Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Learnhouse MEDIUM 5.4
CVE-2025-12269

A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unknown function of the file /dash…

Fix: after 2025-09-21
Fix from $1,600 2025-10-27
Unclassified MEDIUM 6.3
CVE-2025-12266

A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the functio…

Mitigation only
Fix from $1,600 2025-10-27
Chatwoot MEDIUM 6.1
CVE-2025-12246

A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/…

Fix: after 4.7.0
Fix from $1,600 2025-10-27
Simple E Banking System MEDIUM 6.1
CVE-2025-12244

A vulnerability was determined in code-projects Simple E-Banking System 1.0. This affects an unknown part of the file /eBank/register.php. Executing …

No fix yet
Fix from $1,600 2025-10-27
Gate Pass Management System MEDIUM 5.4
CVE-2025-12227

A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.ph…

No fix yet
Fix from $1,600 2025-10-27
Unclassified CRITICAL 9.1
CVE-2025-62959

Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Remote Co…

Mitigation only
Fix from $2,300 2025-10-27
Unclassified MEDIUM 6.3
CVE-2025-8483

The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl…

Mitigation only
Fix from $1,600 2025-10-25
Unclassified HIGH 7.1
CVE-2025-61136

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset…

Mitigation only
Fix from $1,950 2025-10-23
Unclassified CRITICAL 9.0
CVE-2025-62023

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a t…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 10.0
CVE-2025-60206

Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: f…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 7.4
CVE-2025-52756

Improper Control of Generation of Code ('Code Injection') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Remote Code…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.2
CVE-2025-49926

Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection.This issue affects Kalium: f…

No fix yet
Fix from $1,950 2025-10-22
Librechat MEDIUM 5.4
CVE-2025-8848

A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP …

No fix yet
Fix from $1,600 2025-10-22
Unclassified HIGH 7.6
CVE-2025-61488

An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php com…

Mitigation only
Fix from $1,950 2025-10-20
Clipbucket HIGH 7.2
CVE-2025-62429

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbitrary PHP code execution. In …

Fix: 5.5.2-147+
Fix from $1,950 2025-10-20
Logicaldoc MEDIUM 5.4
CVE-2025-11946

A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp…

Fix: after 9.2.1
Fix from $1,600 2025-10-19
Unclassified CRITICAL 9.1
CVE-2025-57567

A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default them…

Mitigation only
Fix from $2,300 2025-10-17
Chancms HIGH 8.8
CVE-2025-11905

A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\control…

Fix: after 3.3.2
Fix from $1,950 2025-10-17
Bagisto MEDIUM 6.8
CVE-2025-62416

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user i…

No fix yet
Fix from $1,600 2025-10-16
Unclassified CRITICAL 9.3
CVE-2025-11548

A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to …

Mitigation only
Fix from $2,300 2025-10-14
Forticlient HIGH 7.1
CVE-2025-31365

An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may al…

Fix: 7.2.9 / 7.4.4+
Fix from $1,950 2025-10-14
Unclassified CRITICAL 9.8
CVE-2025-46581

ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands wit…

Mitigation only
Fix from $2,300 2025-10-14
Unclassified HIGH 8.8
CVE-2025-41699

An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as …

Mitigation only
Fix from $1,950 2025-10-14
Unclassified MEDIUM 5.4
CVE-2025-42901

SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's brow…

Mitigation only
Fix from $1,600 2025-10-14
Unclassified HIGH 7.2
CVE-2025-61927

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower contains a security vulnerabi…

Patch available
Fix from $1,950 2025-10-10
Cherry Studio CRITICAL 9.6
CVE-2025-61929

Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When …

Fix: 1.6.4+
Fix from $2,300 2025-10-10
Unclassified HIGH 8.1
CVE-2025-61773

pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient …

Patch available
Fix from $1,950 2025-10-09
Unclassified CRITICAL 9.9
CVE-2025-11539

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/…

Mitigation only
Fix from $2,300 2025-10-09
Voting System MEDIUM 6.1
CVE-2025-11512

A vulnerability was found in code-projects Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/voters_add.php.…

No fix yet
Fix from $1,600 2025-10-09
Opnform MEDIUM 6.1
CVE-2025-11435

A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /sh…

Fix: after 1.9.3
Fix from $1,600 2025-10-08