CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1mo ago | 9 | Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. |
| Exploit 1mo ago | 9.8 | An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform. |
| Exploit 1mo ago | 9.8 | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17211. |
| 1mo ago | 9.8 | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. |
| Exploit 1mo ago | 9.8 | The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system. |
| 1mo ago | 9.3 | Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress. |
| 1mo ago | 9.6 | Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. |
| 1mo ago | 9.6 | Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
| 1mo ago | 9.1 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2. |
| 1mo ago | 9.8 | This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath) |
| Exploit 1mo ago | 9.8 | The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. |
| 1mo ago | 9.8 | This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function. |
| 1mo ago | 9.8 | This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js. |
| 1mo ago | 9.8 | This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js |
| 1mo ago | 9.4 | This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js. |
| Exploit 1mo ago | 9.8 | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. |
| Exploit 1mo ago | 9.8 | DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. |
| Exploit 1mo ago | 9.8 | An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin. |
| Exploit 1mo ago | 9.9 | The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload. |
| 1mo ago | 9.1 | Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress. |
| Exploit 1mo ago | 9.8 | The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party. |
| Exploit 1mo ago | 9.8 | The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. |
| Exploit 1mo ago | 9.8 | The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. |
| Exploit 1mo ago | 9.8 | The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party. |
| Exploit 1mo ago | 9.8 | The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party. |
| Exploit 1mo ago | 9.8 | The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. |
| Exploit 1mo ago | 9.8 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. |
| Exploit 1mo ago | 9.6 | Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. |
| Exploit 1mo ago | 9.6 | Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| 1mo ago | 9.8 | Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress. |