Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2023-51801 SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to… Simple Student Attendance System No fix yet Fix from $2,3002024-02-29 HIGH 8.6 CVE-2024-25713 yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free … Fedora after 0.8.0 Fix from $1,9502024-02-29 CRITICAL 9.8 CVE-2024-25350 SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters. Zoo Management System No fix yet Fix from $2,3002024-02-28 MEDIUM 6.1 CVE-2024-25202 Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via … User Registration \& Login And User Management System No fix yet Fix from $1,6002024-02-28 HIGH 8.8 CVE-2023-50379 Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cl… Ambari 2.7.8+ Fix from $1,9502024-02-27 CRITICAL 9.8 CVE-2024-1885 This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage. Webos Signage No fix yet Fix from $2,3002024-02-26 CRITICAL 9.8 CVE-2024-22988 ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename … Zkbio Wdms Mitigation only Fix from $2,3002024-02-23 HIGH 8.1 CVE-2024-0220 B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing se… Automation Studio 1.4.0 / 4.6+ Fix from $1,9502024-02-22 HIGH 8.8 CVE-2024-26483 An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF f… Kirby 3.6.6.5 / 3.7.5.4+ Fix from $1,9502024-02-22 HIGH 8.8 CVE-2023-24333 A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via… Ac21 Firmware No fix yet Fix from $1,9502024-02-21 CRITICAL 9.8 CVE-2024-25249 An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments s… He3 App Mitigation only Fix from $2,3002024-02-21 MEDIUM 5.4 CVE-2024-1706 A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. … Zkbio Access Ivs after 3.3.2 Fix from $1,6002024-02-21 HIGH 8.1 CVE-2024-1705 A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/inst… Shopwind after 4.6 Fix from $1,9502024-02-21 HIGH 7.5 CVE-2022-45177 An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/… Vdesk after 031 Fix from $1,9502024-02-21 HIGH 7.2 CVE-2024-21682 This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded… Assets Discovery Data Center 6.2.1+ Fix from $1,9502024-02-20 HIGH 7.5 CVE-2023-51770 Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr… Dolphinscheduler 3.2.1+ Fix from $1,9502024-02-20 CRITICAL 9.8 CVE-2023-49109 Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgr… Dolphinscheduler 3.2.1+ Fix from $2,3002024-02-20 HIGH 7.8 CVE-2024-21892 On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated… Node.js 18.19.1 / 20.11.1+ Fix from $1,9502024-02-20 CRITICAL 9.8 CVE-2023-52381 Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and a… Emui No fix yet Fix from $2,3002024-02-18 HIGH 7.2 CVE-2024-25298 An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php. Redaxo No fix yet Fix from $1,9502024-02-17 HIGH 7.2 CVE-2024-25415EPSS 27% A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via … Ce Phoenix Cart No fix yet Fix from $1,9502024-02-16 CRITICAL 9.8 CVE-2024-25502 Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the do… Flusity No fix yet Fix from $2,3002024-02-15 CRITICAL 9.8 CVE-2022-23088 The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a Fr… FreeBSD 12.3 / 13.0+ Fix from $2,3002024-02-15 HIGH 7.2 CVE-2024-25301 Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php. Redaxo No fix yet Fix from $1,9502024-02-14 HIGH 8.8 CVE-2024-21378EPSS 11% Microsoft Outlook Remote Code Execution Vulnerability 365 Apps Patch available Fix from $1,9502024-02-13 HIGH 7.6 CVE-2024-21351 KEVEPSS 30% Windows SmartScreen Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20469 / 10.0.14393.6709+ Fix from $1,9502024-02-13 MEDIUM 6.1 CVE-2023-50808 Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI. Collaboration 9.0.0+ Fix from $1,6002024-02-13 HIGH 7.2 CVE-2024-22131 In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi… Abap Platform Mitigation only Fix from $1,9502024-02-13 CRITICAL 9.8 CVE-2023-42374 An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted co… Sui 1.6.3+ Fix from $2,3002024-02-13 HIGH 8.1 CVE-2024-25110EPSS 7% The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-aft… Azure Uamqp 2024-02-01+ Fix from $1,9502024-02-12