Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Megatron Lm HIGH 7.8
CVE-2025-23349

NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code inje…

Fix: 0.12.3+
Fix from $1,950 2025-09-24
Api Control Plane HIGH 7.2
CVE-2025-5717

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor a…

Mitigation only
Fix from $1,950 2025-09-23
Unclassified CRITICAL 9.8
CVE-2025-9321

The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input valida…

Mitigation only
Fix from $2,300 2025-09-23
Simple Food Ordering System MEDIUM 5.4
CVE-2025-10837

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerability is an unknown functionali…

Mitigation only
Fix from $1,600 2025-09-23
Restaurant Menu Maker MEDIUM 6.1
CVE-2025-10827

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /previ…

No fix yet
Fix from $1,600 2025-09-23
Flowise CRITICAL 10.0
CVE-2025-59528EPSS 91%

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execu…

Mitigation only
Fix from $2,300 2025-09-22
Unclassified MEDIUM 5.4
CVE-2025-58673

Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue …

Mitigation only
Fix from $1,600 2025-09-22
Creabox Manager HIGH 8.8
CVE-2025-57439

Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacke…

No fix yet
Fix from $1,950 2025-09-22
Car Rental Project MEDIUM 6.1
CVE-2025-10794

A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the file /carrental/search.php. E…

No fix yet
Fix from $1,600 2025-09-22
Ppress HIGH 8.8
CVE-2025-54815

Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.

No fix yet
Fix from $1,950 2025-09-19
Automation Platform CRITICAL 9.1
CVE-2025-57644

Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can exe…

Mitigation only
Fix from $2,300 2025-09-19
Online Petshop Management System MEDIUM 5.4
CVE-2025-10632

A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file ava…

No fix yet
Fix from $1,600 2025-09-18
Online Petshop Management System MEDIUM 5.4
CVE-2025-10631

A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the co…

No fix yet
Fix from $1,600 2025-09-18
E Logbook With Health Monitoring System For Covid 19 MEDIUM 6.1
CVE-2025-10614

A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of…

No fix yet
Fix from $1,600 2025-09-17
Unclassified CRITICAL 9.0
CVE-2025-58766

Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows att…

Patch available
Fix from $2,300 2025-09-17
I Educar MEDIUM 6.1
CVE-2025-10605

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. …

Fix: after 2.10.0
Fix from $1,600 2025-09-17
I Educar MEDIUM 6.1
CVE-2025-10606

A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/Configu…

Fix: after 2.10.0
Fix from $1,600 2025-09-17
I Educar MEDIUM 6.1
CVE-2025-10590

A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuar…

Fix: after 2.10.0
Fix from $1,600 2025-09-17
I Educar MEDIUM 5.4
CVE-2025-10591

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_funcao_cad.php of the…

Fix: after 2.10.0
Fix from $1,600 2025-09-17
Unclassified HIGH 8.8
CVE-2025-10057

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includ…

Mitigation only
Fix from $1,950 2025-09-17
I Educar MEDIUM 5.4
CVE-2025-10584

A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_ca…

Fix: after 2.10.0
Fix from $1,600 2025-09-17
Grocery Sales And Inventory System MEDIUM 6.1
CVE-2025-10566

A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file …

No fix yet
Fix from $1,600 2025-09-16
Unclassified CRITICAL 10.0
CVE-2025-41243

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable wh…

Mitigation only
Fix from $2,300 2025-09-16
E Logbook With Health Monitoring System For Covid 19 MEDIUM 6.1
CVE-2025-10411

A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of …

No fix yet
Fix from $1,600 2025-09-14
Smart Park Management System HIGH 7.2
CVE-2025-10394

A vulnerability has been found in fcba_zzm ics-park Smart Park Management System 2.0. Affected is an unknown function of the file ruoyi-quartz/src/ma…

No fix yet
Fix from $1,950 2025-09-14
I Educar MEDIUM 6.1
CVE-2025-10373

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /intranet/educa…

Fix: after 2.10.0
Fix from $1,600 2025-09-13
I Educar MEDIUM 5.4
CVE-2025-10372

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This m…

Fix: after 2.10.0
Fix from $1,600 2025-09-13
Rpi Jukebox Rfid MEDIUM 6.1
CVE-2025-10369

A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdocs/cardRegisterNew.php. Execut…

Fix: after 2.8.0
Fix from $1,600 2025-09-13
Rpi Jukebox Rfid MEDIUM 5.4
CVE-2025-10370

A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php.…

Fix: after 2.8.0
Fix from $1,600 2025-09-13
Rpi Jukebox Rfid MEDIUM 6.1
CVE-2025-10368

A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/manageFi…

Fix: after 2.8.0
Fix from $1,600 2025-09-13