Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2024-30565 An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php. Seacms No fix yet Fix from $1,9502024-04-04 HIGH 7.6 CVE-2024-27705 Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse e… Leantime No fix yet Fix from $1,9502024-04-03 CRITICAL 9.8 CVE-2024-25096 Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a … Canto after 3.0.7 Fix from $2,3002024-04-03 CRITICAL 9.8 CVE-2024-30568EPSS 47% Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter. R6850 Firmware No fix yet Fix from $2,3002024-04-03 CRITICAL 9.9 CVE-2024-24707 Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly… Mitigation only Fix from $2,3002024-04-03 CRITICAL 9.9 CVE-2024-31390 : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance:… Mitigation only Fix from $2,3002024-04-03 HIGH 8.8 CVE-2024-29477 Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to e… Dolibarr Erp\/crm 19.0.1+ Fix from $1,9502024-04-03 CRITICAL 9.9 CVE-2024-31380 Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, re… No fix yet Fix from $2,3002024-04-03 CRITICAL 9.9 CVE-2024-27972 Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lit… Mitigation only Fix from $2,3002024-04-03 HIGH 8.5 CVE-2024-27191 Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender allows Remote Code Inclusion… Mitigation only Fix from $1,9502024-04-03 HIGH 8.8 CVE-2024-25918 Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect… Instawp Connect 0.1.0.9+ Fix from $1,9502024-04-03 CRITICAL 9.8 CVE-2024-31011 Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the… Beescms No fix yet Fix from $2,3002024-04-03 HIGH 8.1 CVE-2024-31005 An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment Bento4 No fix yet Fix from $1,9502024-04-02 CRITICAL 9.8 CVE-2024-31004 An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragmen… Bento4 No fix yet Fix from $2,3002024-04-02 HIGH 8.8 CVE-2024-31003 Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WriteParti… Bento4 No fix yet Fix from $1,9502024-04-02 CRITICAL 9.8 CVE-2024-29276EPSS 33% An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerCont… Mitigation only Fix from $2,3002024-04-02 CRITICAL 9.8 CVE-2024-30858 netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php. Ns Asg Firmware No fix yet Fix from $2,3002024-04-01 CRITICAL 9.8 CVE-2024-30868 netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php. Ns Asg Firmware No fix yet Fix from $2,3002024-04-01 HIGH 8.8 CVE-2023-41724EPSS 13% A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlyin… Standalone Sentry 9.19.0+ Fix from $1,9502024-03-31 CRITICAL 9.8 CVE-2024-31032 An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code v… Mitigation only Fix from $2,3002024-03-29 CRITICAL 9.9 CVE-2024-29202EPSS 6% JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection v… Jumpserver 3.10.7+ Fix from $2,3002024-03-29 CRITICAL 9.9 CVE-2024-29201EPSS 6% JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism… Jumpserver 3.10.7+ Fix from $2,3002024-03-29 HIGH 8.4 CVE-2024-23727 The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScri… Mitigation only Fix from $1,9502024-03-28 HIGH 7.5 CVE-2024-2097 An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and exe… Mitigation only Fix from $1,9502024-03-27 HIGH 7.5 CVE-2024-0400 SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filt… Mitigation only Fix from $1,9502024-03-27 MEDIUM 6.3 CVE-2024-2209 A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update … 26k70b Firmware 2349c / 2349d+ Fix from $1,6002024-03-27 HIGH 8.1 CVE-2024-0866 The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_… Mitigation only Fix from $1,9502024-03-26 HIGH 7.8 CVE-2024-30202 In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23. Emacs 9.6.23 / 29.3+ Fix from $1,9502024-03-25 CRITICAL 9.8 CVE-2024-28386 An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component. Fastmag Sync after 1.7.51 Fix from $2,3002024-03-25 HIGH 8.8 CVE-2024-23755 ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against c… Clickup 3.3.77+ Fix from $1,9502024-03-23