Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Cicadascms MEDIUM 5.4
CVE-2025-2623

A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

No fix yet
Fix from $1,600 2025-03-22
Unclassified HIGH 8.8
CVE-2025-2303

The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi…

Mitigation only
Fix from $1,950 2025-03-22
Human Resource Management MEDIUM 5.4
CVE-2025-2590

A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic. Affected is the function Up…

No fix yet
Fix from $1,600 2025-03-21
Simple Machines Forum MEDIUM 6.1
CVE-2025-2583

A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php…

No fix yet
Fix from $1,600 2025-03-21
Simple Machines Forum MEDIUM 5.4
CVE-2025-2582

A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file…

No fix yet
Fix from $1,600 2025-03-21
Dataverse HIGH 8.8
CVE-2025-29807

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-03-21
Dify HIGH 8.8
CVE-2025-0185

A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vuln…

No fix yet
Fix from $1,950 2025-03-20
Superagi HIGH 8.8
CVE-2024-9439

SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 8.4
CVE-2024-6982

A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Pytho…

Patch available
Fix from $1,950 2025-03-20
Litellm HIGH 8.8
CVE-2024-6825

BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules'…

Fix: 1.65.4+
Fix from $1,950 2025-03-20
Unclassified HIGH 8.8
CVE-2024-12215

In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, …

Mitigation only
Fix from $1,950 2025-03-20
Gpt Academic HIGH 8.8
CVE-2024-10950

In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause…

Fix: after 3.83
Fix from $1,950 2025-03-20
Gpt Academic HIGH 8.8
CVE-2024-10954

In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided promp…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-10572

In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGB…

No fix yet
Fix from $1,950 2025-03-20
Dify HIGH 7.2
CVE-2024-10252

A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerabi…

Fix: after 0.9.1
Fix from $1,950 2025-03-20
Unclassified CRITICAL 9.8
CVE-2024-57061

An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses c…

Mitigation only
Fix from $2,300 2025-03-19
Emlog CRITICAL 9.8
CVE-2025-29401

An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2025-03-19
Ujcms MEDIUM 5.4
CVE-2025-2491

A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cm…

No fix yet
Fix from $1,600 2025-03-18
Ujcms MEDIUM 5.4
CVE-2025-2490

A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the fi…

No fix yet
Fix from $1,600 2025-03-18
Fortisoar HIGH 8.4
CVE-2024-21760

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versio…

Fix: after 7.4.5
Fix from $1,950 2025-03-18
Vehicle Management System MEDIUM 5.4
CVE-2025-2377

A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown funct…

No fix yet
Fix from $1,600 2025-03-17
Human Metapneumovirus Testing Management System MEDIUM 5.4
CVE-2025-2375

A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unk…

No fix yet
Fix from $1,600 2025-03-17
Human Metapneumovirus Testing Management System MEDIUM 5.4
CVE-2025-2371

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as problematic. Affected by this issue…

No fix yet
Fix from $1,600 2025-03-17
Vblog MEDIUM 5.4
CVE-2025-2364

A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the f…

Mitigation only
Fix from $1,600 2025-03-17
Starsea Mall MEDIUM 5.4
CVE-2025-2352

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the…

Mitigation only
Fix from $1,600 2025-03-16
Unclassified MEDIUM 6.5
CVE-2025-26924

Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Oh…

Mitigation only
Fix from $1,600 2025-03-15
Logicaldoc HIGH 7.2
CVE-2024-54448

The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account …

Fix: 9.1+
Fix from $1,950 2025-03-14
Nest MEDIUM 5.5
CVE-2024-29409

File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.

No fix yet
Fix from $1,600 2025-03-14
Unclassified HIGH 7.3
CVE-2025-1119

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in…

Mitigation only
Fix from $1,950 2025-03-13
Unclassified CRITICAL 9.0
CVE-2025-27407

graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, …

Patch available
Fix from $2,300 2025-03-12