Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-3660
A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions…
Keras
2.13.1+
MEDIUM 6.3
CVE-2024-30567
An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting f…
Mitigation only
MEDIUM 6.1
CVE-2024-31648
Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payloa…
Insurance Management System
No fix yet
MEDIUM 6.6
CVE-2024-3784
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts…
Wbsairback
Mitigation only
MEDIUM 6.6
CVE-2024-3785
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin…
Wbsairback
Mitigation only
MEDIUM 6.6
CVE-2024-3786
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/D…
Wbsairback
Mitigation only
MEDIUM 6.1
CVE-2024-30845
Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation …
Rainbow External Link Network Disk
No fix yet
HIGH 8.1
CVE-2023-44857
An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the…
Sailor 600 Vsat Ku Firmware
No fix yet
HIGH 7.8
CVE-2024-25376
An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbi…
Tusbaudio
5.68.0+
HIGH 7.2
CVE-2024-22722
Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the…
Form Tools
No fix yet
HIGH 7.6
CVE-2024-29399
An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted fil…
Savane
after 3.13
CRITICAL 9.8
CVE-2024-21508
Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of …
Patch available
MEDIUM 6.1
CVE-2024-30878
A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensiti…
Rageframe
No fix yet
CRITICAL 9.8
CVE-2024-29937
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via…
FreeBSD
after 7.4
CRITICAL 9.8
CVE-2024-31996
XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…
Xwiki
14.10.19 / 15.5.4+
HIGH 8.8
CVE-2024-26362
HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via cr…
Password Manager
No fix yet
CRITICAL 9.8
CVE-2024-31819EPSS 16%
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.…
Avideo
after 14.2
CRITICAL 9.8
CVE-2024-31982EPSS 34%
XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…
Xwiki
14.10.20 / 15.5.4+
HIGH 8.8
CVE-2024-31984EPSS 83%
XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document…
Xwiki
14.10.20 / 15.5.4+
CRITICAL 9.8
CVE-2024-29500
An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce …
Secure Lockdown
No fix yet
HIGH 8.8
CVE-2024-31465EPSS 76%
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit rig…
Xwiki
14.10.20 / 15.5.4+
CRITICAL 9.8
CVE-2024-3098
A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for pro…
Patch available
CRITICAL 9.8
CVE-2024-2195
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endp…
Aim
No fix yet
CRITICAL 9.8
CVE-2024-31864
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.
The attacker can inject sensitive configuration or malic…
Zeppelin
0.11.1+
MEDIUM 6.7
CVE-2023-47542
A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below…
Fortimanager
7.0.11 / 7.2.5+
HIGH 8.8
CVE-2023-45590
An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4…
Forticlient
7.0.11+
CRITICAL 9.8
CVE-2024-31807
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSync…
Ex200 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-31022
An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component.
Candycms
Mitigation only
MEDIUM 6.1
CVE-2024-25706
There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL wh…
Portal For Arcgis
after 11.0
CRITICAL 9.8
CVE-2023-36645
SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.
Tradepro
No fix yet