Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-38346
The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and …
Cloudstack
4.18.2.1 / 4.19.0.2+
CRITICAL 9.9
CVE-2024-39932EPSS 17%
Gogs through 0.13.0 allows argument injection during the previewing of changes.
Gogs
after 0.13.0
CRITICAL 9.8
CVE-2024-39165
QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the da…
Mitigation only
HIGH 8.1
CVE-2024-6507
Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API
Patch available
HIGH 8.8
CVE-2024-33871
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, e…
Ghostscript
10.03.1+
CRITICAL 9.8
CVE-2024-39844
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
Mitigation only
HIGH 7.8
CVE-2024-25086
Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
Windriver
12.2.0+
CRITICAL 9.8
CVE-2024-39236
Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered …
Gradio
No fix yet
CRITICAL 9.8
CVE-2024-36401 KEVEPSS 100%
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multipl…
Geoserver
2.22.6 / 2.23.6+
CRITICAL 9.8
CVE-2024-6376
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass'…
Compass
1.42.2+
MEDIUM 6.3
CVE-2024-39002
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to exec…
Jsonic
No fix yet
CRITICAL 9.8
CVE-2024-39015
cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbit…
Mitigation only
CRITICAL 9.8
CVE-2024-39017
agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers t…
Mitigation only
MEDIUM 6.3
CVE-2024-38990
Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute a…
Mitigation only
CRITICAL 9.8
CVE-2024-38993
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute a…
Jsonic
No fix yet
HIGH 7.2
CVE-2024-36074
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protec…
Mitigation only
MEDIUM 6.5
CVE-2024-36075
The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way…
Mitigation only
MEDIUM 6.3
CVE-2024-39209
luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.
Mitigation only
HIGH 7.5
CVE-2024-5979
In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` names…
H2o
Patch available
CRITICAL 9.8
CVE-2024-5826
In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is t…
Mitigation only
CRITICAL 9.8
CVE-2024-5751
BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_de…
Litellm
Mitigation only
CRITICAL 9.8
CVE-2024-39669
In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrar…
Mitigation only
MEDIUM 6.3
CVE-2023-26877
File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/ef…
Mitigation only
HIGH 8.4
CVE-2024-37855
An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary …
Mitigation only
HIGH 7.5
CVE-2024-6206
A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where …
Mitigation only
CRITICAL 9.8
CVE-2024-4883EPSS 65%
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauth…
Whatsup Gold
23.1.3+
CRITICAL 9.8
CVE-2024-4884EPSS 24%
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.…
Whatsup Gold
23.1.3+
CRITICAL 10.0
CVE-2023-50029
PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run ar…
Mitigation only
HIGH 8.8
CVE-2024-37109
Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue aff…
Wishlist Member
after 3.26.7
CRITICAL 9.8
CVE-2024-5683
Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Remo…
Mitigation only