Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-24091
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
Yealink Meeting Server
26.0.0.66+
HIGH 8.0
CVE-2023-45735
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the d…
L206 F2g Firmware
No fix yet
HIGH 8.8
CVE-2024-22514
An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.
Agent Dvr
Mitigation only
HIGH 8.8
CVE-2023-6996
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_dis…
Display Custom Fields In The Frontend Post And User Profile Fields
1.3.0+
HIGH 8.8
CVE-2023-6846EPSS 16%
The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_fileman…
File Manager
after 8.3.4
MEDIUM 6.1
CVE-2024-24396
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code vi…
Dashboard.js
2024.1.2+
HIGH 8.8
CVE-2024-24469
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
Flusity
No fix yet
HIGH 8.8
CVE-2023-5677
Brandon
Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi
did not have a sufficient input validatio…
M3024 Lve Firmware
5.51.7.7+
HIGH 8.8
CVE-2023-5800
Vintage,
member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi
did not have a sufficient input validation allowin…
Axis Os
9.80.55 / 10.12.220+
CRITICAL 9.8
CVE-2024-25089
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
Binisoft Windows Firewall Control
6.9.9.2+
CRITICAL 9.8
CVE-2023-50488
An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.
Lumi Security Camera A31c Firmware
No fix yet
MEDIUM 6.8
CVE-2023-51820
An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.
Lumi Security Camera A31c Firmware
No fix yet
HIGH 7.8
CVE-2021-22282
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code…
Automation Studio
after 4.12
CRITICAL 9.8
CVE-2024-22533
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, …
Beetl
No fix yet
HIGH 8.8
CVE-2024-22899
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
Vinchin Backup And Recovery
after 7.2
CRITICAL 9.8
CVE-2024-23746
Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a k…
Miro
No fix yet
HIGH 8.1
CVE-2023-47257
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Automate
23.8.5+
HIGH 7.8
CVE-2024-0325
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.
Helix Sync
2024.1+
CRITICAL 9.8
CVE-2024-1117
A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the function index of the file /…
Openbi
after 1.0.8
HIGH 8.8
CVE-2024-21649
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). P…
Vantage6
4.2.0+
HIGH 8.8
CVE-2023-37518
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the …
Bigfix Servicenow Data Flow
1.3+
CRITICAL 9.8
CVE-2024-1015
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different comman…
E Ddc3.3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-23741
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArgu…
Hyper
after 3.4.1
CRITICAL 9.8
CVE-2024-23742
An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArg…
Loom
after 0.196.1
HIGH 8.8
CVE-2023-52251EPSS 85%
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/…
Ui
after 0.7.1
HIGH 7.2
CVE-2023-24676
An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when …
Processwire
No fix yet
HIGH 7.2
CVE-2023-31037
NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A succ…
Bluefield Bmc
Mitigation only
CRITICAL 9.8
CVE-2023-36177EPSS 27%
An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via craft…
Snapcast
after 0.27.0
HIGH 8.8
CVE-2024-0755
Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we p…
Firefox
115.7 / 122.0+
HIGH 7.8
CVE-2024-23208
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A…
Ipados
10.3 / 14.3+