Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-39331 In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-comm… Emacs 29.4+ Fix from $2,3002024-06-23 HIGH 8.8 CVE-2024-38319 IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 2948… Soar after 51.0.2.0 Fix from $1,9502024-06-22 CRITICAL 9.0 CVE-2023-45673 Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on … Joplin 2.13.3+ Fix from $2,3002024-06-21 HIGH 8.0 CVE-2024-37899 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the u… Xwiki 14.10.21 / 15.5.5+ Fix from $1,9502024-06-20 MEDIUM 5.3 CVE-2024-28397 An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call. Mitigation only Fix from $1,6002024-06-20 MEDIUM 6.3 CVE-2024-33335 SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file. Mitigation only Fix from $1,6002024-06-20 HIGH 8.8 CVE-2024-3562 The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field… Custom Field Suite after 2.6.7 Fix from $1,9502024-06-20 CRITICAL 10.0 CVE-2024-36679 In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token… Mitigation only Fix from $2,3002024-06-19 HIGH 8.1 CVE-2024-32030EPSS 34% Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their ne… Patch available Fix from $1,9502024-06-19 CRITICAL 9.8 CVE-2024-37124 Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an ar… Mitigation only Fix from $2,3002024-06-19 HIGH 8.8 CVE-2024-37821 An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code v… Dolibarr Erp\/crm 19.0.2+ Fix from $1,9502024-06-18 CRITICAL 9.8 CVE-2024-36575 A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor. Mitigation only Fix from $2,3002024-06-17 HIGH 7.6 CVE-2024-36581 A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm. Mitigation only Fix from $1,9502024-06-17 CRITICAL 9.8 CVE-2024-38396 An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in… Iterm2 3.5.2+ Fix from $2,3002024-06-16 HIGH 8.8 CVE-2024-38458 Xenforo before 2.2.16 allows code injection. Xenforo 2.2.16+ Fix from $1,9502024-06-16 CRITICAL 9.1 CVE-2024-38448 htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used. Mitigation only Fix from $2,3002024-06-16 CRITICAL 9.8 CVE-2024-38395 In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivial… Iterm2 3.5.2+ Fix from $2,3002024-06-16 CRITICAL 9.9 CVE-2024-3105 The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, a… Mitigation only Fix from $2,3002024-06-15 HIGH 8.1 CVE-2024-36598 An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file. Mitigation only Fix from $1,9502024-06-14 HIGH 7.8 CVE-2024-37885 The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client fo… Desktop 3.12.0+ Fix from $1,9502024-06-14 HIGH 8.8 CVE-2024-32925 In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e… Android Mitigation only Fix from $1,9502024-06-13 CRITICAL 9.8 CVE-2024-37849 A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username pa… Billing System No fix yet Fix from $2,3002024-06-13 CRITICAL 9.8 CVE-2024-1577 Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving cra… Megabip after 5.11.2 Fix from $2,3002024-06-12 HIGH 8.8 CVE-2024-5834 Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML p… Chrome 126.0.6478.54+ Fix from $1,9502024-06-11 CRITICAL 9.1 CVE-2024-34405 Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within th… Mitigation only Fix from $2,3002024-06-11 HIGH 7.8 CVE-2024-27857 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 1… Ipados 1.2 / 14.5+ Fix from $1,9502024-06-10 CRITICAL 9.8 CVE-2024-37014EPSS 57% Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a … Langflow after 0.6.19 Fix from $2,3002024-06-10 HIGH 7.8 CVE-2022-32897 A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff f… macOS 12.5+ Fix from $1,9502024-06-10 HIGH 8.5 CVE-2024-34761 Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE … Mitigation only Fix from $1,9502024-06-10 MEDIUM 5.7 CVE-2024-36531 nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php compo… Egovernment after 4.5.05 Fix from $1,6002024-06-10