Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 8.4
CVE-2025-67750

Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.…

Patch available
Fix from $1,950 2025-12-12
Qualitor MEDIUM 6.1
CVE-2025-14580

A security vulnerability has been detected in Qualitor up to 8.24.73. The impacted element is an unknown function of the file /Qualitor/html/bc/bcdoc…

Fix: 8.20.78 / 8.24.74+
Fix from $1,600 2025-12-12
Mineadmin CRITICAL 9.8
CVE-2025-65854

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeo…

Fix: 3.0+
Fix from $2,300 2025-12-12
Wave Terminal MEDIUM 5.5
CVE-2025-12843

Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.

No fix yet
Fix from $1,600 2025-12-12
Parse Server CRITICAL 9.8
CVE-2025-67727

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI …

Fix: after 8.5.0
Fix from $2,300 2025-12-12
Unclassified MEDIUM 5.3
CVE-2025-14166

The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin …

Mitigation only
Fix from $1,600 2025-12-12
Pgadmin 4 HIGH 8.8
CVE-2025-13780

pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restor…

Fix: after 9.10
Fix from $1,950 2025-12-11
Pdf Editor HIGH 7.8
CVE-2025-55313

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code executi…

Fix: after 2025.1.0.66692
Fix from $1,950 2025-12-11
Hfly MEDIUM 5.4
CVE-2025-14519

A security flaw has been discovered in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. This issue affects some unknown processing of the …

Fix: after 2016-05-11
Fix from $1,600 2025-12-11
Neuron HIGH 8.2
CVE-2025-67509

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only B…

Fix: 2.8.12+
Fix from $1,950 2025-12-10
Xwiki Rendering HIGH 8.8
CVE-2025-66474

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)…

Fix: 16.10.10 / 17.4.3+
Fix from $1,950 2025-12-10
Hub M2 Firmware CRITICAL 9.8
CVE-2025-65294

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabli…

Mitigation only
Fix from $2,300 2025-12-10
Popojicms HIGH 7.2
CVE-2024-58284

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code throug…

No fix yet
Fix from $1,950 2025-12-10
Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware MEDIUM 6.8
CVE-2025-65829

The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only…

Mitigation only
Fix from $1,600 2025-12-10
Chancms CRITICAL 9.8
CVE-2025-65602

A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST…

Mitigation only
Fix from $2,300 2025-12-10
Unclassified CRITICAL 9.8
CVE-2025-67489

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution…

Patch available
Fix from $2,300 2025-12-09
Elysia HIGH 8.8
CVE-2025-66457

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.17 and b…

Fix: 1.4.18+
Fix from $1,950 2025-12-09
Unclassified MEDIUM 5.3
CVE-2025-66533

Improper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection.This issue affects GiveWP: fro…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified CRITICAL 9.9
CVE-2025-42880

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled functio…

Mitigation only
Fix from $2,300 2025-12-09
Firefox CRITICAL 9.8
CVE-2025-14324

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund…

Fix: 115.31.0 / 140.6.0+
Fix from $2,300 2025-12-09
Unclassified MEDIUM 5.4
CVE-2025-13642

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…

Mitigation only
Fix from $1,600 2025-12-09
Deepchat CRITICAL 9.6
CVE-2025-66481

DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through impro…

Fix: after 0.5.1
Fix from $2,300 2025-12-09
Azuriom HIGH 8.8
CVE-2025-65271

Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of…

Fix: 1.2.7+
Fix from $1,950 2025-12-08
Banking System MEDIUM 5.4
CVE-2025-14221

A vulnerability was detected in SourceCodester Online Banking System 1.0. This impacts an unknown function of the file /?page=user. The manipulation …

No fix yet
Fix from $1,600 2025-12-08
Chamber Of Commerce Membership Management System MEDIUM 5.4
CVE-2025-14205

A vulnerability was found in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is an unknown function of the file /members…

Mitigation only
Fix from $1,600 2025-12-08
Hotel Management Services Using Mysql And Php MEDIUM 6.1
CVE-2025-14200

A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected …

Mitigation only
Fix from $1,600 2025-12-07
Employee Profile Management System MEDIUM 5.4
CVE-2025-14194

A vulnerability was identified in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file /view_…

No fix yet
Fix from $1,600 2025-12-07
Tuui CRITICAL 9.6
CVE-2025-66562

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exi…

Fix: 1.3.4+
Fix from $2,300 2025-12-05
Xunruicms MEDIUM 6.1
CVE-2025-14006

A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown functionality of the file /admind4…

Fix: after 4.7.1
Fix from $1,600 2025-12-04
Xunruicms MEDIUM 6.1
CVE-2025-14007

A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mobil…

Fix: after 4.7.1
Fix from $1,600 2025-12-04