Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.5 CVE-2024-3734 The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and… Mitigation only Fix from $1,6002024-05-02 HIGH 7.7 CVE-2024-29309 An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service. Mitigation only Fix from $1,9502024-05-02 CRITICAL 9.8 CVE-2024-3955 URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subsequently passed to the "os.sy… Mitigation only Fix from $2,3002024-05-02 HIGH 8.8 CVE-2024-33430 An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file. Phiola No fix yet Fix from $1,9502024-05-01 HIGH 7.7 CVE-2024-28893 Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified … Softpaqs Mitigation only Fix from $1,9502024-05-01 HIGH 7.1 CVE-2024-33443 An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component. Onethink No fix yet Fix from $1,9502024-04-29 CRITICAL 9.8 CVE-2024-31822 An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via… Ecommerce Codeigniter Bootstrap 2024-01-02+ Fix from $2,3002024-04-29 HIGH 8.8 CVE-2024-31823 An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via… Ecommerce Codeigniter Bootstrap Patch available Fix from $1,9502024-04-29 HIGH 7.6 CVE-2024-31621EPSS 60% An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component. Flowise after 1.6.5 Fix from $1,9502024-04-29 CRITICAL 9.8 CVE-2024-32491 An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a ma… Znuny after 7.0.16 Fix from $2,3002024-04-29 HIGH 7.1 CVE-2024-32492 An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript. Znuny after 7.0.16 Fix from $1,9502024-04-29 CRITICAL 9.8 CVE-2024-33445 An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the Sy… Hisiphp No fix yet Fix from $2,3002024-04-29 MEDIUM 6.0 CVE-2024-32404 Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafte… Relate 2024.1+ Fix from $1,6002024-04-26 CRITICAL 9.8 CVE-2024-22632 Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hm… No fix yet Fix from $2,3002024-04-26 CRITICAL 9.8 CVE-2024-22633 Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hp… Mitigation only Fix from $2,3002024-04-26 HIGH 7.5 CVE-2024-32358 An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different… Jpress Mitigation only Fix from $1,9502024-04-25 MEDIUM 6.8 CVE-2024-25624 Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of … Iris 2.4.6+ Fix from $1,6002024-04-25 CRITICAL 9.0 CVE-2024-22144 Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows C… No fix yet Fix from $2,3002024-04-25 CRITICAL 9.1 CVE-2024-31266 Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommerce allows Code Injection.This… Mitigation only Fix from $2,3002024-04-25 MEDIUM 6.0 CVE-2024-20359 KEVEPSS 19% A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secu… Adaptive Security Appliance Software Mitigation only Fix from $1,6002024-04-24 CRITICAL 9.8 CVE-2024-21511 Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the … Patch available Fix from $2,3002024-04-23 CRITICAL 10.0 CVE-2024-4040 KEVEPSS 100% A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote at… Crushftp 10.7.1 / 11.1.0+ Fix from $2,3002024-04-22 CRITICAL 9.8 CVE-2024-31666 An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component. Flusity No fix yet Fix from $2,3002024-04-22 HIGH 7.8 CVE-2024-28699 A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutp… No fix yet Fix from $1,9502024-04-22 MEDIUM 5.0 CVE-2024-29991 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Edge Chromium 124.0.2478.51+ Fix from $1,6002024-04-19 MEDIUM 6.7 CVE-2023-51797 Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:7… Fedora Mitigation only Fix from $1,6002024-04-19 HIGH 8.8 CVE-2023-50260EPSS 41% Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to … Wazuh 4.7.2+ Fix from $1,9502024-04-19 CRITICAL 9.8 CVE-2024-30923 SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rend… Derbynet after 9.0 Fix from $2,3002024-04-18 CRITICAL 10.0 CVE-2024-32599 Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator.This is… Mitigation only Fix from $2,3002024-04-18 MEDIUM 5.4 CVE-2024-3931 A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the fil… Totara 13.46 / 14.38+ Fix from $1,6002024-04-18