Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Plenti HIGH 8.8
CVE-2025-26260

Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript…

Fix: 0.7.17+
Fix from $1,950 2025-03-12
Microweber MEDIUM 6.1
CVE-2025-2214

A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/mo…

No fix yet
Fix from $1,600 2025-03-12
Cbw383g2n Firmware MEDIUM 6.1
CVE-2025-2212

A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an unknown part of the file /RgS…

Fix: after 2025-03-01
Fix from $1,600 2025-03-11
Ptz Dual Band Camera Firmware HIGH 7.7
CVE-2025-25680

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The …

No fix yet
Fix from $1,950 2025-03-11
Mrcms MEDIUM 6.1
CVE-2025-2196

A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /adm…

No fix yet
Fix from $1,600 2025-03-11
Mrcms MEDIUM 6.1
CVE-2025-2194

A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the c…

No fix yet
Fix from $1,600 2025-03-11
Mrcms MEDIUM 6.1
CVE-2025-2195

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of…

No fix yet
Fix from $1,600 2025-03-11
Keras CRITICAL 9.8
CVE-2025-1550

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras arch…

Fix: 3.8.0+
Fix from $2,300 2025-03-11
Unclassified HIGH 7.3
CVE-2025-2169

The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified CRITICAL 10.0
CVE-2025-26936

Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework allows Code Injection.This issue…

Mitigation only
Fix from $2,300 2025-03-10
Plotai CRITICAL 9.8
CVE-2025-1497

A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attack…

Fix: 0.0.7+
Fix from $2,300 2025-03-10
Openxe MEDIUM 5.4
CVE-2025-2130

A vulnerability was found in OpenXE up to 1.12. It has been declared as problematic. This vulnerability affects unknown code of the component Ticket …

Fix: after 1.12
Fix from $1,600 2025-03-09
Jux Real Estate MEDIUM 6.1
CVE-2025-2127

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the …

No fix yet
Fix from $1,600 2025-03-09
Geshi MEDIUM 6.1
CVE-2025-2123

A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is the function get_var of the fi…

Fix: after 1.0.9.1
Fix from $1,600 2025-03-09
Code Snippets Cpt MEDIUM 6.3
CVE-2024-13895

The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is du…

Fix: after 2.1.0
Fix from $1,600 2025-03-08
Allow Php Execute HIGH 7.2
CVE-2024-13890

The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP…

Mitigation only
Fix from $1,950 2025-03-08
Tornado CRITICAL 9.8
CVE-2024-42733

An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script to the UNC path input

Fix: after 2.9.7
Fix from $2,300 2025-03-07
Qts MEDIUM 5.5
CVE-2024-50405

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If …

Mitigation only
Fix from $1,600 2025-03-07
Qts HIGH 7.1
CVE-2024-53693

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If …

Mitigation only
Fix from $1,950 2025-03-07
Starsea Mall MEDIUM 6.1
CVE-2025-2087

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the…

No fix yet
Fix from $1,600 2025-03-07
Starsea Mall MEDIUM 6.1
CVE-2025-2086

A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown code of the file /admin/indexCo…

No fix yet
Fix from $1,600 2025-03-07
Starsea Mall MEDIUM 6.1
CVE-2025-2085

A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of the file /admin/carousels/sav…

No fix yet
Fix from $1,600 2025-03-07
Human Metapneumovirus MEDIUM 6.1
CVE-2025-2084

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as problematic. Affected is an un…

No fix yet
Fix from $1,600 2025-03-07
Online Ticket Reservation System MEDIUM 6.1
CVE-2025-2061

A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unkn…

No fix yet
Fix from $1,600 2025-03-07
Student Manage MEDIUM 5.4
CVE-2024-13902

A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown part of the component Edit a …

No fix yet
Fix from $1,600 2025-03-06
Unclassified CRITICAL 9.8
CVE-2025-25362

A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload …

Mitigation only
Fix from $2,300 2025-03-05
Unclassified MEDIUM 6.5
CVE-2024-13815

The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the s…

Mitigation only
Fix from $1,600 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27678

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001.

Fix: 20.0.1923 / 22.0.843+
Fix from $2,300 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27657

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.

Fix: 20.0.1923 / 22.0.843+
Fix from $2,300 2025-03-05
Online Class And Exam Scheduling System MEDIUM 5.4
CVE-2025-1955

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is s…

No fix yet
Fix from $1,600 2025-03-04