Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 7.8
CVE-2025-33183

NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successf…

Mitigation only
Fix from $1,950 2025-11-18
Unclassified HIGH 7.8
CVE-2025-33184

NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successf…

Mitigation only
Fix from $1,950 2025-11-18
Student Grades Management System MEDIUM 5.4
CVE-2025-13349

A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown processing of the file /grades…

No fix yet
Fix from $1,600 2025-11-18
Interview Management System MEDIUM 5.4
CVE-2025-13343

A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function of the file /editQuestion.php.…

No fix yet
Fix from $1,600 2025-11-18
Unclassified MEDIUM 5.4
CVE-2025-7711

The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve…

Mitigation only
Fix from $1,600 2025-11-17
Student Information System MEDIUM 6.1
CVE-2025-13244

A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown function of the file /register.php…

No fix yet
Fix from $1,600 2025-11-16
Student Information System MEDIUM 5.4
CVE-2025-13245

A vulnerability was identified in code-projects Student Information System 2.0. The impacted element is an unknown function of the file /editprofile.…

No fix yet
Fix from $1,600 2025-11-16
Simple Cafe Ordering System MEDIUM 5.4
CVE-2025-13202

A security flaw has been discovered in code-projects Simple Cafe Ordering System 1.0. This affects an unknown part of the file /add_to_cart. Performi…

No fix yet
Fix from $1,600 2025-11-15
Isshue MEDIUM 5.4
CVE-2025-13186

A weakness has been identified in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution up to 4.0. This impacts an unknown function o…

Fix: after 4.0
Fix from $1,600 2025-11-14
Pgadmin 4 CRITICAL 9.8
CVE-2025-12762EPSS 12%

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restore…

Fix: 9.10+
Fix from $2,300 2025-11-13
Unclassified HIGH 8.8
CVE-2025-12733

The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,…

Mitigation only
Fix from $1,950 2025-11-13
Extplorer MEDIUM 5.4
CVE-2025-13058

A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler…

Fix: after 2.1.15
Fix from $1,600 2025-11-12
Smartfabric Os10 MEDIUM 6.7
CVE-2024-48829

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A hig…

Fix: 10.6.1.0+
Fix from $1,600 2025-11-12
Nemo HIGH 7.8
CVE-2025-33178

NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause…

Fix: 2.5.0+
Fix from $1,950 2025-11-11
Unclassified HIGH 7.8
CVE-2025-23357

NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection iss…

Mitigation only
Fix from $1,950 2025-11-11
Nemo HIGH 7.8
CVE-2025-23361

NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause improper control…

Fix: 2.5.0+
Fix from $1,950 2025-11-11
Unclassified CRITICAL 9.8
CVE-2025-12813

The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'conten…

Mitigation only
Fix from $2,300 2025-11-11
Unclassified HIGH 8.8
CVE-2025-12637

The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation feature in the process_theme f…

Mitigation only
Fix from $1,950 2025-11-11
Unclassified MEDIUM 6.9
CVE-2025-42895

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply c…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified CRITICAL 9.9
CVE-2025-42887

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled functio…

Mitigation only
Fix from $2,300 2025-11-11
Unclassified HIGH 8.8
CVE-2025-9334

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and includin…

Mitigation only
Fix from $1,950 2025-11-08
Unclassified CRITICAL 9.2
CVE-2020-36870

Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management s…

Mitigation only
Fix from $2,300 2025-11-07
Unclassified CRITICAL 10.0
CVE-2025-49372

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code I…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.1
CVE-2025-47588

Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynami…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.9
CVE-2025-32222

Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic allows Code Injection.This issue…

Mitigation only
Fix from $2,300 2025-11-06
Api Control Plane HIGH 7.2
CVE-2025-11093

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Media…

Fix: 3.1.0.345 / 3.2.0.446+
Fix from $1,950 2025-11-05
Javascript Expression Evaluator CRITICAL 9.8
CVE-2025-12735

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variable…

Fix: after 2.0.2
Fix from $2,300 2025-11-05
Cursor HIGH 8.8
CVE-2025-64108

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to ci…

Fix: 2.0+
Fix from $1,950 2025-11-04
Xibo HIGH 7.2
CVE-2025-62369

Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution …

Fix: 4.3.1+
Fix from $1,950 2025-11-04
Mulesoft Anypoint Code Builder MEDIUM 5.3
CVE-2025-64318

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Conf…

Fix: 1.12.1+
Fix from $1,600 2025-11-04