Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Oa System MEDIUM 6.1
CVE-2025-3391

A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function …

Fix: 2025.01.01+
Fix from $1,600 2025-04-08
Oa System MEDIUM 6.1
CVE-2025-3389

A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMes…

Fix: 2025.01.01+
Fix from $1,600 2025-04-08
Oa System MEDIUM 6.1
CVE-2025-3390

A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of …

Fix: 2025.01.01+
Fix from $1,600 2025-04-08
Oa System MEDIUM 6.1
CVE-2025-3388

A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of th…

Fix: 2025.01.01+
Fix from $1,600 2025-04-07
Renren Security MEDIUM 5.4
CVE-2025-3387

A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknown part of the component JSON …

Fix: after 5.4.0
Fix from $1,600 2025-04-07
Langflow CRITICAL 9.8
CVE-2025-3248 KEVEPSS 100%

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can …

Fix: 1.3.0+
Fix from $2,300 2025-04-07
Iboot MEDIUM 6.1
CVE-2025-3327

A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown processing of the file /comm…

No fix yet
Fix from $1,600 2025-04-07
Admintwo MEDIUM 6.1
CVE-2025-3252

A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unknown code of the file /resourc…

No fix yet
Fix from $1,600 2025-04-04
Admintwo MEDIUM 6.1
CVE-2025-3253

A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown processing of the file /ztree/ins…

No fix yet
Fix from $1,600 2025-04-04
Admintwo MEDIUM 6.1
CVE-2025-3251

A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet.…

No fix yet
Fix from $1,600 2025-04-04
Br 6478ac V3 Firmware CRITICAL 9.8
CVE-2025-28146EPSS 11%

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm…

No fix yet
Fix from $2,300 2025-04-04
Perfex Crm MEDIUM 5.4
CVE-2025-3219

A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown function of the file /perfex/…

No fix yet
Fix from $1,600 2025-04-04
Unclassified CRITICAL 9.8
CVE-2024-13645

The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. Th…

Mitigation only
Fix from $2,300 2025-04-04
Unclassified HIGH 8.8
CVE-2024-45199

insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, trig…

Mitigation only
Fix from $1,950 2025-04-03
X18 Firmware CRITICAL 9.8
CVE-2025-29064

An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi.

Mitigation only
Fix from $2,300 2025-04-03
Unclassified HIGH 8.8
CVE-2024-45198

insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering …

Mitigation only
Fix from $1,950 2025-04-03
Password Secure CRITICAL 9.8
CVE-2025-26818

Netwrix Password Secure through 9.2 allows command injection.

Fix: 9.2.2+
Fix from $2,300 2025-04-03
Lmdeploy HIGH 7.8
CVE-2025-3163

A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of …

Fix: after 0.7.1
Fix from $1,950 2025-04-03
Supersonic CRITICAL 9.8
CVE-2025-3164

A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknow…

Fix: after 0.9.8
Fix from $2,300 2025-04-03
Pgadmin 4 HIGH 8.8
CVE-2025-2945EPSS 47%

Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POS…

Fix: 9.2+
Fix from $1,950 2025-04-03
Templating Engine HIGH 8.8
CVE-2025-31722

In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with It…

Fix: 2.5.4+
Fix from $1,950 2025-04-02
Unclassified CRITICAL 10.0
CVE-2025-30580

Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidgets-image-editor allows Remote …

Mitigation only
Fix from $2,300 2025-04-01
Unclassified CRITICAL 9.9
CVE-2025-30911

Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This iss…

Mitigation only
Fix from $2,300 2025-04-01
Ipados HIGH 7.8
CVE-2025-24243

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sono…

Fix: 2.4 / 13.7.5+
Fix from $1,950 2025-03-31
Studentservlet Jsp MEDIUM 6.1
CVE-2025-3036

A vulnerability, which was classified as problematic, was found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b60a77a2c85f52d2102f5/d4d7a064…

No fix yet
Fix from $1,600 2025-03-31
Wnr854t Firmware CRITICAL 9.8
CVE-2024-54807

In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInterna…

No fix yet
Fix from $2,300 2025-03-31
Wnr854t Firmware CRITICAL 9.8
CVE-2024-54803

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the …

No fix yet
Fix from $2,300 2025-03-31
Wnr854t Firmware CRITICAL 9.8
CVE-2024-54804

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the …

No fix yet
Fix from $2,300 2025-03-31
Wnr854t Firmware CRITICAL 9.8
CVE-2024-54805

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the …

No fix yet
Fix from $2,300 2025-03-31
Wnr854t Firmware CRITICAL 9.8
CVE-2024-54806

Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via t…

No fix yet
Fix from $2,300 2025-03-31