Vulnerabilities (CVE)

Filtered by CWE-94
Total 4461 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38448 2024-11-21 N/A 9.1 CRITICAL
htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.
CVE-2024-38396 2024-11-21 N/A 9.8 CRITICAL
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.
CVE-2024-38395 2024-11-21 N/A 9.8 CRITICAL
In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."
CVE-2024-38319 2024-11-21 N/A 7.5 HIGH
IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.
CVE-2024-37934 1 Ninjaforms 1 Ninja Forms 2024-11-21 N/A 5.4 MEDIUM
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
CVE-2024-37885 2 Apple, Nextcloud 2 Macos, Desktop 2024-11-21 N/A 3.8 LOW
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.
CVE-2024-37855 2024-11-21 N/A 8.4 HIGH
An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary code via the router's Telnet port 2345 without requiring authentication credentials.
CVE-2024-37849 1 Itsourcecode 1 Billing System 2024-11-21 N/A 9.8 CRITICAL
A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.
CVE-2024-37821 2024-11-21 N/A 8.8 HIGH
An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
CVE-2024-37770 2024-11-21 N/A 9.1 CRITICAL
14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.
CVE-2024-37405 2024-11-21 N/A 6.5 MEDIUM
Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.
CVE-2024-37273 1 Homebrew 1 Jan 2024-11-21 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-37124 2024-11-21 N/A 9.8 CRITICAL
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.
CVE-2024-37109 1 Wishlistmember 1 Wishlist Member 2024-11-21 N/A 9.9 CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7.
CVE-2024-37084 1 Vmware 1 Spring Cloud Data Flow 2024-11-21 N/A 9.8 CRITICAL
In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
CVE-2024-37014 1 Langflow 1 Langflow 2024-11-21 N/A 9.8 CRITICAL
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.
CVE-2024-36679 2024-11-21 N/A 10.0 CRITICAL
In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file.
CVE-2024-36598 2024-11-21 N/A 8.1 HIGH
An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.
CVE-2024-36581 2024-11-21 N/A 7.6 HIGH
A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.
CVE-2024-36575 2024-11-21 N/A 9.8 CRITICAL
A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.