Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Xunruicms MEDIUM 6.1
CVE-2025-14005

A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionality of the file /admind45f74ad…

Fix: after 4.7.1
Fix from $1,600 2025-12-04
Deepchat CRITICAL 9.6
CVE-2025-66222

DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the M…

Fix: after 0.5.0
Fix from $2,300 2025-12-03
Masacms CRITICAL 9.8
CVE-2024-32641EPSS 12%

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code …

Fix: 7.2.8 / 7.3.13+
Fix from $2,300 2025-12-03
Unclassified CRITICAL 9.8
CVE-2025-13486EPSS 74%

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_…

Mitigation only
Fix from $2,300 2025-12-03
Unclassified CRITICAL 9.3
CVE-2025-13658

A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence o…

Mitigation only
Fix from $2,300 2025-12-02
Vllm HIGH 8.8
CVE-2025-66448

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a conf…

Fix: 0.11.1+
Fix from $1,950 2025-12-01
Grav HIGH 8.8
CVE-2025-66299

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenti…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav HIGH 8.8
CVE-2025-66294

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authentic…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Keros HIGH 8.1
CVE-2024-39148

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute ar…

Fix: 5.12+
Fix from $1,950 2025-12-01
Unclassified HIGH 7.3
CVE-2025-13792

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stde…

Mitigation only
Fix from $1,950 2025-11-30
Wtcms CRITICAL 9.8
CVE-2025-13786

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. P…

Fix: after 2019-12-20
Fix from $2,300 2025-11-30
Orangehrm HIGH 8.8
CVE-2025-66224

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw i…

Fix: 5.8+
Fix from $1,950 2025-11-29
Ray HIGH 8.8
CVE-2025-62593 KEV

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabi…

Fix: 2.52.0+
Fix from $1,950 2025-11-26
Nemo HIGH 7.8
CVE-2025-33204

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cau…

Fix: 2.5.1+
Fix from $1,950 2025-11-25
Redaxo HIGH 7.2
CVE-2025-64050

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to e…

No fix yet
Fix from $1,950 2025-11-25
Unclassified CRITICAL 9.8
CVE-2025-6389EPSS 73%

The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pa…

Mitigation only
Fix from $2,300 2025-11-25
Hostel Management System MEDIUM 5.4
CVE-2025-13577

A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Ex…

Mitigation only
Fix from $1,600 2025-11-24
Unclassified CRITICAL 10.0
CVE-2025-65108

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block…

Patch available
Fix from $2,300 2025-11-21
Online Beauty Parlor Management System MEDIUM 6.1
CVE-2025-13484

A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file …

No fix yet
Fix from $1,600 2025-11-20
Lite Xl HIGH 7.3
CVE-2025-12120

Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for co…

Fix: after 2.1.8
Fix from $1,950 2025-11-20
Online Shop Project MEDIUM 5.4
CVE-2025-13450

A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipu…

No fix yet
Fix from $1,600 2025-11-20
Easyimages2.0 MEDIUM 5.4
CVE-2025-13415

A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image H…

Fix: after 2.8.6
Fix from $1,600 2025-11-19
Retro Basketball Shoes Online Store MEDIUM 6.1
CVE-2025-13412

A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file…

No fix yet
Fix from $1,600 2025-11-19
Claude Code CRITICAL 9.8
CVE-2025-65099

Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked…

Fix: 1.0.39+
Fix from $2,300 2025-11-19
Esm.sh CRITICAL 9.6
CVE-2025-65026

esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Litera…

Fix: 136+
Fix from $2,300 2025-11-19
Unclassified HIGH 8.6
CVE-2025-10702

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Acc…

Mitigation only
Fix from $1,950 2025-11-19
Unclassified HIGH 8.6
CVE-2025-10703

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Acc…

Mitigation only
Fix from $1,950 2025-11-19
Unclassified HIGH 8.0
CVE-2025-13035

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's u…

Mitigation only
Fix from $1,950 2025-11-19
Dzzoffice MEDIUM 5.4
CVE-2025-63693

The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in m…

Fix: after 2.3.7
Fix from $1,600 2025-11-18
Arubaos Cx HIGH 8.8
CVE-2025-37157

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond…

Fix: 10.10.1170 / 10.13.1101+
Fix from $1,950 2025-11-18