Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified MEDIUM 5.3
CVE-2025-48120

Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Code Injection…

No fix yet
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-47562

Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg allows Code Injection.This issue affects MapSVG: f…

No fix yet
Fix from $1,600 2025-05-16
Invisioncommunity CRITICAL 9.8
CVE-2025-47916EPSS 84%

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeed…

Fix: 5.0.7+
Fix from $2,300 2025-05-16
Unclassified MEDIUM 5.3
CVE-2025-4767

A vulnerability was found in defog-ai introspect up to 0.1.4. It has been rated as critical. Affected by this issue is the function test_custom_tool …

Mitigation only
Fix from $1,600 2025-05-16
Employee Record System MEDIUM 5.4
CVE-2025-4745

A vulnerability, which was classified as problematic, was found in code-projects Employee Record System 1.0. This affects an unknown part of the file…

No fix yet
Fix from $1,600 2025-05-16
Unclassified HIGH 8.8
CVE-2025-3053

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions u…

Mitigation only
Fix from $1,950 2025-05-15
Unclassified CRITICAL 9.8
CVE-2025-32363

mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.

Mitigation only
Fix from $2,300 2025-05-14
Unclassified MEDIUM 6.5
CVE-2025-0134

A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privi…

Mitigation only
Fix from $1,600 2025-05-14
Pfsense Ce HIGH 8.8
CVE-2024-54780EPSS 12%

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to impro…

Fix: 2.8.0 / 25.03+
Fix from $1,950 2025-05-14
Iotdb CRITICAL 9.8
CVE-2024-24780

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu…

Fix: 1.3.4+
Fix from $2,300 2025-05-14
Endpoint Manager Mobile HIGH 8.8
CVE-2025-4428 KEVEPSS 86%

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t…

Fix: 11.12.0.5 / 12.3.0.2+
Fix from $1,950 2025-05-13
Cv 7428ns Firmware CRITICAL 9.8
CVE-2025-45857

EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

No fix yet
Fix from $2,300 2025-05-13
Unclassified HIGH 8.3
CVE-2025-43010

SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to exe…

Mitigation only
Fix from $1,950 2025-05-13
Vvveb CRITICAL 9.8
CVE-2025-44022

An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.

Patch available
Fix from $2,300 2025-05-12
Unclassified MEDIUM 6.3
CVE-2025-47271

The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In vers…

Patch available
Fix from $1,600 2025-05-12
Continew Admin MEDIUM 5.4
CVE-2025-4551

A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/c…

Fix: after 3.6.0
Fix from $1,600 2025-05-11
Oa Web Application System HIGH 8.8
CVE-2025-4531

A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected by this issue is the function …

Mitigation only
Fix from $1,950 2025-05-11
Jadmin MEDIUM 5.4
CVE-2025-4495

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of…

No fix yet
Fix from $1,600 2025-05-10
Client Database Management System CRITICAL 9.8
CVE-2025-46191

Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbit…

Mitigation only
Fix from $2,300 2025-05-09
Rx1800 Firmware HIGH 8.8
CVE-2025-28203

Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.

No fix yet
Fix from $1,950 2025-05-09
Unclassified CRITICAL 9.3
CVE-2025-1087

Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vuln…

Mitigation only
Fix from $2,300 2025-05-09
Online Student Clearance System MEDIUM 5.4
CVE-2025-4469

A vulnerability classified as problematic has been found in SourceCodester Online Student Clearance System 1.0. Affected is an unknown function of th…

No fix yet
Fix from $1,600 2025-05-09
Online Student Clearance System MEDIUM 5.4
CVE-2025-4470

A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by this vulnerability is an unkno…

No fix yet
Fix from $1,600 2025-05-09
N150rt Firmware MEDIUM 5.4
CVE-2025-4461

A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unknown code of the component Virt…

No fix yet
Fix from $1,600 2025-05-09
Znuny CRITICAL 9.8
CVE-2025-26845

An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command e…

Fix: after 7.1.3
Fix from $2,300 2025-05-08
Nex Forms MEDIUM 6.3
CVE-2025-4208

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up t…

Fix: after 8.9.2
Fix from $1,600 2025-05-08
Wolmart HIGH 7.3
CVE-2024-13793

The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an…

Fix: 1.8.12+
Fix from $1,950 2025-05-08
Unclassified MEDIUM 5.5
CVE-2025-47691

Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified MEDIUM 5.3
CVE-2025-47481

Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Code Injection.This…

Mitigation only
Fix from $1,600 2025-05-07
Mrcms MEDIUM 5.4
CVE-2025-4326

A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of …

No fix yet
Fix from $1,600 2025-05-06