Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2024-3734
The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and…
Mitigation only
HIGH 7.7
CVE-2024-29309
An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.
Mitigation only
CRITICAL 9.8
CVE-2024-3955
URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subsequently passed to the "os.sy…
Mitigation only
HIGH 8.8
CVE-2024-33430
An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.
Phiola
No fix yet
HIGH 7.7
CVE-2024-28893
Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified …
Softpaqs
Mitigation only
HIGH 7.1
CVE-2024-33443
An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.
Onethink
No fix yet
CRITICAL 9.8
CVE-2024-31822
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via…
Ecommerce Codeigniter Bootstrap
2024-01-02+
HIGH 8.8
CVE-2024-31823
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via…
Ecommerce Codeigniter Bootstrap
Patch available
HIGH 7.6
CVE-2024-31621EPSS 60%
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
Flowise
after 1.6.5
CRITICAL 9.8
CVE-2024-32491
An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a ma…
Znuny
after 7.0.16
HIGH 7.1
CVE-2024-32492
An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript.
Znuny
after 7.0.16
CRITICAL 9.8
CVE-2024-33445
An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the Sy…
Hisiphp
No fix yet
MEDIUM 6.0
CVE-2024-32404
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafte…
Relate
2024.1+
CRITICAL 9.8
CVE-2024-22632
Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hm…
No fix yet
CRITICAL 9.8
CVE-2024-22633
Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hp…
Mitigation only
HIGH 7.5
CVE-2024-32358
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different…
Jpress
Mitigation only
MEDIUM 6.8
CVE-2024-25624
Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of …
Iris
2.4.6+
CRITICAL 9.0
CVE-2024-22144
Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows C…
No fix yet
CRITICAL 9.1
CVE-2024-31266
Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommerce allows Code Injection.This…
Mitigation only
MEDIUM 6.0
CVE-2024-20359 KEVEPSS 19%
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secu…
Adaptive Security Appliance Software
Mitigation only
CRITICAL 9.8
CVE-2024-21511
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the …
Patch available
CRITICAL 10.0
CVE-2024-4040 KEVEPSS 100%
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote at…
Crushftp
10.7.1 / 11.1.0+
CRITICAL 9.8
CVE-2024-31666
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.
Flusity
No fix yet
HIGH 7.8
CVE-2024-28699
A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutp…
No fix yet
MEDIUM 5.0
CVE-2024-29991
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Edge Chromium
124.0.2478.51+
MEDIUM 6.7
CVE-2023-51797
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:7…
Fedora
Mitigation only
HIGH 8.8
CVE-2023-50260EPSS 41%
Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to …
Wazuh
4.7.2+
CRITICAL 9.8
CVE-2024-30923
SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rend…
Derbynet
after 9.0
CRITICAL 10.0
CVE-2024-32599
Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator.This is…
Mitigation only
MEDIUM 5.4
CVE-2024-3931
A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the fil…
Totara
13.46 / 14.38+