Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-38346 The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and … Cloudstack 4.18.2.1 / 4.19.0.2+ Fix from $2,3002024-07-05 CRITICAL 9.9 CVE-2024-39932EPSS 17% Gogs through 0.13.0 allows argument injection during the previewing of changes. Gogs after 0.13.0 Fix from $2,3002024-07-04 CRITICAL 9.8 CVE-2024-39165 QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the da… Mitigation only Fix from $2,3002024-07-04 HIGH 8.1 CVE-2024-6507 Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API Patch available Fix from $1,9502024-07-04 HIGH 8.8 CVE-2024-33871 An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, e… Ghostscript 10.03.1+ Fix from $1,9502024-07-03 CRITICAL 9.8 CVE-2024-39844 In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK. Mitigation only Fix from $2,3002024-07-03 HIGH 7.8 CVE-2024-25086 Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code. Windriver 12.2.0+ Fix from $1,9502024-07-02 CRITICAL 9.8 CVE-2024-39236 Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered … Gradio No fix yet Fix from $2,3002024-07-01 CRITICAL 9.8 CVE-2024-36401 KEVEPSS 100% GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multipl… Geoserver 2.22.6 / 2.23.6+ Fix from $2,3002024-07-01 CRITICAL 9.8 CVE-2024-6376 MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass'… Compass 1.42.2+ Fix from $2,3002024-07-01 MEDIUM 6.3 CVE-2024-39002 rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to exec… Jsonic No fix yet Fix from $1,6002024-07-01 CRITICAL 9.8 CVE-2024-39015 cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbit… Mitigation only Fix from $2,3002024-07-01 CRITICAL 9.8 CVE-2024-39017 agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers t… Mitigation only Fix from $2,3002024-07-01 MEDIUM 6.3 CVE-2024-38990 Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute a… Mitigation only Fix from $1,6002024-07-01 CRITICAL 9.8 CVE-2024-38993 rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute a… Jsonic No fix yet Fix from $2,3002024-07-01 HIGH 7.2 CVE-2024-36074 Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protec… Mitigation only Fix from $1,9502024-06-27 MEDIUM 6.5 CVE-2024-36075 The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way… Mitigation only Fix from $1,6002024-06-27 MEDIUM 6.3 CVE-2024-39209 luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter. Mitigation only Fix from $1,6002024-06-27 HIGH 7.5 CVE-2024-5979 In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` names… H2o Patch available Fix from $1,9502024-06-27 CRITICAL 9.8 CVE-2024-5826 In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is t… Mitigation only Fix from $2,3002024-06-27 CRITICAL 9.8 CVE-2024-5751 BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_de… Litellm Mitigation only Fix from $2,3002024-06-27 CRITICAL 9.8 CVE-2024-39669 In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrar… Mitigation only Fix from $2,3002024-06-27 MEDIUM 6.3 CVE-2023-26877 File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/ef… Mitigation only Fix from $1,6002024-06-26 HIGH 8.4 CVE-2024-37855 An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary … Mitigation only Fix from $1,9502024-06-25 HIGH 7.5 CVE-2024-6206 A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where … Mitigation only Fix from $1,9502024-06-25 CRITICAL 9.8 CVE-2024-4883EPSS 65% In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauth… Whatsup Gold 23.1.3+ Fix from $2,3002024-06-25 CRITICAL 9.8 CVE-2024-4884EPSS 24% In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.… Whatsup Gold 23.1.3+ Fix from $2,3002024-06-25 CRITICAL 10.0 CVE-2023-50029 PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run ar… Mitigation only Fix from $2,3002024-06-24 HIGH 8.8 CVE-2024-37109 Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue aff… Wishlist Member after 3.26.7 Fix from $1,9502024-06-24 CRITICAL 9.8 CVE-2024-5683 Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Remo… Mitigation only Fix from $2,3002024-06-24