Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Mrcms MEDIUM 5.4
CVE-2025-4324

A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file /admin/link/edit.do of the c…

No fix yet
Fix from $1,600 2025-05-06
Mrcms MEDIUM 5.4
CVE-2025-4323

A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the comp…

No fix yet
Fix from $1,600 2025-05-06
Unclassified HIGH 7.3
CVE-2025-2802

The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.3.1. This is due to the so…

Mitigation only
Fix from $1,950 2025-05-06
Mrcms MEDIUM 5.4
CVE-2025-4292

A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /…

No fix yet
Fix from $1,600 2025-05-05
Mrcms MEDIUM 5.4
CVE-2025-4293

A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group…

No fix yet
Fix from $1,600 2025-05-05
Seacms CRITICAL 9.8
CVE-2025-44071

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attacker…

No fix yet
Fix from $2,300 2025-05-05
Retrieval Based Voice Conversion Webui CRITICAL 9.8
CVE-2025-43845

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. T…

Fix: after 2.2.231006
Fix from $2,300 2025-05-05
Opencti CRITICAL 9.1
CVE-2025-24977

OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute…

Fix: 6.4.11+
Fix from $2,300 2025-05-05
Unclassified MEDIUM 5.3
CVE-2025-4261

A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as critical. This affects the fu…

Mitigation only
Fix from $1,600 2025-05-05
Seacms MEDIUM 6.1
CVE-2025-4257

A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pa…

No fix yet
Fix from $1,600 2025-05-05
Seacms MEDIUM 5.4
CVE-2025-4256

A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipu…

No fix yet
Fix from $1,600 2025-05-05
Unclassified HIGH 7.3
CVE-2024-13738

The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…

Mitigation only
Fix from $1,950 2025-05-03
Browserpilot HIGH 7.8
CVE-2025-4218

A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulnerability is the function GPTS…

Fix: after 0.2.51
Fix from $1,950 2025-05-02
Sambabox CRITICAL 9.8
CVE-2025-2421

Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection. This issue affects S…

Fix: 5.1+
Fix from $2,300 2025-05-02
Unclassified HIGH 7.4
CVE-2025-46569

Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API …

Patch available
Fix from $1,950 2025-05-01
Online Banquet Booking System CRITICAL 9.8
CVE-2025-45947

An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the …

No fix yet
Fix from $2,300 2025-04-28
Project Center CRITICAL 9.8
CVE-2024-32499

Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.

Fix: after 2023.3.0.32259
Fix from $2,300 2025-04-28
Workspace CRITICAL 9.8
CVE-2023-42404

OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.

Mitigation only
Fix from $2,300 2025-04-28
Usermin HIGH 8.8
CVE-2015-2079

Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argume…

Fix: 1.660+
Fix from $1,950 2025-04-28
Webarena HIGH 8.8
CVE-2025-4022

A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentE…

Fix: after 0.2.0
Fix from $1,950 2025-04-28
Metazo CRITICAL 9.8
CVE-2025-46661

IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template ex…

Fix: after 8.1.13
Fix from $2,300 2025-04-28
Oa Web Application System MEDIUM 5.4
CVE-2025-4000

A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function …

Mitigation only
Fix from $1,600 2025-04-28
Oa Web Application System MEDIUM 5.4
CVE-2025-3999

A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unk…

Mitigation only
Fix from $1,600 2025-04-28
Central Authentication Service HIGH 7.5
CVE-2025-3984

A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\we…

Mitigation only
Fix from $1,950 2025-04-27
Sverchok HIGH 8.8
CVE-2025-3982

A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sve…

No fix yet
Fix from $1,950 2025-04-27
Jsite MEDIUM 5.4
CVE-2025-3970

A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. Th…

Fix: after 1.0
Fix from $1,600 2025-04-27
Paicoding MEDIUM 5.4
CVE-2025-3965

A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality …

No fix yet
Fix from $1,600 2025-04-27
Zxcloud Goldendb HIGH 7.8
CVE-2025-46579

There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users d…

Fix: 6.1.03.11+
Fix from $1,950 2025-04-27
Unclassified MEDIUM 6.5
CVE-2024-13812

The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.1.1. This is du…

Mitigation only
Fix from $1,600 2025-04-26
Unclassified HIGH 7.2
CVE-2025-3491

The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and inc…

Mitigation only
Fix from $1,950 2025-04-26