Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Advanced School Management System MEDIUM 5.4
CVE-2025-9306

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.…

No fix yet
Fix from $1,600 2025-08-21
Ecommerce Website MEDIUM 5.4
CVE-2025-9237

A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of t…

No fix yet
Fix from $1,600 2025-08-20
Scada Lts MEDIUM 5.4
CVE-2025-9235

A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of …

Fix: after 2.7.8.1
Fix from $1,600 2025-08-20
Scada Lts MEDIUM 5.4
CVE-2025-9234

A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenance_events.shtm. The manipul…

Fix: after 2.7.8.1
Fix from $1,600 2025-08-20
Scada Lts MEDIUM 5.4
CVE-2025-9233

A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_edit.shtm. The manipulation o…

Fix: after 2.7.8.1
Fix from $1,600 2025-08-20
Xwiki HIGH 8.8
CVE-2025-51991

XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Met…

Fix: after 17.3.0
Fix from $1,950 2025-08-20
Unclassified MEDIUM 6.5
CVE-2025-54019

Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: f…

Mitigation only
Fix from $1,600 2025-08-20
Unclassified CRITICAL 10.0
CVE-2025-53577

Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Code Inclusion.This issue affect…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.9
CVE-2025-48169

Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Remote Code Inclusion.This issue…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified HIGH 7.5
CVE-2025-30975

Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issu…

Mitigation only
Fix from $1,950 2025-08-20
Solidinvoice MEDIUM 5.4
CVE-2025-9171

A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Cl…

Fix: after 2.4.0
Fix from $1,600 2025-08-19
Solidinvoice MEDIUM 5.4
CVE-2025-9169

A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This m…

Fix: after 2.4.0
Fix from $1,600 2025-08-19
Solidinvoice MEDIUM 5.4
CVE-2025-9170

A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax R…

Fix: after 2.4.0
Fix from $1,600 2025-08-19
Solidinvoice MEDIUM 5.4
CVE-2025-9168

A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creat…

Fix: after 2.4.0
Fix from $1,600 2025-08-19
Solidinvoice MEDIUM 5.4
CVE-2025-9167

A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component R…

Fix: after 2.4.0
Fix from $1,600 2025-08-19
Deepchat CRITICAL 9.6
CVE-2025-55733

DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerab…

Patch available
Fix from $2,300 2025-08-19
Getsemantic MEDIUM 6.1
CVE-2025-9147

A vulnerability has been found in jasonclark getsemantic up to 040c96eb8cf9947488bd01b8de99b607b0519f7d. The impacted element is an unknown function …

No fix yet
Fix from $1,600 2025-08-19
Scada Lts MEDIUM 5.4
CVE-2025-9145

A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file view_edit.shtm of the compone…

No fix yet
Fix from $1,600 2025-08-19
Scada Lts MEDIUM 5.4
CVE-2025-9143

A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. The manipulation of the argume…

No fix yet
Fix from $1,600 2025-08-19
Scada Lts MEDIUM 5.4
CVE-2025-9144

A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit.shtm. This manipulation of th…

No fix yet
Fix from $1,600 2025-08-19
Unclassified CRITICAL 10.0
CVE-2025-50567

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (e…

Mitigation only
Fix from $2,300 2025-08-19
Scada Lts MEDIUM 5.4
CVE-2025-9138

A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Performing manipulation of the argum…

No fix yet
Fix from $1,600 2025-08-19
Unclassified CRITICAL 9.8
CVE-2025-8723EPSS 15%

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization…

Mitigation only
Fix from $2,300 2025-08-19
I Diario MEDIUM 6.1
CVE-2025-9107

A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/search_autocomplete. Executin…

Fix: after 1.5.0
Fix from $1,600 2025-08-18
I Diario MEDIUM 5.4
CVE-2025-9106

A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the c…

Fix: after 1.5.0
Fix from $1,600 2025-08-18
I Diario MEDIUM 5.4
CVE-2025-9105

A vulnerability has been found in Portabilis i-Diario up to 1.5.0. The impacted element is an unknown function of the file /planos-de-ensino-por-area…

Fix: after 1.5.0
Fix from $1,600 2025-08-18
I Diario MEDIUM 5.4
CVE-2025-9104

A flaw has been found in Portabilis i-Diario up to 1.5.0. The affected element is an unknown function of the file /planos-de-aulas-por-disciplina/ of…

Fix: after 1.5.0
Fix from $1,600 2025-08-18
My Blog MEDIUM 5.4
CVE-2025-9101

A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the comp…

No fix yet
Fix from $1,600 2025-08-18
Unclassified MEDIUM 6.5
CVE-2025-8878

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is…

Mitigation only
Fix from $1,600 2025-08-16
Unclassified HIGH 7.3
CVE-2025-8105

The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the so…

Mitigation only
Fix from $1,950 2025-08-16