Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Coolify HIGH 8.8
CVE-2025-34159

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platf…

Fix: 4.0.0+
Fix from $1,950 2025-08-27
Freeform CRITICAL 9.8
CVE-2025-52122

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code…

Fix: 5.10.16+
Fix from $2,300 2025-08-27
Unclassified CRITICAL 9.4
CVE-2025-30056

The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on …

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 9.4
CVE-2025-30057

In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF func…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 9.0
CVE-2025-30055

The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code pr…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 9.4
CVE-2025-2313

In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.

Mitigation only
Fix from $2,300 2025-08-27
Nemo HIGH 7.8
CVE-2025-23315

NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious data created by an attacker coul…

Fix: 2.4.0+
Fix from $1,950 2025-08-26
Nemo Curator HIGH 7.8
CVE-2025-23307

NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. A successful…

Fix: 25.07+
Fix from $1,950 2025-08-26
Nemo HIGH 7.8
CVE-2025-23312

NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker cou…

Fix: 2.4.0+
Fix from $1,950 2025-08-26
Nemo HIGH 7.8
CVE-2025-23313

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code…

Fix: 2.4.0+
Fix from $1,950 2025-08-26
Nemo HIGH 7.8
CVE-2025-23314

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code…

Fix: 2.4.0+
Fix from $1,950 2025-08-26
Selectzero HIGH 7.5
CVE-2025-52218

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified param…

Fix: 2025.5.2+
Fix from $1,950 2025-08-26
Unclassified HIGH 7.8
CVE-2025-53419

Delta Electronics COMMGR has Code Injection vulnerability.

No fix yet
Fix from $1,950 2025-08-26
Online Student Project Report Submission And Evaluation System MEDIUM 6.1
CVE-2025-9439

A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this vulnerability is an unkno…

No fix yet
Fix from $1,600 2025-08-26
Online Student Project Report Submission And Evaluation System MEDIUM 6.1
CVE-2025-9440

A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some…

No fix yet
Fix from $1,600 2025-08-26
Mblog MEDIUM 6.1
CVE-2025-9433

A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin…

Fix: after 3.5.0
Fix from $1,600 2025-08-26
Online Student Project Report Submission And Evaluation System MEDIUM 6.1
CVE-2025-9434

A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects an unknown function of the fi…

No fix yet
Fix from $1,600 2025-08-26
Online Student Project Report Submission And Evaluation System MEDIUM 6.1
CVE-2025-9438

A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected is an unknown function of th…

No fix yet
Fix from $1,600 2025-08-26
Mblog MEDIUM 6.1
CVE-2025-9431

A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cr…

Fix: after 3.5.0
Fix from $1,600 2025-08-26
Mblog MEDIUM 6.1
CVE-2025-9432

A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component …

Fix: after 3.5.0
Fix from $1,600 2025-08-26
Mblog MEDIUM 5.4
CVE-2025-9429

A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the compon…

Fix: after 3.5.0
Fix from $1,600 2025-08-26
Samarium MEDIUM 5.4
CVE-2025-9422

A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team of the component Team Image H…

Fix: after 0.9.6
Fix from $1,600 2025-08-25
Dataease CRITICAL 9.8
CVE-2025-57772EPSS 9%

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If…

Fix: 2.10.12+
Fix from $2,300 2025-08-25
Dataease CRITICAL 9.8
CVE-2025-57773EPSS 8%

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JN…

Fix: 2.10.12+
Fix from $2,300 2025-08-25
Mblog MEDIUM 5.4
CVE-2025-9407

A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing…

Fix: after 3.5.0
Fix from $1,600 2025-08-25
Scada Lts MEDIUM 5.4
CVE-2025-9404

A vulnerability was identified in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file /pointHierarchySLTS of the compone…

Fix: after 2.7.8.1
Fix from $1,600 2025-08-25
Scada Lts MEDIUM 5.4
CVE-2025-9388

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of th…

Fix: after 2.7.8.1
Fix from $1,600 2025-08-24
Unclassified CRITICAL 10.0
CVE-2022-31491

Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to…

Mitigation only
Fix from $2,300 2025-08-22
Unclassified CRITICAL 9.8
CVE-2024-52786

An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted U…

Mitigation only
Fix from $2,300 2025-08-22
Unclassified HIGH 8.4
CVE-2010-20120

Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .maplet file is opened. This be…

No fix yet
Fix from $1,950 2025-08-21