Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-24091 Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface. Yealink Meeting Server 26.0.0.66+ Fix from $2,3002024-02-08 HIGH 8.0 CVE-2023-45735 A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the d… L206 F2g Firmware No fix yet Fix from $1,9502024-02-06 HIGH 8.8 CVE-2024-22514 An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file. Agent Dvr Mitigation only Fix from $1,9502024-02-06 HIGH 8.8 CVE-2023-6996 The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_dis… Display Custom Fields In The Frontend Post And User Profile Fields 1.3.0+ Fix from $1,9502024-02-05 HIGH 8.8 CVE-2023-6846EPSS 16% The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_fileman… File Manager after 8.3.4 Fix from $1,9502024-02-05 MEDIUM 6.1 CVE-2024-24396 Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code vi… Dashboard.js 2024.1.2+ Fix from $1,6002024-02-05 HIGH 8.8 CVE-2024-24469 Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php. Flusity No fix yet Fix from $1,9502024-02-05 HIGH 8.8 CVE-2023-5677 Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validatio… M3024 Lve Firmware 5.51.7.7+ Fix from $1,9502024-02-05 HIGH 8.8 CVE-2023-5800 Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowin… Axis Os 9.80.55 / 10.12.220+ Fix from $1,9502024-02-05 CRITICAL 9.8 CVE-2024-25089 Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes. Binisoft Windows Firewall Control 6.9.9.2+ Fix from $2,3002024-02-04 CRITICAL 9.8 CVE-2023-50488 An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code. Lumi Security Camera A31c Firmware No fix yet Fix from $2,3002024-02-02 MEDIUM 6.8 CVE-2023-51820 An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code. Lumi Security Camera A31c Firmware No fix yet Fix from $1,6002024-02-02 HIGH 7.8 CVE-2021-22282 Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code… Automation Studio after 4.12 Fix from $1,9502024-02-02 CRITICAL 9.8 CVE-2024-22533 Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, … Beetl No fix yet Fix from $2,3002024-02-02 HIGH 8.8 CVE-2024-22899 Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function. Vinchin Backup And Recovery after 7.2 Fix from $1,9502024-02-02 CRITICAL 9.8 CVE-2024-23746 Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a k… Miro No fix yet Fix from $2,3002024-02-02 HIGH 8.1 CVE-2023-47257 ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. Automate 23.8.5+ Fix from $1,9502024-02-01 HIGH 7.8 CVE-2024-0325 In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.   Helix Sync 2024.1+ Fix from $1,9502024-02-01 CRITICAL 9.8 CVE-2024-1117 A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the function index of the file /… Openbi after 1.0.8 Fix from $2,3002024-01-31 HIGH 8.8 CVE-2024-21649 The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). P… Vantage6 4.2.0+ Fix from $1,9502024-01-30 HIGH 8.8 CVE-2023-37518 HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the … Bigfix Servicenow Data Flow 1.3+ Fix from $1,9502024-01-30 CRITICAL 9.8 CVE-2024-1015 Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different comman… E Ddc3.3 Firmware Mitigation only Fix from $2,3002024-01-29 CRITICAL 9.8 CVE-2024-23741 An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArgu… Hyper after 3.4.1 Fix from $2,3002024-01-28 CRITICAL 9.8 CVE-2024-23742 An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArg… Loom after 0.196.1 Fix from $2,3002024-01-28 HIGH 8.8 CVE-2023-52251EPSS 85% An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/… Ui after 0.7.1 Fix from $1,9502024-01-25 HIGH 7.2 CVE-2023-24676 An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when … Processwire No fix yet Fix from $1,9502024-01-24 HIGH 7.2 CVE-2023-31037 NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A succ… Bluefield Bmc Mitigation only Fix from $1,9502024-01-24 CRITICAL 9.8 CVE-2023-36177EPSS 27% An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via craft… Snapcast after 0.27.0 Fix from $2,3002024-01-23 HIGH 8.8 CVE-2024-0755 Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we p… Firefox 115.7 / 122.0+ Fix from $1,9502024-01-23 HIGH 7.8 CVE-2024-23208 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A… Ipados 10.3 / 14.3+ Fix from $1,9502024-01-23