Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Simple Stock System MEDIUM 6.1
CVE-2025-14962

A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file /market/chatuser.php. This ma…

No fix yet
Fix from $1,600 2025-12-19
Dive CRITICAL 9.6
CVE-2025-66580

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS)…

Fix: 0.11.1+
Fix from $2,300 2025-12-19
Gt Edge Ai CRITICAL 9.8
CVE-2025-63665

An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into…

Fix: 2.0.12+
Fix from $2,300 2025-12-19
Unclassified CRITICAL 9.3
CVE-2025-34433

AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installati…

Patch available
Fix from $2,300 2025-12-19
Azure Container Apps CRITICAL 10.0
CVE-2025-65037

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-12-18
Purview HIGH 7.2
CVE-2025-64676

'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2025-12-18
Unclassified HIGH 7.8
CVE-2023-53940

Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious m…

No fix yet
Fix from $1,950 2025-12-18
Tinacms HIGH 8.8
CVE-2025-68278

Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing att…

Fix: 2.0.3 / 2.0.4+
Fix from $1,950 2025-12-18
Unclassified CRITICAL 9.1
CVE-2025-66078

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote …

Mitigation only
Fix from $2,300 2025-12-18
Unclassified MEDIUM 6.5
CVE-2025-60070

Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This issue affects Molla: from n/a …

Mitigation only
Fix from $1,600 2025-12-18
Unclassified MEDIUM 6.5
CVE-2025-60068

Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code Injection.This issue affects Ja…

Mitigation only
Fix from $1,600 2025-12-18
Ruoyi HIGH 8.8
CVE-2025-14856

A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/get…

Fix: after 4.8.1
Fix from $1,950 2025-12-18
Zzcms HIGH 7.2
CVE-2025-14837

A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Back…

No fix yet
Fix from $1,950 2025-12-18
Churchcrm CRITICAL 9.8
CVE-2025-62521

ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM'…

Fix: 5.21.0+
Fix from $2,300 2025-12-17
Ritecms HIGH 7.2
CVE-2025-67172

RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.

No fix yet
Fix from $1,950 2025-12-17
Pagekit CRITICAL 9.9
CVE-2025-67164

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2025-12-17
Filemaker Server CRITICAL 9.8
CVE-2025-46295

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the t…

Fix: 22.0.4+
Fix from $2,300 2025-12-16
Oneview CRITICAL 9.8
CVE-2025-37164 KEVEPSS 90%

A remote code execution issue exists in HPE OneView.

Fix: after 10.20.00
Fix from $2,300 2025-12-16
Deepchat CRITICAL 9.6
CVE-2025-67744

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerab…

Fix: 0.5.3+
Fix from $2,300 2025-12-16
Fickling HIGH 7.8
CVE-2025-67748

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of uns…

Fix: 0.1.6+
Fix from $1,950 2025-12-16
Ctcms HIGH 7.2
CVE-2025-14729

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_A…

Fix: after 2.1.2
Fix from $1,950 2025-12-15
Ctcms HIGH 7.2
CVE-2025-14730

A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms…

Fix: after 2.1.2
Fix from $1,950 2025-12-15
Webedition Cms HIGH 7.2
CVE-2023-53883

Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page…

No fix yet
Fix from $1,950 2025-12-15
Zomplog HIGH 8.8
CVE-2023-53888

Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file …

No fix yet
Fix from $1,950 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66437

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function rend…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66438

A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, th…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Erpnext HIGH 8.8
CVE-2025-66434

An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function r…

Fix: after 15.89.0
Fix from $1,950 2025-12-15
Mayan Edms MEDIUM 6.1
CVE-2025-14691

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation r…

Fix: 4.10.2+
Fix from $1,600 2025-12-14
Student File Management System MEDIUM 5.4
CVE-2025-14662

A vulnerability was found in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php of the…

No fix yet
Fix from $1,600 2025-12-14
Unclassified MEDIUM 5.4
CVE-2025-14539

The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to …

Mitigation only
Fix from $1,600 2025-12-13