Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Securerom MEDIUM 6.8
CVE-2019-8900EPSS 69%

A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting t…

Mitigation only
Fix from $1,600 2025-02-21
Ac6 Firmware MEDIUM 6.5
CVE-2025-25507

There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command executi…

No fix yet
Fix from $1,600 2025-02-21
Loggrove CRITICAL 9.8
CVE-2025-26014

A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.

No fix yet
Fix from $2,300 2025-02-21
Head\, Footer\, And Post Injections HIGH 7.2
CVE-2024-13900

The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes…

Fix: 3.3.1+
Fix from $1,950 2025-02-21
Ac10 Firmware CRITICAL 9.8
CVE-2025-25675

Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput pa…

Mitigation only
Fix from $2,300 2025-02-20
Unclassified CRITICAL 9.8
CVE-2024-54756

A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via suppl…

Mitigation only
Fix from $2,300 2025-02-20
Xwiki CRITICAL 9.8
CVE-2025-24893 KEVEPSS 100%

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code …

Fix: 15.10.11 / 16.4.1+
Fix from $2,300 2025-02-20
Security Verify Access HIGH 7.8
CVE-2025-0161

IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restri…

Fix: after 10.0.0.9
Fix from $1,950 2025-02-20
Shared Asset Booking System MEDIUM 6.5
CVE-2023-51324

PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnera…

No fix yet
Fix from $1,600 2025-02-20
Cleaning Business Software MEDIUM 6.5
CVE-2023-51331

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerab…

No fix yet
Fix from $1,600 2025-02-20
Restaurant Booking System MEDIUM 6.5
CVE-2023-51317

PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, …

No fix yet
Fix from $1,600 2025-02-20
Night Club Booking Software MEDIUM 5.3
CVE-2023-51320

PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnera…

No fix yet
Fix from $1,600 2025-02-20
Unclassified CRITICAL 9.8
CVE-2024-57401

SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password func…

Mitigation only
Fix from $2,300 2025-02-20
Restaurant Booking System HIGH 8.8
CVE-2023-51313

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerabi…

No fix yet
Fix from $1,950 2025-02-20
Woocommerce Food CRITICAL 9.8
CVE-2024-13792

The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and…

Fix: 3.3.3+
Fix from $2,300 2025-02-20
Unclassified MEDIUM 5.3
CVE-2025-27218EPSS 65%

Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

Mitigation only
Fix from $1,600 2025-02-20
Bento4 HIGH 7.8
CVE-2025-25943

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component lo…

No fix yet
Fix from $1,950 2025-02-19
Bento4 HIGH 7.3
CVE-2025-25944

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_Rtp…

No fix yet
Fix from $1,950 2025-02-19
Lmxcms MEDIUM 6.6
CVE-2025-1465

A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the compone…

No fix yet
Fix from $1,600 2025-02-19
Unclassified CRITICAL 9.8
CVE-2025-25467

Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted …

Mitigation only
Fix from $2,300 2025-02-18
Unclassified MEDIUM 6.3
CVE-2024-13689

The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the…

Mitigation only
Fix from $1,600 2025-02-18
Pressmart CRITICAL 9.8
CVE-2024-13797

The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to…

Fix: 1.2.17+
Fix from $2,300 2025-02-18
Dir 816 Firmware MEDIUM 5.4
CVE-2025-1392EPSS 8%

A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Mitigation only
Fix from $1,600 2025-02-17
Unclassified CRITICAL 9.8
CVE-2025-1302EPSS 10%

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can…

Patch available
Fix from $2,300 2025-02-15
Avada CRITICAL 9.8
CVE-2024-13346

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and…

Fix: 7.11.14+
Fix from $2,300 2025-02-13
Avada Builder CRITICAL 9.8
CVE-2024-13345

The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to t…

Fix: 3.11.14+
Fix from $2,300 2025-02-13
Maxair MEDIUM 5.4
CVE-2025-1213

A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the fi…

No fix yet
Fix from $1,600 2025-02-12
Wazifa System MEDIUM 5.4
CVE-2025-1209

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_…

No fix yet
Fix from $1,600 2025-02-12
Wazifa System MEDIUM 5.4
CVE-2025-1208

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the fil…

No fix yet
Fix from $1,600 2025-02-12
Real Estate Property Management System MEDIUM 5.4
CVE-2025-1195

A vulnerability, which was classified as problematic, has been found in code-projects Real Estate Property Management System 1.0. This issue affects …

No fix yet
Fix from $1,600 2025-02-12