Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2023-32728 The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability f… Zabbix Agent2 after 6.4.8 Fix from $2,3002023-12-18 CRITICAL 9.8 CVE-2023-6899 A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of t… Dashmachine No fix yet Fix from $2,3002023-12-17 CRITICAL 9.8 CVE-2023-6886 A vulnerability was found in xnx3 wangmarket 6.1. It has been rated as critical. Affected by this issue is some unknown functionality of the componen… Wangmarket Mitigation only Fix from $2,3002023-12-17 CRITICAL 9.8 CVE-2023-6851 A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been rated as critical. This issue affects the function unzipList of the fil… Kodexplorer 4.52.01+ Fix from $2,3002023-12-16 HIGH 8.8 CVE-2023-50723 XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wi… Xwiki 14.10.5 / 15.5.2+ Fix from $1,9502023-12-15 HIGH 8.8 CVE-2023-50721EPSS 79% XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration inte… Xwiki 14.10.5 / 15.5.2+ Fix from $1,9502023-12-15 MEDIUM 5.7 CVE-2023-5512 An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versi… GitLab 16.4.4 / 16.5.4+ Fix from $1,6002023-12-15 MEDIUM 6.5 CVE-2023-6051 An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starti… GitLab 16.4.4 / 16.5.4+ Fix from $1,6002023-12-15 CRITICAL 9.8 CVE-2023-6553EPSS 98% The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup… Backup Migration after 1.3.7 Fix from $2,3002023-12-15 CRITICAL 9.8 CVE-2023-48390 Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject code and acce… Easylog Web\+ Firmware Mitigation only Fix from $2,3002023-12-15 CRITICAL 9.8 CVE-2023-48085EPSS 76% Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php. Nagios Xi 5.11.3+ Fix from $2,3002023-12-14 CRITICAL 9.8 CVE-2023-43364 main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution. Searchor 2.4.2+ Fix from $2,3002023-12-12 HIGH 8.8 CVE-2023-42890 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2,… Safari 10.2 / 14.2+ Fix from $1,9502023-12-12 HIGH 8.8 CVE-2023-5500 This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full con… Frauscher Diagnostic System 102 2.10.2+ Fix from $1,9502023-12-11 HIGH 8.2 CVE-2023-43301 An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access toke… Line No fix yet Fix from $1,9502023-12-07 HIGH 7.8 CVE-2023-6288 Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environmen… Remote Desktop Manager 2023.3.10.2+ Fix from $1,9502023-12-06 CRITICAL 9.8 CVE-2023-49070EPSS 95% Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Us… Ofbiz 18.12.10+ Fix from $2,3002023-12-05 HIGH 8.8 CVE-2023-5762 The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execut… Filr 1.2.3.6+ Fix from $1,9502023-12-04 HIGH 8.8 CVE-2023-49093 HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpag… Htmlunit 3.9.0+ Fix from $1,9502023-12-04 CRITICAL 9.1 CVE-2023-44382 October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms… October 3.4.15+ Fix from $2,3002023-12-01 HIGH 7.5 CVE-2023-5226 An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting fro… GitLab 16.4.3 / 16.5.3+ Fix from $1,9502023-12-01 CRITICAL 9.8 CVE-2022-42541 Remote code execution Android No fix yet Fix from $2,3002023-11-29 CRITICAL 9.8 CVE-2023-49313 A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected … Xmachoviewer No fix yet Fix from $2,3002023-11-28 HIGH 7.8 CVE-2023-49314 Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through … Desktop Mitigation only Fix from $1,9502023-11-28 CRITICAL 9.8 CVE-2023-46480 An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the ind… Owncast Mitigation only Fix from $2,3002023-11-27 CRITICAL 9.8 CVE-2023-5604 The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configu… Asgaros Forum 2.7.1+ Fix from $2,3002023-11-27 HIGH 7.2 CVE-2021-22150 It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, th… Kibana 7.14.1+ Fix from $1,9502023-11-22 CRITICAL 9.8 CVE-2023-48699 fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker… Fastbots 0.1.5+ Fix from $2,3002023-11-21 CRITICAL 9.8 CVE-2023-6248 The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to ex… Syrus 4g Iot Telematics Gateway Firmware Mitigation only Fix from $2,3002023-11-21 HIGH 7.8 CVE-2023-48192 An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function. A3700r Firmware No fix yet Fix from $1,9502023-11-20