Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-0195EPSS 19% A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file … Spider Flow No fix yet Fix from $2,3002024-01-02 HIGH 8.8 CVE-2023-39157 Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For El… Jetelements after 2.6.10 Fix from $1,9502023-12-31 CRITICAL 9.8 CVE-2023-41544 SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport… Jeecg Boot after 3.5.3 Fix from $2,3002023-12-30 HIGH 8.8 CVE-2023-51420 Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D… Verge3d after 4.5.2 Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-49830 Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through … Astra after 4.3.1 Fix from $1,9502023-12-29 HIGH 7.2 CVE-2023-45751 Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a th… Nexter Extension after 2.0.3 Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-46623 Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra: from n/a through 6.2. Wp Extra after 6.2 Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-47840 Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential A… Qode Essential Addons after 1.5.2 Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-22677 Improper Control of Generation of Code ('Code Injection') vulnerability in BinaryStash WP Booklet.This issue affects WP Booklet: from n/a through 2.1… Wp Booklet after 2.1.8 Fix from $1,9502023-12-29 CRITICAL 9.8 CVE-2023-25054 Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.… Rsvpmaker after 10.6.6 Fix from $2,3002023-12-29 HIGH 8.8 CVE-2023-32095 Improper Control of Generation of Code ('Code Injection') vulnerability in Milan Dinić Rename Media Files.This issue affects Rename Media Files: from… Rename Media Files after 1.0.1 Fix from $1,9502023-12-29 HIGH 7.2 CVE-2023-40606 Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban… Kanban Boards For Wordpress after 2.5.21 Fix from $1,9502023-12-29 MEDIUM 5.3 CVE-2023-31296 CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive informatio… Cash Point \& Transport Optimizer Mitigation only Fix from $1,6002023-12-29 HIGH 8.1 CVE-2023-7148 A vulnerability has been found in ShifuML shifu 0.12.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the … Shifu No fix yet Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-46987 SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php. Seacms Mitigation only Fix from $1,9502023-12-28 CRITICAL 9.8 CVE-2023-49000 An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis… Artisbrowser after 34.1.5 Fix from $2,3002023-12-27 CRITICAL 9.8 CVE-2023-49001 An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the com.example.gu… Indi Browser Mitigation only Fix from $2,3002023-12-27 CRITICAL 9.8 CVE-2023-43955 The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. This allows attackers to execute… Tv Bro after 2.0.0 Fix from $2,3002023-12-27 CRITICAL 9.8 CVE-2023-47883 The com.altamirano.fabricio.tvbrowser TV browser application through 4.5.1 for Android is vulnerable to JavaScript code execution via an explicit int… Tv Browser after 4.5.1 Fix from $2,3002023-12-27 CRITICAL 9.8 CVE-2023-43481 An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbitrary Ja… Browser Tv Web Browsehere No fix yet Fix from $2,3002023-12-27 HIGH 7.8 CVE-2023-7101 KEVEPSS 17% Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execut… Debian Linux after 0.65 Fix from $1,9502023-12-24 HIGH 8.8 CVE-2023-51387 Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are suppo… Hertzbeat 1.4.1+ Fix from $1,9502023-12-22 CRITICAL 9.8 CVE-2023-51015 TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cst… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51018 TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig i… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-51026 TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg in… Ex1800t Firmware No fix yet Fix from $2,3002023-12-22 HIGH 7.5 CVE-2023-49391 An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF compon… Free5gc No fix yet Fix from $1,9502023-12-22 MEDIUM 5.4 CVE-2023-7035 A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file pac… Automad after 1.10.9 Fix from $1,6002023-12-21 CRITICAL 9.8 CVE-2023-49032 An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack o… Self Service Password 1.5.4+ Fix from $2,3002023-12-21 CRITICAL 9.8 CVE-2023-49004 An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter. Dir 850l Firmware Mitigation only Fix from $2,3002023-12-19 HIGH 7.8 CVE-2023-6691 Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code executi… Epmp Force 300 25 Firmware Mitigation only Fix from $1,9502023-12-18