Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified CRITICAL 9.2
CVE-2020-36870

Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management s…

Mitigation only
Fix from $2,300 2025-11-07
Unclassified CRITICAL 10.0
CVE-2025-49372

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code I…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.1
CVE-2025-47588

Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynami…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.9
CVE-2025-32222

Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic allows Code Injection.This issue…

Mitigation only
Fix from $2,300 2025-11-06
Api Control Plane HIGH 7.2
CVE-2025-11093

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Media…

Fix: 3.1.0.345 / 3.2.0.446+
Fix from $1,950 2025-11-05
Javascript Expression Evaluator CRITICAL 9.8
CVE-2025-12735

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variable…

Fix: after 2.0.2
Fix from $2,300 2025-11-05
Cursor HIGH 8.8
CVE-2025-64108

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to ci…

Fix: 2.0+
Fix from $1,950 2025-11-04
Xibo HIGH 7.2
CVE-2025-62369

Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution …

Fix: 4.3.1+
Fix from $1,950 2025-11-04
Mulesoft Anypoint Code Builder MEDIUM 5.3
CVE-2025-64318

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Conf…

Fix: 1.12.1+
Fix from $1,600 2025-11-04
Agentforce Vibes MEDIUM 6.5
CVE-2025-64320

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affec…

Fix: 3.2.0+
Fix from $1,600 2025-11-04
Agentforce Vibes MEDIUM 5.3
CVE-2025-64321

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configur…

Fix: 3.3.0+
Fix from $1,600 2025-11-04
Mulesoft Anypoint Code Builder MEDIUM 6.5
CVE-2025-10875

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue a…

Fix: 1.11.6+
Fix from $1,600 2025-11-04
Icescrum HIGH 8.8
CVE-2025-60785

A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary cod…

No fix yet
Fix from $1,950 2025-11-03
Unclassified HIGH 8.8
CVE-2025-6990

The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via the `TH_PhpCode` pagebuilder…

Mitigation only
Fix from $1,950 2025-11-01
Unclassified HIGH 7.3
CVE-2025-10487

The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.12 via …

Mitigation only
Fix from $1,950 2025-11-01
Logicaldoc MEDIUM 5.4
CVE-2025-12546

A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This m…

Fix: after 9.2.1
Fix from $1,600 2025-10-31
Veeam Backup \& Replication HIGH 8.8
CVE-2025-48984

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

Fix: 12.3.2.4165+
Fix from $1,950 2025-10-31
Log Server CRITICAL 9.8
CVE-2025-34277

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated …

Fix: 2024+
Fix from $2,300 2025-10-30
Unclassified HIGH 8.8
CVE-2025-61196

An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter.

Mitigation only
Fix from $1,950 2025-10-30
Unclassified CRITICAL 9.8
CVE-2025-50739

iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization.

Mitigation only
Fix from $2,300 2025-10-30
Unclassified HIGH 8.8
CVE-2025-56399

alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload…

Mitigation only
Fix from $1,950 2025-10-28
E Commerce Website MEDIUM 6.1
CVE-2025-12335

A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages…

No fix yet
Fix from $1,600 2025-10-28
E Commerce Website MEDIUM 6.1
CVE-2025-12334

A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulati…

No fix yet
Fix from $1,600 2025-10-27
E Commerce Website MEDIUM 6.1
CVE-2025-12333

A vulnerability has been found in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/supplier_add.php. The man…

No fix yet
Fix from $1,600 2025-10-27
Simple Food Ordering System MEDIUM 6.1
CVE-2025-12302

A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.p…

No fix yet
Fix from $1,600 2025-10-27
Simple Food Ordering System MEDIUM 6.1
CVE-2025-12300

A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addcategory.…

No fix yet
Fix from $1,600 2025-10-27
Simple Food Ordering System MEDIUM 6.1
CVE-2025-12298

A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the file /editcategory.php. The mani…

No fix yet
Fix from $1,600 2025-10-27
Simple Food Ordering System MEDIUM 6.1
CVE-2025-12299

A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct…

No fix yet
Fix from $1,600 2025-10-27
Client Details System MEDIUM 5.4
CVE-2025-12280

A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Per…

No fix yet
Fix from $1,600 2025-10-27
Client Details System MEDIUM 5.4
CVE-2025-12281

A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executi…

No fix yet
Fix from $1,600 2025-10-27