 823x Firmware No fix yet Fix from $2,3002024-07-19 HIGH 8.8 CVE-2024-29178 On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker … Streampark 2.1.4+ Fix from $1,9502024-07-18 HIGH 8.8 CVE-2024-29014 Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execu… Netextender 10.2.341+ Fix from $1,9502024-07-18 HIGH 8.8 CVE-2024-39877 Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that … Airflow 2.9.3+ Fix from $1,9502024-07-17 CRITICAL 9.8 CVE-2024-39700 JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include … Jupyterlab 4.3.0+ Fix from $2,3002024-07-16 HIGH 7.0 CVE-2024-6655 A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current wo… Mitigation only Fix from $1,9502024-07-16 CRITICAL 9.9 CVE-2024-39915 Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allo… Patch available Fix from $2,3002024-07-15 CRITICAL 9.4 CVE-2024-36456 This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted… Mitigation only Fix from $2,3002024-07-15 HIGH 8.5 CVE-2024-21513 Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving values from t… Langchain Experimental 0.0.21+ Fix from $1,9502024-07-15 HIGH 8.8 CVE-2024-6345 A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. The… Patch available Fix from $1,9502024-07-15 HIGH 8.8 CVE-2024-40521 SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrict… Seacms No fix yet Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40522 There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in with… Seacms No fix yet Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40546 An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code … Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40552 PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 MEDIUM 6.5 CVE-2024-37405 Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory. Mitigation only Fix from $1,6002024-07-12 CRITICAL 9.8 CVE-2024-25077 An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images… Mitigation only Fix from $2,3002024-07-10 HIGH 8.8 CVE-2024-37149EPSS 21% GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An… Glpi 10.0.16+ Fix from $1,9502024-07-10 CRITICAL 9.1 CVE-2024-37770 14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attacke… 14finger No fix yet Fix from $2,3002024-07-10 CRITICAL 9.8 CVE-2024-39071 Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php. Mitigation only Fix from $2,3002024-07-09 MEDIUM 6.1 CVE-2024-40726 A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected … Netbox No fix yet Fix from $1,6002024-07-09 MEDIUM 6.1 CVE-2024-40735 A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected … Netbox No fix yet Fix from $1,6002024-07-09 CRITICAL 9.8 CVE-2024-6602 A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thu… Firefox 115.13 / 128.0+ Fix from $2,3002024-07-09 CRITICAL 9.8 CVE-2024-37934 Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja … Ninja Forms 3.8.5+ Fix from $2,3002024-07-09 CRITICAL 9.8 CVE-2024-6365 The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomT… Mitigation only Fix from $2,3002024-07-09 MEDIUM 6.5 CVE-2024-22020 A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute ar… Mitigation only Fix from $1,6002024-07-09 CRITICAL 9.8 CVE-2024-39864 The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio… Cloudstack 4.18.2.1 / 4.19.0.2+ Fix from $2,3002024-07-05