Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.1 CVE-2025-14005 A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionality of the file /admind45f74ad… Xunruicms after 4.7.1 Fix from $1,6002025-12-04 CRITICAL 9.6 CVE-2025-66222 DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the M… Deepchat after 0.5.0 Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2024-32641EPSS 12% Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code … Masacms 7.2.8 / 7.3.13+ Fix from $2,3002025-12-03 CRITICAL 9.8 CVE-2025-13486EPSS 74% The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_… Mitigation only Fix from $2,3002025-12-03 CRITICAL 9.3 CVE-2025-13658 A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed endpoint, due to the absence o… Mitigation only Fix from $2,3002025-12-02 HIGH 8.8 CVE-2025-66448 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a conf… Vllm 0.11.1+ Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-66299 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenti… Grav 1.8.0+ Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-66294 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authentic… Grav 1.8.0+ Fix from $1,9502025-12-01 HIGH 8.1 CVE-2024-39148 The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute ar… Keros 5.12+ Fix from $1,9502025-12-01 HIGH 7.3 CVE-2025-13792 A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stde… Mitigation only Fix from $1,9502025-11-30 CRITICAL 9.8 CVE-2025-13786 A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. P… Wtcms after 2019-12-20 Fix from $2,3002025-11-30 HIGH 8.8 CVE-2025-66224 OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw i… Orangehrm 5.8+ Fix from $1,9502025-11-29 HIGH 8.8 CVE-2025-62593 KEV Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerabi… Ray 2.52.0+ Fix from $1,9502025-11-26 HIGH 7.8 CVE-2025-33204 NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cau… Nemo 2.5.1+ Fix from $1,9502025-11-25 HIGH 7.2 CVE-2025-64050 A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to e… Redaxo No fix yet Fix from $1,9502025-11-25 CRITICAL 9.8 CVE-2025-6389EPSS 73% The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pa… Mitigation only Fix from $2,3002025-11-25 MEDIUM 5.4 CVE-2025-13577 A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Ex… Hostel Management System Mitigation only Fix from $1,6002025-11-24 CRITICAL 10.0 CVE-2025-65108 md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block… Patch available Fix from $2,3002025-11-21 MEDIUM 6.1 CVE-2025-13484 A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file … Online Beauty Parlor Management System No fix yet Fix from $1,6002025-11-20 HIGH 7.3 CVE-2025-12120 Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for co… Lite Xl after 2.1.8 Fix from $1,9502025-11-20 MEDIUM 5.4 CVE-2025-13450 A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipu… Online Shop Project No fix yet Fix from $1,6002025-11-20 MEDIUM 5.4 CVE-2025-13415 A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image H… Easyimages2.0 after 2.8.6 Fix from $1,6002025-11-19 MEDIUM 6.1 CVE-2025-13412 A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file… Retro Basketball Shoes Online Store No fix yet Fix from $1,6002025-11-19 CRITICAL 9.8 CVE-2025-65099 Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked… Claude Code 1.0.39+ Fix from $2,3002025-11-19 CRITICAL 9.6 CVE-2025-65026 esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Litera… Esm.sh 136+ Fix from $2,3002025-11-19 HIGH 8.6 CVE-2025-10702 Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Acc… Mitigation only Fix from $1,9502025-11-19 HIGH 8.6 CVE-2025-10703 Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Acc… Mitigation only Fix from $1,9502025-11-19 HIGH 8.0 CVE-2025-13035 The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's u… Mitigation only Fix from $1,9502025-11-19 MEDIUM 5.4 CVE-2025-63693 The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in m… Dzzoffice after 2.3.7 Fix from $1,6002025-11-18 HIGH 8.8 CVE-2025-37157 A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to cond… Arubaos Cx 10.10.1170 / 10.13.1101+ Fix from $1,9502025-11-18