Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a per… Moodle Mitigation only Fix from $1,6002024-03-22 HIGH 8.8 CVE-2024-28118 Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Gra… Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-28119 Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from gra… Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-28116EPSS 6% Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI… Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-28117 Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDanger… Grav 1.7.45+ Fix from $1,9502024-03-21 MEDIUM 6.6 CVE-2024-22724 An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator prof… Oscommerce No fix yet Fix from $1,6002024-03-21 HIGH 8.8 CVE-2024-2016 A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontr… Zhicms No fix yet Fix from $1,9502024-03-21 MEDIUM 6.6 CVE-2024-25359 An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file. Lagom Mitigation only Fix from $1,6002024-03-21 HIGH 7.8 CVE-2024-24520 An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place. Leptoncms No fix yet Fix from $1,9502024-03-21 HIGH 7.5 CVE-2024-28396 An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component. Orders \(csv\, Excel\) Export Pro after 6.0.2 Fix from $1,9502024-03-20 MEDIUM 6.1 CVE-2024-2610 Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulne… Firefox 115.9.0 / 124.0+ Fix from $1,6002024-03-19 HIGH 7.5 CVE-2024-24230 Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to exec… Mitigation only Fix from $1,9502024-03-18 HIGH 8.8 CVE-2024-28847 OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml… Openmetadata 1.2.4+ Fix from $1,9502024-03-15 HIGH 8.8 CVE-2024-28848EPSS 8% OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml… Openmetadata 1.2.4+ Fix from $1,9502024-03-15 HIGH 8.8 CVE-2024-28253EPSS 13% OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seaml… Openmetadata 1.3.1+ Fix from $1,9502024-03-15 HIGH 7.2 CVE-2024-2497 A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/p… Raspap No fix yet Fix from $1,9502024-03-15 HIGH 8.8 CVE-2024-27756 GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title. Glpi after 10.0.12 Fix from $1,9502024-03-15 HIGH 8.8 CVE-2024-28424 zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. Th… Zenml No fix yet Fix from $1,9502024-03-14 HIGH 7.5 CVE-2022-46070 GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path. Gv Asmanager Mitigation only Fix from $1,9502024-03-11 HIGH 8.6 CVE-2024-23278 The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS… Ipados 10.4 / 13.6.5+ Fix from $1,9502024-03-08 CRITICAL 9.8 CVE-2023-41503 Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function. Student Enrollment Mitigation only Fix from $2,3002024-03-07 CRITICAL 9.8 CVE-2024-0917 remote code execution in paddlepaddle/paddle 2.6.0 Paddlepaddle No fix yet Fix from $2,3002024-03-07 HIGH 7.5 CVE-2024-24278 An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to… Teamwire after 2.4.0 Fix from $1,9502024-03-05 HIGH 7.2 CVE-2024-27622 A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerabil… Cms Made Simple No fix yet Fix from $1,9502024-03-05 MEDIUM 6.1 CVE-2024-27627 A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript cod… No fix yet Fix from $1,6002024-03-05 HIGH 7.2 CVE-2024-22188 TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges o… TYPO3 8.7.57 / 9.5.46+ Fix from $1,9502024-03-05 CRITICAL 9.3 CVE-2024-25293 mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute. Mjml App No fix yet Fix from $2,3002024-03-01 CRITICAL 9.8 CVE-2024-25180 An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is dispu… Pdfmake No fix yet Fix from $2,3002024-02-29 CRITICAL 9.8 CVE-2024-25291 Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin. Deskfiler No fix yet Fix from $2,3002024-02-29 CRITICAL 9.8 CVE-2024-24525 An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the… Epointwebbuilder Mitigation only Fix from $2,3002024-02-29