Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-3408EPSS 78% man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulner… D Tale Patch available Fix from $2,3002024-06-06 HIGH 7.2 CVE-2024-4889 A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated input in the eval function wi… Litellm 1.44.16+ Fix from $1,9502024-06-06 HIGH 7.3 CVE-2024-4194 The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includin… Album And Image Gallery Plus Lightbox 2.1+ Fix from $1,9502024-06-06 CRITICAL 9.8 CVE-2024-37273 An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploadin… Jan No fix yet Fix from $2,3002024-06-04 CRITICAL 10.0 CVE-2024-25600EPSS 88% Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bri… Mitigation only Fix from $2,3002024-06-04 HIGH 8.8 CVE-2024-37061 Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execu… Mlflow No fix yet Fix from $1,9502024-06-04 CRITICAL 9.8 CVE-2024-36568 Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=. Gas Agency Management System No fix yet Fix from $2,3002024-06-03 HIGH 7.8 CVE-2024-36120 javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification c… Javascript Deobfuscator 1.1.0+ Fix from $1,9502024-05-31 HIGH 8.1 CVE-2024-5565EPSS 15% The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and r… Mitigation only Fix from $1,9502024-05-31 CRITICAL 9.8 CVE-2024-23692 KEVEPSS 99% Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, … Http File Server after 2.4 Fix from $2,3002024-05-31 HIGH 8.8 CVE-2023-6743 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up… Unlimited Elements For Elementor after 1.5.89 Fix from $1,9502024-05-29 HIGH 7.3 CVE-2024-35226 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template aut… Patch available Fix from $1,9502024-05-28 MEDIUM 6.1 CVE-2024-35581 A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or H… Computer Laboratory Management System No fix yet Fix from $1,6002024-05-28 CRITICAL 9.8 CVE-2024-23601 A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can le… P3 550e Firmware Mitigation only Fix from $2,3002024-05-28 HIGH 8.4 CVE-2024-28886 OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), … Mitigation only Fix from $1,9502024-05-28 CRITICAL 9.8 CVE-2024-5407 A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allo… Rhinos Mitigation only Fix from $2,3002024-05-27 CRITICAL 9.8 CVE-2024-35339 Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac. Fh1206 Firmware No fix yet Fix from $2,3002024-05-24 HIGH 7.3 CVE-2024-4037 The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is… Wp Photo Album Plus 8.7.00.004+ Fix from $1,9502024-05-24 HIGH 8.1 CVE-2024-0867 The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce fu… Mitigation only Fix from $1,9502024-05-24 MEDIUM 6.8 CVE-2024-36361 Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileCli… Patch available Fix from $1,6002024-05-24 HIGH 8.8 CVE-2024-4662 The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is… Mitigation only Fix from $1,9502024-05-23 HIGH 7.8 CVE-2024-33225 An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to… Mitigation only Fix from $1,9502024-05-22 HIGH 8.4 CVE-2024-33228 An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execu… Mitigation only Fix from $1,9502024-05-22 MEDIUM 5.4 CVE-2024-4261 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t… Mitigation only Fix from $1,6002024-05-22 MEDIUM 6.6 CVE-2024-31396 Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If… A Blog Cms 3.0.32 / 3.1.12+ Fix from $1,6002024-05-22 HIGH 8.8 CVE-2024-21683EPSS 88% This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Co… Confluence Data Center 4.8.15 / 5.4.21+ Fix from $1,9502024-05-21 HIGH 7.2 CVE-2024-22274 The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter app… Cloud Foundation 5.1.1+ Fix from $1,9502024-05-21 CRITICAL 9.8 CVE-2024-24294 A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty func… Mitigation only Fix from $2,3002024-05-20 MEDIUM 6.7 CVE-2024-36078 In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server t… Zammad Mitigation only Fix from $1,6002024-05-19 CRITICAL 9.8 CVE-2024-4264 A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `e… Mitigation only Fix from $2,3002024-05-18