Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Blogbook MEDIUM 5.4
CVE-2025-5407

A vulnerability has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513 and classified as problematic. Affected by th…

Fix: after 2021-11-22
Fix from $1,600 2025-06-01
Blogbook MEDIUM 5.4
CVE-2025-5405

A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This i…

Fix: after 2021-11-22
Fix from $1,600 2025-06-01
Ishare Maps MEDIUM 6.1
CVE-2025-5378

A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown part of the file mycouncil2.a…

Mitigation only
Fix from $1,600 2025-05-31
Ishare Maps MEDIUM 6.1
CVE-2025-5377

A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issue is some unknown functionali…

Mitigation only
Fix from $1,600 2025-05-31
Freescout HIGH 7.2
CVE-2025-48390

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code injection due to insufficient…

Fix: 1.8.178+
Fix from $1,950 2025-05-29
Unclassified HIGH 7.8
CVE-2025-32801

Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry p…

Mitigation only
Fix from $1,950 2025-05-28
Introspect HIGH 7.8
CVE-2025-5151

A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This affects the function execute_analysis_code_safely of t…

Fix: after 0.1.4
Fix from $1,950 2025-05-25
Docarray HIGH 8.8
CVE-2025-5150

A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /do…

Fix: after 0.40.1
Fix from $1,950 2025-05-25
Dedecms HIGH 7.2
CVE-2025-5137

A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an unknown function of the file dede/sys_verifies.php?a…

No fix yet
Fix from $1,950 2025-05-25
Tmall Demo MEDIUM 6.1
CVE-2025-5135

A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionali…

Fix: after 2025-05-05
Fix from $1,600 2025-05-24
Tmall Demo MEDIUM 6.1
CVE-2025-5134

A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the c…

Fix: after 2025-05-05
Fix from $1,600 2025-05-24
Tmall Demo MEDIUM 6.1
CVE-2025-5133

A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function of the component Search Box. T…

Fix: after 2025-05-05
Fix from $1,600 2025-05-24
Flir Ax8 Firmware MEDIUM 5.4
CVE-2025-5127

A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. Executing manipu…

Fix: after 1.46.16
Fix from $1,600 2025-05-24
Hospital Management System CRITICAL 9.8
CVE-2024-51360

An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file

No fix yet
Fix from $2,300 2025-05-23
Unclassified HIGH 8.4
CVE-2024-13952

Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromis…

Mitigation only
Fix from $1,950 2025-05-22
Unclassified HIGH 8.0
CVE-2025-30172

Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterpr…

No fix yet
Fix from $1,950 2025-05-22
Unclassified HIGH 8.0
CVE-2024-9639

Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enter…

No fix yet
Fix from $1,950 2025-05-22
Unclassified HIGH 7.2
CVE-2024-13928

SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become…

Mitigation only
Fix from $1,950 2025-05-22
Unclassified HIGH 7.2
CVE-2024-13929

Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects A…

Mitigation only
Fix from $1,950 2025-05-22
Vtiger Crm HIGH 7.2
CVE-2025-45753

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP…

Mitigation only
Fix from $1,950 2025-05-21
Seeddms HIGH 7.2
CVE-2025-45752

A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality i…

No fix yet
Fix from $1,950 2025-05-21
Unclassified HIGH 8.4
CVE-2025-27998

An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.

Mitigation only
Fix from $1,950 2025-05-21
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2025-44881

A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a c…

No fix yet
Fix from $2,300 2025-05-20
Langroid CRITICAL 9.8
CVE-2025-46724

Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval…

Fix: 0.53.15+
Fix from $2,300 2025-05-20
Langroid CRITICAL 9.8
CVE-2025-46725

Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas ev…

Fix: 0.53.15+
Fix from $2,300 2025-05-20
Credit Card Application Management System MEDIUM 6.1
CVE-2025-4939

A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown c…

No fix yet
Fix from $1,600 2025-05-19
Opencti MEDIUM 6.8
CVE-2025-26621

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with the capabi…

Fix: 6.5.2+
Fix from $1,600 2025-05-19
Rill Flow HIGH 8.8
CVE-2025-4866

A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown function of the component Manageme…

No fix yet
Fix from $1,950 2025-05-18
Directory Management System MEDIUM 6.1
CVE-2025-4862

A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some un…

No fix yet
Fix from $1,600 2025-05-18
Unclassified MEDIUM 5.3
CVE-2025-48119

Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP Book Showcase rs-wp-books-showcase allows Code Injectio…

Mitigation only
Fix from $1,600 2025-05-16