Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.4 CVE-2025-67750 Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.… Patch available Fix from $1,9502025-12-12 MEDIUM 6.1 CVE-2025-14580 A security vulnerability has been detected in Qualitor up to 8.24.73. The impacted element is an unknown function of the file /Qualitor/html/bc/bcdoc… Qualitor 8.20.78 / 8.24.74+ Fix from $1,6002025-12-12 CRITICAL 9.8 CVE-2025-65854 Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeo… Mineadmin 3.0+ Fix from $2,3002025-12-12 MEDIUM 5.5 CVE-2025-12843 Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2. Wave Terminal No fix yet Fix from $1,6002025-12-12 CRITICAL 9.8 CVE-2025-67727 Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI … Parse Server after 8.5.0 Fix from $2,3002025-12-12 MEDIUM 5.3 CVE-2025-14166 The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin … Mitigation only Fix from $1,6002025-12-12 HIGH 8.8 CVE-2025-13780 pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restor… Pgadmin 4 after 9.10 Fix from $1,9502025-12-11 HIGH 7.8 CVE-2025-55313 An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code executi… Pdf Editor after 2025.1.0.66692 Fix from $1,9502025-12-11 MEDIUM 5.4 CVE-2025-14519 A security flaw has been discovered in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. This issue affects some unknown processing of the … Hfly after 2016-05-11 Fix from $1,6002025-12-11 HIGH 8.2 CVE-2025-67509 Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only B… Neuron 2.8.12+ Fix from $1,9502025-12-10 HIGH 8.8 CVE-2025-66474 XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)… Xwiki Rendering 16.10.10 / 17.4.3+ Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2025-65294 Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabli… Hub M2 Firmware Mitigation only Fix from $2,3002025-12-10 HIGH 7.2 CVE-2024-58284 PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code throug… Popojicms No fix yet Fix from $1,9502025-12-10 MEDIUM 6.8 CVE-2025-65829 The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only… Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware Mitigation only Fix from $1,6002025-12-10 CRITICAL 9.8 CVE-2025-65602 A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST… Chancms Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-67489 @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution… Patch available Fix from $2,3002025-12-09 HIGH 8.8 CVE-2025-66457 Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.17 and b… Elysia 1.4.18+ Fix from $1,9502025-12-09 MEDIUM 5.3 CVE-2025-66533 Improper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection.This issue affects GiveWP: fro… Mitigation only Fix from $1,6002025-12-09 CRITICAL 9.9 CVE-2025-42880 Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled functio… Mitigation only Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-14324 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund… Firefox 115.31.0 / 140.6.0+ Fix from $2,3002025-12-09 MEDIUM 5.4 CVE-2025-13642 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul… Mitigation only Fix from $1,6002025-12-09 CRITICAL 9.6 CVE-2025-66481 DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through impro… Deepchat after 0.5.1 Fix from $2,3002025-12-09 HIGH 8.8 CVE-2025-65271 Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of… Azuriom 1.2.7+ Fix from $1,9502025-12-08 MEDIUM 5.4 CVE-2025-14221 A vulnerability was detected in SourceCodester Online Banking System 1.0. This impacts an unknown function of the file /?page=user. The manipulation … Banking System No fix yet Fix from $1,6002025-12-08 MEDIUM 5.4 CVE-2025-14205 A vulnerability was found in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is an unknown function of the file /members… Chamber Of Commerce Membership Management System Mitigation only Fix from $1,6002025-12-08 MEDIUM 6.1 CVE-2025-14200 A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected … Hotel Management Services Using Mysql And Php Mitigation only Fix from $1,6002025-12-07 MEDIUM 5.4 CVE-2025-14194 A vulnerability was identified in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file /view_… Employee Profile Management System No fix yet Fix from $1,6002025-12-07 CRITICAL 9.6 CVE-2025-66562 TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exi… Tuui 1.3.4+ Fix from $2,3002025-12-05 MEDIUM 6.1 CVE-2025-14006 A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown functionality of the file /admind4… Xunruicms after 4.7.1 Fix from $1,6002025-12-04 MEDIUM 6.1 CVE-2025-14007 A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mobil… Xunruicms after 4.7.1 Fix from $1,6002025-12-04