Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Rpi Jukebox Rfid MEDIUM 6.1
CVE-2025-10367

A vulnerability has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdo…

Fix: after 2.8.0
Fix from $1,600 2025-09-13
Rpi Jukebox Rfid MEDIUM 5.4
CVE-2025-10366

A flaw has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/inc.setWlanIpMail.php. This manip…

Fix: after 2.8.0
Fix from $1,600 2025-09-13
Unmark MEDIUM 5.4
CVE-2025-10332

A vulnerability was found in cdevroe unmark up to 1.9.3. Impacted is an unknown function of the file application/views/marks/info.php. Performing man…

Fix: after 1.9.3
Fix from $1,600 2025-09-13
Unmark MEDIUM 5.4
CVE-2025-10331

A vulnerability has been found in cdevroe unmark up to 1.9.3. This issue affects some unknown processing of the file /application/controllers/Marks.p…

Fix: after 1.9.3
Fix from $1,600 2025-09-13
Unmark MEDIUM 6.1
CVE-2025-10330

A flaw has been found in cdevroe unmark up to 1.9.3. This vulnerability affects unknown code of the file application/views/layouts/topbar/searchform.…

Fix: after 1.9.3
Fix from $1,600 2025-09-12
10oa MEDIUM 6.1
CVE-2025-10274

A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the file /trial/mvc/item. Performin…

No fix yet
Fix from $1,600 2025-09-12
10oa MEDIUM 6.1
CVE-2025-10272

A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. This manipulation of the argum…

No fix yet
Fix from $1,600 2025-09-11
10oa MEDIUM 6.1
CVE-2025-10271

A vulnerability was found in erjinzhi 10OA 1.0. This impacts an unknown function of the file /trial/mvc/finder. The manipulation of the argument Name…

No fix yet
Fix from $1,600 2025-09-11
Unclassified CRITICAL 9.6
CVE-2025-59053

AIRI is a self-hosted, artificial intelligence based Grok Companion. In v0.7.2-beta.2 in the `packages/stage-ui/src/components/MarkdownRenderer.vue` …

Patch available
Fix from $2,300 2025-09-11
Unclassified HIGH 8.1
CVE-2025-8417

The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is…

Mitigation only
Fix from $1,950 2025-09-11
Claude Code CRITICAL 9.8
CVE-2025-59041

Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`. Prior to version 1.0.105…

Fix: 1.0.105+
Fix from $2,300 2025-09-10
Claude Code CRITICAL 9.8
CVE-2025-58764

Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to a bypass of the Claude Code c…

Fix: 1.0.105+
Fix from $2,300 2025-09-10
Unclassified HIGH 7.0
CVE-2025-59042

PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during t…

Patch available
Fix from $1,950 2025-09-09
Deepchat CRITICAL 9.6
CVE-2025-58768

DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operat…

Fix: 0.3.5+
Fix from $2,300 2025-09-09
Pro Macros CRITICAL 9.8
CVE-2025-55727

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to vers…

Fix: 1.26.5+
Fix from $2,300 2025-09-09
Pro Macros CRITICAL 9.8
CVE-2025-55728

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to vers…

Fix: 1.26.5+
Fix from $2,300 2025-09-09
Unclassified HIGH 8.0
CVE-2025-9539

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unautho…

Mitigation only
Fix from $1,950 2025-09-09
Unclassified MEDIUM 5.0
CVE-2025-9489

The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.…

Mitigation only
Fix from $1,600 2025-09-09
Unclassified CRITICAL 9.9
CVE-2025-42922

SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file…

Mitigation only
Fix from $2,300 2025-09-09
Simple To Do List System MEDIUM 5.4
CVE-2025-10117

A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the co…

No fix yet
Fix from $1,600 2025-09-09
Wegia HIGH 8.8
CVE-2025-58745

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. T…

Fix: 3.4.11+
Fix from $1,950 2025-09-08
Sim CRITICAL 9.8
CVE-2025-10097

A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app/api/function/execute/route.t…

Mitigation only
Fix from $2,300 2025-09-08
Ruisibi CRITICAL 9.8
CVE-2025-57141

rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.

No fix yet
Fix from $2,300 2025-09-08
Personal Time Tracker MEDIUM 5.4
CVE-2025-10088

A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing mani…

No fix yet
Fix from $1,600 2025-09-08
Online Polling System MEDIUM 5.4
CVE-2025-10075

A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-prof…

No fix yet
Fix from $1,600 2025-09-08
I Educar MEDIUM 5.4
CVE-2025-10074

A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manip…

Fix: after 2.10.0
Fix from $1,600 2025-09-08
Point Of Sale System MEDIUM 6.1
CVE-2025-10067

A vulnerability was detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function of the file /inventory/main/ve…

No fix yet
Fix from $1,600 2025-09-07
Point Of Sale System MEDIUM 6.1
CVE-2025-10066

A security vulnerability has been detected in itsourcecode POS Point of Sale System 1.0. The affected element is an unknown function of the file /inv…

No fix yet
Fix from $1,600 2025-09-07
Point Of Sale System MEDIUM 6.1
CVE-2025-10064

A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown processing of the file /inventory/m…

No fix yet
Fix from $1,600 2025-09-07
Point Of Sale System MEDIUM 6.1
CVE-2025-10065

A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file /inventory/main/vendors/data…

No fix yet
Fix from $1,600 2025-09-07