Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 8.4
CVE-2025-34124

A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m m…

No fix yet
Fix from $1,950 2025-07-16
Unclassified HIGH 8.4
CVE-2025-34123

A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The …

No fix yet
Fix from $1,950 2025-07-16
Autopass License Server CRITICAL 9.8
CVE-2025-37105

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

Fix: 9.18+
Fix from $2,300 2025-07-16
Unclassified CRITICAL 9.8
CVE-2025-53890

pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code a…

Patch available
Fix from $2,300 2025-07-15
Xwiki HIGH 8.8
CVE-2025-53836

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2025-07-15
Online Library Management System MEDIUM 5.4
CVE-2025-7601

A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vulnerability affects unknown c…

No fix yet
Fix from $1,600 2025-07-14
Autopass License Server HIGH 8.0
CVE-2024-51768

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Fix: 9.17+
Fix from $1,950 2025-07-14
Unclassified HIGH 7.2
CVE-2024-58258EPSS 13%

SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.

Mitigation only
Fix from $1,950 2025-07-13
Unclassified HIGH 7.2
CVE-2025-50123

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged a…

Mitigation only
Fix from $1,950 2025-07-11
Unclassified CRITICAL 9.8
CVE-2025-5392

The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front()…

Mitigation only
Fix from $2,300 2025-07-11
Unclassified MEDIUM 6.1
CVE-2025-53626

pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabili…

Patch available
Fix from $1,600 2025-07-10
Zoo Management System MEDIUM 5.4
CVE-2025-7408

A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerability affects unknown code of …

No fix yet
Fix from $1,600 2025-07-10
Unclassified MEDIUM 6.3
CVE-2024-7650

Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The vulnerabili…

Mitigation only
Fix from $1,600 2025-07-10
Unclassified CRITICAL 10.0
CVE-2025-34077EPSS 10%

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arb…

Mitigation only
Fix from $2,300 2025-07-09
Helm HIGH 8.6
CVE-2025-53547

Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock fi…

Fix: 3.17.4 / 3.18.4+
Fix from $1,950 2025-07-08
Sharepoint Server HIGH 8.8
CVE-2025-49704 KEVEPSS 100%

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-07-08
Azure Monitor Agent HIGH 7.5
CVE-2025-47988

Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent net…

Fix: 1.35.1+
Fix from $1,950 2025-07-08
Student Transcript Processing System MEDIUM 6.1
CVE-2025-7182

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability…

No fix yet
Fix from $1,600 2025-07-08
Woodmart HIGH 7.3
CVE-2025-6744

The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the s…

Fix: 8.2.4+
Fix from $1,950 2025-07-08
Unclassified CRITICAL 9.9
CVE-2025-42967

SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to cre…

Mitigation only
Fix from $2,300 2025-07-08
Simple Hospital Management System MEDIUM 5.4
CVE-2025-7153

A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown …

No fix yet
Fix from $1,600 2025-07-08
Simple Hospital Management System MEDIUM 5.4
CVE-2025-7148

A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown fu…

No fix yet
Fix from $1,600 2025-07-07
Best Salon Management System MEDIUM 5.4
CVE-2025-7142

A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is so…

No fix yet
Fix from $1,600 2025-07-07
Best Salon Management System MEDIUM 5.4
CVE-2025-7143

A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of t…

No fix yet
Fix from $1,600 2025-07-07
Best Salon Management System MEDIUM 5.4
CVE-2025-7140

A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the f…

No fix yet
Fix from $1,600 2025-07-07
Best Salon Management System MEDIUM 5.4
CVE-2025-7141

A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown …

No fix yet
Fix from $1,600 2025-07-07
Best Salon Management System MEDIUM 5.4
CVE-2025-7139

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This issue affects some unknown proce…

No fix yet
Fix from $1,600 2025-07-07
Integration Bus MEDIUM 6.7
CVE-2025-36014

IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.

Fix: after 10.1.0.5
Fix from $1,600 2025-07-07
Challenges CRITICAL 9.8
CVE-2025-45479

Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted c…

Mitigation only
Fix from $2,300 2025-07-07
I Educar MEDIUM 5.4
CVE-2025-7111

A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects unknown code of the file /intra…

Mitigation only
Fix from $1,600 2025-07-07