Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.1 CVE-2025-14962 A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file /market/chatuser.php. This ma… Simple Stock System No fix yet Fix from $1,6002025-12-19 CRITICAL 9.6 CVE-2025-66580 Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS)… Dive 0.11.1+ Fix from $2,3002025-12-19 CRITICAL 9.8 CVE-2025-63665 An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into… Gt Edge Ai 2.0.12+ Fix from $2,3002025-12-19 CRITICAL 9.3 CVE-2025-34433 AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installati… Patch available Fix from $2,3002025-12-19 CRITICAL 10.0 CVE-2025-65037 Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. Azure Container Apps Mitigation only Fix from $2,3002025-12-18 HIGH 7.2 CVE-2025-64676 '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. Purview No fix yet Fix from $1,9502025-12-18 HIGH 7.8 CVE-2023-53940 Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious m… No fix yet Fix from $1,9502025-12-18 HIGH 8.8 CVE-2025-68278 Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing att… Tinacms 2.0.3 / 2.0.4+ Fix from $1,9502025-12-18 CRITICAL 9.1 CVE-2025-66078 Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote … Mitigation only Fix from $2,3002025-12-18 MEDIUM 6.5 CVE-2025-60070 Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This issue affects Molla: from n/a … Mitigation only Fix from $1,6002025-12-18 MEDIUM 6.5 CVE-2025-60068 Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code Injection.This issue affects Ja… Mitigation only Fix from $1,6002025-12-18 HIGH 8.8 CVE-2025-14856 A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/get… Ruoyi after 4.8.1 Fix from $1,9502025-12-18 HIGH 7.2 CVE-2025-14837 A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/siteconfig.php of the component Back… Zzcms No fix yet Fix from $1,9502025-12-18 CRITICAL 9.8 CVE-2025-62521 ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM'… Churchcrm 5.21.0+ Fix from $2,3002025-12-17 HIGH 7.2 CVE-2025-67172 RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function. Ritecms No fix yet Fix from $1,9502025-12-17 CRITICAL 9.9 CVE-2025-67164 An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c… Pagekit Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2025-46295 Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the t… Filemaker Server 22.0.4+ Fix from $2,3002025-12-16 CRITICAL 9.8 CVE-2025-37164 KEVEPSS 90% A remote code execution issue exists in HPE OneView. Oneview after 10.20.00 Fix from $2,3002025-12-16 CRITICAL 9.6 CVE-2025-67744 DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerab… Deepchat 0.5.3+ Fix from $2,3002025-12-16 HIGH 7.8 CVE-2025-67748 Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of uns… Fickling 0.1.6+ Fix from $1,9502025-12-16 HIGH 7.2 CVE-2025-14729 A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_A… Ctcms after 2.1.2 Fix from $1,9502025-12-15 HIGH 7.2 CVE-2025-14730 A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms… Ctcms after 2.1.2 Fix from $1,9502025-12-15 HIGH 7.2 CVE-2023-53883 Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page… Webedition Cms No fix yet Fix from $1,9502025-12-15 HIGH 8.8 CVE-2023-53888 Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file … Zomplog No fix yet Fix from $1,9502025-12-15 HIGH 8.8 CVE-2025-66437 An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function rend… Erpnext after 15.89.0 Fix from $1,9502025-12-15 HIGH 8.8 CVE-2025-66438 A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, th… Erpnext after 15.89.0 Fix from $1,9502025-12-15 HIGH 8.8 CVE-2025-66434 An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function r… Erpnext after 15.89.0 Fix from $1,9502025-12-15 MEDIUM 6.1 CVE-2025-14691 A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation r… Mayan Edms 4.10.2+ Fix from $1,6002025-12-14 MEDIUM 5.4 CVE-2025-14662 A vulnerability was found in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php of the… Student File Management System No fix yet Fix from $1,6002025-12-14 MEDIUM 5.4 CVE-2025-14539 The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to … Mitigation only Fix from $1,6002025-12-13