Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Leave Management System MEDIUM 6.1
CVE-2025-11433

A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/cont…

No fix yet
Fix from $1,600 2025-10-08
Voting System MEDIUM 5.4
CVE-2025-11421

A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin/candidates_edit.php. This ma…

No fix yet
Fix from $1,600 2025-10-08
Cyber Cafe Management System MEDIUM 6.1
CVE-2025-11390

A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file…

No fix yet
Fix from $1,600 2025-10-07
Unclassified CRITICAL 9.3
CVE-2025-61774

PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vul…

Patch available
Fix from $2,300 2025-10-06
Ilias CRITICAL 9.8
CVE-2025-11344

A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate I…

Mitigation only
Fix from $2,300 2025-10-06
Cmseasy MEDIUM 6.1
CVE-2025-11332

A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php of the component URL Handler.…

Fix: after 7.7.7.0
Fix from $1,600 2025-10-06
Foxcms MEDIUM 6.1
CVE-2025-11306

A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The m…

Fix: after 1.2
Fix from $1,600 2025-10-05
Cicadascms MEDIUM 5.4
CVE-2025-11289

A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the…

No fix yet
Fix from $1,600 2025-10-05
Learning MEDIUM 6.1
CVE-2025-11282

A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Pe…

Fix: after 2.35.0
Fix from $1,600 2025-10-05
Eidos HIGH 8.8
CVE-2025-54374

Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code execution vulnerability. An …

Fix: after 0.21.0
Fix from $1,950 2025-10-03
Redis HIGH 7.3
CVE-2025-46818

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…

Fix: 6.2.20 / 7.2.11+
Fix from $1,950 2025-10-03
Cursor HIGH 8.8
CVE-2025-61593

Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive …

Fix: after 1.7
Fix from $1,950 2025-10-03
Cursor HIGH 7.5
CVE-2025-61590

Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual St…

Fix: 1.7+
Fix from $1,950 2025-10-03
Claude Code HIGH 8.8
CVE-2025-59536EPSS 33%

Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementat…

Fix: 1.0.111+
Fix from $1,950 2025-10-03
Unclassified CRITICAL 9.3
CVE-2025-61588

RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below …

Patch available
Fix from $2,300 2025-10-02
Dolibarr Erp\/crm HIGH 8.8
CVE-2025-56588

Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed f…

Patch available
Fix from $1,950 2025-10-01
Firefox HIGH 7.5
CVE-2025-11153

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.

Fix: 143.0.3+
Fix from $1,950 2025-09-30
Knowage CRITICAL 9.8
CVE-2025-59954

Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using a…

Fix: 8.1.27+
Fix from $2,300 2025-09-30
Unclassified HIGH 8.7
CVE-2025-59952

MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service…

Patch available
Fix from $1,950 2025-09-30
Project Monitoring System MEDIUM 5.4
CVE-2025-11124

A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/pos…

No fix yet
Fix from $1,600 2025-09-28
Hostel Management System MEDIUM 6.1
CVE-2025-11119

A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of …

No fix yet
Fix from $1,600 2025-09-28
Employee Record Management System MEDIUM 6.1
CVE-2025-11112

A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown function of the file /myprofi…

No fix yet
Fix from $1,600 2025-09-28
Vvveb MEDIUM 5.4
CVE-2025-11027

A vulnerability was identified in givanz Vvveb up to 1.0.7.2. Affected by this issue is some unknown functionality of the component SVG File Handler.…

Fix: after 1.0.7.2
Fix from $1,600 2025-09-26
Unclassified MEDIUM 6.6
CVE-2025-60114

Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Code Injection.This issue affec…

Mitigation only
Fix from $1,600 2025-09-26
Muyucms HIGH 7.2
CVE-2025-10993

A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the componen…

Fix: after 2.7
Fix from $1,950 2025-09-26
Unclassified CRITICAL 9.9
CVE-2025-59823

Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Ex…

Mitigation only
Fix from $2,300 2025-09-25
Edge Chromium HIGH 7.6
CVE-2025-59251

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 140.0.3485.81+
Fix from $1,950 2025-09-24
Megatron Lm HIGH 7.8
CVE-2025-23353

NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause …

Fix: 0.12.3+
Fix from $1,950 2025-09-24
Megatron Lm HIGH 7.8
CVE-2025-23354

NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause …

Fix: 0.12.3+
Fix from $1,950 2025-09-24
Megatron Lm HIGH 7.8
CVE-2025-23348

NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a cod…

Fix: 0.12.3+
Fix from $1,950 2025-09-24