Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-3408EPSS 78%
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulner…
D Tale
Patch available
HIGH 7.2
CVE-2024-4889
A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated input in the eval function wi…
Litellm
1.44.16+
HIGH 7.3
CVE-2024-4194
The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includin…
Album And Image Gallery Plus Lightbox
2.1+
CRITICAL 9.8
CVE-2024-37273
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploadin…
Jan
No fix yet
CRITICAL 10.0
CVE-2024-25600EPSS 88%
Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bri…
Mitigation only
HIGH 8.8
CVE-2024-37061
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execu…
Mlflow
No fix yet
CRITICAL 9.8
CVE-2024-36568
Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.
Gas Agency Management System
No fix yet
HIGH 7.8
CVE-2024-36120
javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification c…
Javascript Deobfuscator
1.1.0+
HIGH 8.1
CVE-2024-5565EPSS 15%
The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and r…
Mitigation only
CRITICAL 9.8
CVE-2024-23692 KEVEPSS 99%
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, …
Http File Server
after 2.4
HIGH 8.8
CVE-2023-6743
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up…
Unlimited Elements For Elementor
after 1.5.89
HIGH 7.3
CVE-2024-35226
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template aut…
Patch available
MEDIUM 6.1
CVE-2024-35581
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or H…
Computer Laboratory Management System
No fix yet
CRITICAL 9.8
CVE-2024-23601
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can le…
P3 550e Firmware
Mitigation only
HIGH 8.4
CVE-2024-28886
OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), …
Mitigation only
CRITICAL 9.8
CVE-2024-5407
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allo…
Rhinos
Mitigation only
CRITICAL 9.8
CVE-2024-35339
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.
Fh1206 Firmware
No fix yet
HIGH 7.3
CVE-2024-4037
The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is…
Wp Photo Album Plus
8.7.00.004+
HIGH 8.1
CVE-2024-0867
The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce fu…
Mitigation only
MEDIUM 6.8
CVE-2024-36361
Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileCli…
Patch available
HIGH 8.8
CVE-2024-4662
The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is…
Mitigation only
HIGH 7.8
CVE-2024-33225
An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to…
Mitigation only
HIGH 8.4
CVE-2024-33228
An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execu…
Mitigation only
MEDIUM 5.4
CVE-2024-4261
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…
Mitigation only
MEDIUM 6.6
CVE-2024-31396
Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If…
A Blog Cms
3.0.32 / 3.1.12+
HIGH 8.8
CVE-2024-21683EPSS 88%
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.
This RCE (Remote Co…
Confluence Data Center
4.8.15 / 5.4.21+
HIGH 7.2
CVE-2024-22274
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter app…
Cloud Foundation
5.1.1+
CRITICAL 9.8
CVE-2024-24294
A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty func…
Mitigation only
MEDIUM 6.7
CVE-2024-36078
In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server t…
Zammad
Mitigation only
CRITICAL 9.8
CVE-2024-4264
A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `e…
Mitigation only