Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified MEDIUM 6.5
CVE-2025-26996

Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This iss…

Mitigation only
Fix from $1,600 2025-04-15
Smp 111 Firmware HIGH 7.2
CVE-2024-50960

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and…

Fix: after 3.02
Fix from $1,950 2025-04-15
Perfreeblog HIGH 8.8
CVE-2025-29281

In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files an…

No fix yet
Fix from $1,950 2025-04-15
Unclassified CRITICAL 9.3
CVE-2025-3579

In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the…

Mitigation only
Fix from $2,300 2025-04-15
My Blog Layui MEDIUM 5.4
CVE-2025-3592

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the f…

No fix yet
Fix from $1,600 2025-04-14
My Blog Layui MEDIUM 5.4
CVE-2025-3591

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functio…

No fix yet
Fix from $1,600 2025-04-14
Avantfax CRITICAL 9.9
CVE-2025-1782

In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to includ…

Fix: 1.2.1 / 1.3.2+
Fix from $2,300 2025-04-14
Db Hospital Drug MEDIUM 6.1
CVE-2025-3570

A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This affects the function Save of th…

No fix yet
Fix from $1,600 2025-04-14
Krayin Crm MEDIUM 5.4
CVE-2025-3568

A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functiona…

No fix yet
Fix from $1,600 2025-04-14
Wuzhicms HIGH 7.2
CVE-2025-3563

A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachm…

No fix yet
Fix from $1,950 2025-04-14
Uzy Ssm Mall MEDIUM 5.4
CVE-2025-3560

A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /produ…

No fix yet
Fix from $1,600 2025-04-14
Phpshe MEDIUM 6.1
CVE-2025-3554

A vulnerability was found in phpshe 1.8. It has been rated as problematic. This issue affects some unknown processing of the file api.php?mod=cron&ac…

No fix yet
Fix from $1,600 2025-04-14
Youdiancms MEDIUM 6.1
CVE-2025-3533

A vulnerability, which was classified as problematic, has been found in YouDianCMS 9.5.21. This issue affects some unknown processing of the file /Ap…

No fix yet
Fix from $1,600 2025-04-13
Youdiancms MEDIUM 6.1
CVE-2025-3532

A vulnerability classified as problematic was found in YouDianCMS 9.5.21. This vulnerability affects unknown code of the file /App/Tpl/Member/Default…

No fix yet
Fix from $1,600 2025-04-13
Youdiancms MEDIUM 6.1
CVE-2025-3531

A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of the file /App/Tpl/Admin/Default/Log/in…

No fix yet
Fix from $1,600 2025-04-13
Safari HIGH 7.3
CVE-2023-42875

Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safar…

Fix: 10.0 / 14.0+
Fix from $1,950 2025-04-11
Taegis Endpoint Agent HIGH 7.8
CVE-2024-13861

A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitra…

Fix: 1.3.10+
Fix from $1,950 2025-04-11
Everest Forms MEDIUM 6.3
CVE-2025-3422

The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary s…

Fix: 3.1.2+
Fix from $1,600 2025-04-11
Maxkb HIGH 7.2
CVE-2025-32383

MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generat…

Fix: 1.10.4+
Fix from $1,950 2025-04-10
Unclassified HIGH 7.3
CVE-2025-2805

The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the so…

Mitigation only
Fix from $1,950 2025-04-10
Unclassified HIGH 7.3
CVE-2025-2809

The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2…

Mitigation only
Fix from $1,950 2025-04-10
Simple User Management System MEDIUM 6.1
CVE-2025-3489

A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by this issue is some unknown func…

No fix yet
Fix from $1,600 2025-04-10
Unclassified CRITICAL 9.4
CVE-2025-3114

Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute without adequate security valida…

Mitigation only
Fix from $2,300 2025-04-09
Spotfire Enterprise Runtime For R CRITICAL 9.8
CVE-2025-3115

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, …

Fix: 1.17.7 / 6.1.5+
Fix from $2,300 2025-04-09
Unclassified MEDIUM 6.7
CVE-2025-30013

SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevat…

Mitigation only
Fix from $1,600 2025-04-08
Unclassified CRITICAL 9.9
CVE-2025-31330

SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This fl…

Mitigation only
Fix from $2,300 2025-04-08
Unclassified CRITICAL 9.9
CVE-2025-27429

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injectio…

Mitigation only
Fix from $2,300 2025-04-08
Unclassified HIGH 8.5
CVE-2025-23186

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restri…

Mitigation only
Fix from $1,950 2025-04-08
Oa System MEDIUM 6.1
CVE-2025-3392

A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue is the function Save of the f…

Fix: 2025.01.01+
Fix from $1,600 2025-04-08
Yzmcms MEDIUM 6.1
CVE-2025-3397

A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of …

No fix yet
Fix from $1,600 2025-04-08