Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
I Educar MEDIUM 5.4
CVE-2025-7112

A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown processing of the file /intrane…

Mitigation only
Fix from $1,600 2025-07-07
I Educar MEDIUM 5.4
CVE-2025-7113

A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown function of the file /module/Co…

Mitigation only
Fix from $1,600 2025-07-07
I Educar MEDIUM 5.4
CVE-2025-7110

A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown part of the file /intranet/educ…

Mitigation only
Fix from $1,600 2025-07-07
I Educar MEDIUM 5.4
CVE-2025-7109

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionali…

Mitigation only
Fix from $1,600 2025-07-07
Boyuncms CRITICAL 9.8
CVE-2025-7101

A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of the file /install/install_ok.…

Fix: after 1.4.20
Fix from $2,300 2025-07-07
Unclassified CRITICAL 9.5
CVE-2025-5333

Remote attackers can execute arbitrary code in the context of the vulnerable service process.

No fix yet
Fix from $2,300 2025-07-06
Unclassified HIGH 7.2
CVE-2025-52718

Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code Inclusion.This issue affects A…

Mitigation only
Fix from $1,950 2025-07-04
Unclassified CRITICAL 10.0
CVE-2025-49302

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows Remote Code Inclusion.This i…

Mitigation only
Fix from $2,300 2025-07-04
Cockpit MEDIUM 6.1
CVE-2025-7053

A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/u…

Fix: after 2.11.3
Fix from $1,600 2025-07-04
Unclassified CRITICAL 9.3
CVE-2025-34089

An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in version…

No fix yet
Fix from $2,300 2025-07-03
Bolt HIGH 8.8
CVE-2025-34086

Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A …

Fix: after 3.7.0
Fix from $1,950 2025-07-03
Unclassified CRITICAL 9.3
CVE-2025-34061

A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. Th…

Mitigation only
Fix from $2,300 2025-07-03
Unclassified CRITICAL 9.4
CVE-2025-34074

An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task function…

Mitigation only
Fix from $2,300 2025-07-02
Nsclient\+\+ HIGH 7.8
CVE-2025-34079

An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and ExternalScripts module are enab…

No fix yet
Fix from $1,950 2025-07-02
Insight Remote Support CRITICAL 9.8
CVE-2025-37099

A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

Fix: 7.15.0.646+
Fix from $2,300 2025-07-01
Unclassified CRITICAL 9.1
CVE-2025-49029

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget a…

Mitigation only
Fix from $2,300 2025-07-01
Unclassified HIGH 8.8
CVE-2025-49521

A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 te…

Mitigation only
Fix from $1,950 2025-06-30
Unclassified HIGH 8.6
CVE-2025-28993

Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-cache allows Code Injection.Th…

Mitigation only
Fix from $1,950 2025-06-27
Xxl Sso MEDIUM 6.1
CVE-2025-6700

A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/log…

No fix yet
Fix from $1,600 2025-06-26
Llama Factory CRITICAL 9.8
CVE-2025-53002

LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and…

Fix: 0.9.4+
Fix from $2,300 2025-06-26
Hospital Management System MEDIUM 5.4
CVE-2025-6613

A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $1,600 2025-06-25
Knowledgegpt CRITICAL 9.8
CVE-2024-37743

An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.

Mitigation only
Fix from $2,300 2025-06-24
Megatron Lm HIGH 7.8
CVE-2025-23265

NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a…

Fix: 0.12.1+
Fix from $1,950 2025-06-24
Megatron Lm HIGH 7.8
CVE-2025-23264

NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a…

Fix: 0.12.1+
Fix from $1,950 2025-06-24
School Fees Payment System MEDIUM 6.1
CVE-2025-6569

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vulnerability is an unknown fun…

No fix yet
Fix from $1,600 2025-06-24
Hope Boot MEDIUM 5.4
CVE-2025-6551

A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/j…

No fix yet
Fix from $1,600 2025-06-24
Terminal Handler CRITICAL 9.8
CVE-2023-47030

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a U…

Mitigation only
Fix from $2,300 2025-06-23
Terminal Handler CRITICAL 9.8
CVE-2023-47032

Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOA…

Mitigation only
Fix from $2,300 2025-06-23
Itm Web Terminal CRITICAL 9.8
CVE-2023-48978

An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL com…

Mitigation only
Fix from $2,300 2025-06-23
Unclassified CRITICAL 10.0
CVE-2025-6512

On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administra…

Mitigation only
Fix from $2,300 2025-06-23