Vulnerability index

Browse CVEs

1,274 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Electronic Lab Notebook HIGH 8.8
CVE-2023-24217

AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.

No fix yet
Fix from $1,950 2023-03-06
Flatpress CRITICAL 9.8
CVE-2022-4606EPSS 35%

PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: after 1.2.1
Fix from $2,300 2022-12-18
Corebos CRITICAL 9.8
CVE-2022-4446

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

Fix: 8.0+
Fix from $2,300 2022-12-13
Appalti \& Contratti HIGH 7.5
CVE-2022-44786

An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href paramet…

No fix yet
Fix from $1,950 2022-11-21
Mobile Security Framework HIGH 7.5
CVE-2022-41547

Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.p…

Fix: after 0.9.2
Fix from $1,950 2022-10-18
Simple College Website CRITICAL 9.8
CVE-2022-40089

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vu…

No fix yet
Fix from $2,300 2022-09-22
Concrete Cms HIGH 7.2
CVE-2021-22968

A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versio…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
R Seenet CRITICAL 9.8
CVE-2021-21804

A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr…

No fix yet
Fix from $2,300 2021-07-16
Cloud Access Connector HIGH 7.5
CVE-2020-13175

The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earli…

Fix: 2020-04-20+
Fix from $1,950 2020-08-11
Larvitbase HIGH 7.5
CVE-2019-5479

An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).

Fix: 0.5.5+
Fix from $1,950 2019-09-03
Experion Process Knowledge System CRITICAL 9.8
CVE-2014-9186

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.…

Mitigation only
Fix from $2,300 2019-04-08
Bmxnoc0401 Firmware MEDIUM 5.4
CVE-2015-6461

Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNO…

Mitigation only
Fix from $1,600 2019-03-21
Nextgen Gallery HIGH 7.5
CVE-2016-6565

The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POS…

Fix: 2.1.57+
Fix from $1,950 2018-07-13
Smart Protection Server HIGH 8.1
CVE-2017-14095EPSS 12%

A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command executio…

Fix: after 3.2
Fix from $1,950 2018-01-19