Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-3660 A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions… Keras 2.13.1+ Fix from $2,3002024-04-16 MEDIUM 6.3 CVE-2024-30567 An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting f… Mitigation only Fix from $1,6002024-04-16 MEDIUM 6.1 CVE-2024-31648 Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payloa… Insurance Management System No fix yet Fix from $1,6002024-04-15 MEDIUM 6.6 CVE-2024-3784 Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts… Wbsairback Mitigation only Fix from $1,6002024-04-15 MEDIUM 6.6 CVE-2024-3785 Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin… Wbsairback Mitigation only Fix from $1,6002024-04-15 MEDIUM 6.6 CVE-2024-3786 Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/D… Wbsairback Mitigation only Fix from $1,6002024-04-15 MEDIUM 6.1 CVE-2024-30845 Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation … Rainbow External Link Network Disk No fix yet Fix from $1,6002024-04-12 HIGH 8.1 CVE-2023-44857 An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the… Sailor 600 Vsat Ku Firmware No fix yet Fix from $1,9502024-04-12 HIGH 7.8 CVE-2024-25376 An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbi… Tusbaudio 5.68.0+ Fix from $1,9502024-04-11 HIGH 7.2 CVE-2024-22722 Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the… Form Tools No fix yet Fix from $1,9502024-04-11 HIGH 7.6 CVE-2024-29399 An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted fil… Savane after 3.13 Fix from $1,9502024-04-11 CRITICAL 9.8 CVE-2024-21508 Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of … Patch available Fix from $2,3002024-04-11 MEDIUM 6.1 CVE-2024-30878 A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensiti… Rageframe No fix yet Fix from $1,6002024-04-11 CRITICAL 9.8 CVE-2024-29937 NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via… FreeBSD after 7.4 Fix from $2,3002024-04-11 CRITICAL 9.8 CVE-2024-31996 XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca… Xwiki 14.10.19 / 15.5.4+ Fix from $2,3002024-04-10 HIGH 8.8 CVE-2024-26362 HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via cr… Password Manager No fix yet Fix from $1,9502024-04-10 CRITICAL 9.8 CVE-2024-31819EPSS 16% An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.… Avideo after 14.2 Fix from $2,3002024-04-10 CRITICAL 9.8 CVE-2024-31982EPSS 34% XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas… Xwiki 14.10.20 / 15.5.4+ Fix from $2,3002024-04-10 HIGH 8.8 CVE-2024-31984EPSS 83% XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document… Xwiki 14.10.20 / 15.5.4+ Fix from $1,9502024-04-10 CRITICAL 9.8 CVE-2024-29500 An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce … Secure Lockdown No fix yet Fix from $2,3002024-04-10 HIGH 8.8 CVE-2024-31465EPSS 76% XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit rig… Xwiki 14.10.20 / 15.5.4+ Fix from $1,9502024-04-10 CRITICAL 9.8 CVE-2024-3098 A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for pro… Patch available Fix from $2,3002024-04-10 CRITICAL 9.8 CVE-2024-2195 A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endp… Aim No fix yet Fix from $2,3002024-04-10 CRITICAL 9.8 CVE-2024-31864 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malic… Zeppelin 0.11.1+ Fix from $2,3002024-04-09 MEDIUM 6.7 CVE-2023-47542 A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below… Fortimanager 7.0.11 / 7.2.5+ Fix from $1,6002024-04-09 HIGH 8.8 CVE-2023-45590 An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4… Forticlient 7.0.11+ Fix from $1,9502024-04-09 CRITICAL 9.8 CVE-2024-31807 TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSync… Ex200 Firmware No fix yet Fix from $2,3002024-04-08 CRITICAL 9.8 CVE-2024-31022 An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component. Candycms Mitigation only Fix from $2,3002024-04-08 MEDIUM 6.1 CVE-2024-25706 There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL wh… Portal For Arcgis after 11.0 Fix from $1,6002024-04-04 CRITICAL 9.8 CVE-2023-36645 SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function. Tradepro No fix yet Fix from $2,3002024-04-04