Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2024-23750 MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Pop… Metagpt after 0.6.4 Fix from $1,9502024-01-22 HIGH 7.8 CVE-2024-0521 Code Injection in paddlepaddle/paddle Paddle Patch available Fix from $1,9502024-01-20 CRITICAL 9.8 CVE-2024-0738 A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the fil… Mldong No fix yet Fix from $2,3002024-01-19 HIGH 8.1 CVE-2023-50447 Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817… Pillow after 10.1.0 Fix from $1,9502024-01-19 HIGH 8.8 CVE-2023-6548 KEV Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP… Netscaler Application Delivery Controller 12.1-55.302 / 13.0-92.21+ Fix from $1,9502024-01-17 CRITICAL 9.8 CVE-2021-4434 The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. T… Social Warfare 3.5.3+ Fix from $2,3002024-01-17 HIGH 7.8 CVE-2023-22514 This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. … Sourcetree 3.4.15 / 4.2.5+ Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2022-1609EPSS 64% The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API … School Management 9.9.7+ Fix from $2,3002024-01-16 CRITICAL 9.8 CVE-2023-6395 The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary co… Fedora Patch available Fix from $2,3002024-01-16 HIGH 8.8 CVE-2024-21672 This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execu… Confluence Data Center 7.19.18 / 8.5.5+ Fix from $1,9502024-01-16 HIGH 8.8 CVE-2024-21673 This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Exe… Confluence Data Center 7.19.18 / 8.5.5+ Fix from $1,9502024-01-16 HIGH 7.5 CVE-2024-21674 This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Exec… Confluence Data Center 7.19.18 / 8.5.5+ Fix from $1,9502024-01-16 HIGH 8.8 CVE-2023-22526 This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Exe… Confluence Data Center 7.19.17 / 8.5.5+ Fix from $1,9502024-01-16 HIGH 8.8 CVE-2023-43449 An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/L… Hummerrisk after 1.4.1 Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-51282 An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter. Mcms No fix yet Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2023-46226 Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to v… Iotdb 1.3.0+ Fix from $2,3002024-01-15 HIGH 8.8 CVE-2023-51066 An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily e… Archive Storage Manager No fix yet Fix from $1,9502024-01-13 HIGH 8.8 CVE-2023-33472 An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileg… Scada Lts after 2.7.5.2 Fix from $1,9502024-01-13 HIGH 8.8 CVE-2024-0252EPSS 8% ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer… Manageengine Adselfservice Plus 6.4+ Fix from $1,9502024-01-11 HIGH 8.8 CVE-2023-42833 A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web conte… Safari 14.0 / 17.0+ Fix from $1,9502024-01-10 HIGH 7.8 CVE-2023-32383 This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed in macOS Monterey 12.6.6, macO… macOS 11.7.7 / 12.6.6+ Fix from $1,9502024-01-10 HIGH 8.8 CVE-2024-21643 IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's i… Identitymodel Extensions 6.34.0 / 7.1.2+ Fix from $1,9502024-01-10 CRITICAL 9.1 CVE-2024-21737 In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers… Application Interface Framework Mitigation only Fix from $2,3002024-01-09 CRITICAL 9.8 CVE-2024-21646EPSS 5% Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When… Azure Uamqp 2024-01-01+ Fix from $2,3002024-01-09 CRITICAL 9.8 CVE-2024-21650EPSS 93% XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code executi… Xwiki 14.10.17 / 15.5.3+ Fix from $2,3002024-01-08 HIGH 7.8 CVE-2023-7224 OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARI… Connect after 3.4.6 Fix from $1,9502024-01-08 HIGH 7.5 CVE-2023-6540 A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that… Browser Hd 2.1.4.1 / 9.1.3.1+ Fix from $1,9502024-01-03 CRITICAL 9.8 CVE-2023-51784 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, … Inlong 1.10.0+ Fix from $2,3002024-01-03 HIGH 7.8 CVE-2023-41783 There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker co… Zxcloud Irai 7.23.32+ Fix from $1,9502024-01-03 HIGH 8.8 CVE-2024-0196 A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the… Magic Api after 2.0.1 Fix from $1,9502024-01-02