Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.3 CVE-2024-31974 The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary… Mitigation only Fix from $1,6002024-05-17 CRITICAL 9.9 CVE-2024-33644 Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affect… Mitigation only Fix from $2,3002024-05-17 HIGH 8.8 CVE-2024-32680 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerabili… Husky Products Filter Professional For Woocommerce 1.3.5.3+ Fix from $1,9502024-05-17 CRITICAL 9.9 CVE-2023-23645 Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue aff… Code Snippets Extension 4.0.3+ Fix from $2,3002024-05-17 CRITICAL 9.8 CVE-2023-48643 Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authori… Mitigation only Fix from $2,3002024-05-16 HIGH 8.8 CVE-2024-4181 A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI … Llamaindex 0.10.13+ Fix from $1,9502024-05-16 HIGH 8.6 CVE-2024-4202 In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulner… Telerik Reporting 18.1.24.514+ Fix from $1,9502024-05-15 MEDIUM 6.7 CVE-2024-3892 A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability cou… Telerik Ui For Winforms 2024.2.514+ Fix from $1,6002024-05-15 CRITICAL 9.1 CVE-2024-3319 An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticate… Mitigation only Fix from $2,3002024-05-15 MEDIUM 6.5 CVE-2024-3044 Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt … Fedora 7.6.7.1 / 24.2.3.1+ Fix from $1,6002024-05-14 MEDIUM 6.5 CVE-2024-4144 The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,… Mitigation only Fix from $1,6002024-05-14 HIGH 8.8 CVE-2024-32352 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEna… X5000r Firmware No fix yet Fix from $1,9502024-05-14 HIGH 8.8 CVE-2024-32350 TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" pa… X5000r Firmware No fix yet Fix from $1,9502024-05-14 HIGH 8.8 CVE-2024-4605 The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is du… Mitigation only Fix from $1,9502024-05-14 MEDIUM 6.5 CVE-2024-4038 The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerable to arbitrary shortcode exe… Mitigation only Fix from $1,6002024-05-14 MEDIUM 6.5 CVE-2024-4039 The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and … Mitigation only Fix from $1,6002024-05-14 MEDIUM 6.6 CVE-2024-3787 Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Explo… Wbsairback Mitigation only Fix from $1,6002024-05-14 MEDIUM 6.6 CVE-2024-3788 Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploi… Wbsairback Mitigation only Fix from $1,6002024-05-14 MEDIUM 6.1 CVE-2024-34225 Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote a… Computer Laboratory Management System No fix yet Fix from $1,6002024-05-14 HIGH 7.8 CVE-2024-29513 An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the dr… Mitigation only Fix from $1,9502024-05-14 HIGH 7.8 CVE-2024-27793 The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termina… Itunes 12.13.2+ Fix from $1,9502024-05-14 MEDIUM 5.4 CVE-2024-4135 The WP Latest Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to t… Mitigation only Fix from $1,6002024-05-08 MEDIUM 6.0 CVE-2024-29209 A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to r… Mitigation only Fix from $1,6002024-05-07 HIGH 8.8 CVE-2024-30973 An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive informa… Mitigation only Fix from $1,9502024-05-06 CRITICAL 9.1 CVE-2024-33294 An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the s… Mitigation only Fix from $2,3002024-05-06 CRITICAL 9.8 CVE-2024-34461 Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code executio… Mitigation only Fix from $2,3002024-05-04 MEDIUM 6.6 CVE-2023-35701 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and… Hive Mitigation only Fix from $1,6002024-05-03 HIGH 7.2 CVE-2023-39469EPSS 58% PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … Papercut Mf 22.1.1+ Fix from $1,9502024-05-03 MEDIUM 5.9 CVE-2024-33394 An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component. Kubevirt after 1.2.0 Fix from $1,6002024-05-02 HIGH 7.3 CVE-2024-3957 The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 7.1.8. This allow… Booster For Woocommerce 7.1.9+ Fix from $1,9502024-05-02