Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.3 CVE-2026-3955 A security vulnerability has been detected in elecV2P up to 3.8.3. Affected by this issue is the function runJSFile of the file source-code/elecV2P-m… Mitigation only Fix from $1,6002026-03-11 CRITICAL 9.8 CVE-2019-25468 NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by … Mitigation only Fix from $2,3002026-03-11 HIGH 8.8 CVE-2026-31857 Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions sys… Craft Cms 4.17.4 / 5.9.9+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-31861EPSS 6% Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-conf… Cloud Cli 1.24.0+ Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2025-67038 KEVEPSS 14% An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. … Eds5032 Firmware Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2025-67035 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due… Eds5032 Firmware Mitigation only Fix from $2,3002026-03-11 HIGH 8.8 CVE-2025-67036 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing s… Eds5032 Firmware Mitigation only Fix from $1,9502026-03-11 HIGH 8.8 CVE-2025-67037 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a t… Eds5032 Firmware Mitigation only Fix from $1,9502026-03-11 HIGH 8.8 CVE-2025-67034 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL … Eds5032 Firmware Mitigation only Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2026-30741 A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt… Openclaw after 2026.2.6 Fix from $2,3002026-03-11 HIGH 7.2 CVE-2026-20892 Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privileges to execute arbitrary com… Mitigation only Fix from $1,9502026-03-11 CRITICAL 9.4 CVE-2026-30960 rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics … Mitigation only Fix from $2,3002026-03-10 HIGH 8.2 CVE-2026-2273 CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the enginee… Ecostruxure Automation Expert 25.0.1+ Fix from $1,9502026-03-10 CRITICAL 9.9 CVE-2026-30887 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/Java… Oneuptime 10.0.18+ Fix from $2,3002026-03-10 MEDIUM 5.4 CVE-2026-3819 A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown function of the file /?page=manage… Resort Reservation System No fix yet Fix from $1,6002026-03-09 MEDIUM 6.1 CVE-2026-3812 A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the file /manage_employee_allowances… Payroll Management System No fix yet Fix from $1,6002026-03-09 MEDIUM 5.4 CVE-2026-3766 A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file … Web Based Pharmacy Product Management System No fix yet Fix from $1,6002026-03-08 MEDIUM 6.1 CVE-2026-3763 A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown function of the file showhisto… Simple Flight Ticket Booking System No fix yet Fix from $1,6002026-03-08 MEDIUM 5.4 CVE-2026-3741 A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php… Yifang No fix yet Fix from $1,6002026-03-08 MEDIUM 5.4 CVE-2026-3742 A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a… Yifang No fix yet Fix from $1,6002026-03-08 MEDIUM 5.4 CVE-2026-3743 A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation … Yifang No fix yet Fix from $1,6002026-03-08 MEDIUM 5.4 CVE-2026-3721 A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of the file sa-base/src/main/ja… Smartadmin after 3.29 Fix from $1,6002026-03-08 MEDIUM 5.4 CVE-2026-3720 A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript… Smartadmin after 3.29 Fix from $1,6002026-03-08 MEDIUM 6.1 CVE-2026-3702 A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /index.ph… Loan Management System No fix yet Fix from $1,6002026-03-08 HIGH 7.2 CVE-2026-3352 The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0.4 via the `update_wp_memory_… Mitigation only Fix from $1,9502026-03-07 HIGH 8.1 CVE-2026-29091 Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) f… Locutus 3.0.0+ Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-29075 Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and pri… Mesa after 3.5.0 Fix from $2,3002026-03-06 MEDIUM 6.1 CVE-2026-2830 The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t… Mitigation only Fix from $1,6002026-03-06 HIGH 7.5 CVE-2026-29039 changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to … Changedetection 0.54.4+ Fix from $1,9502026-03-06 HIGH 7.8 CVE-2026-28801 Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code contained inside of a pattern or … Natro Macro 1.1.0+ Fix from $1,9502026-03-06