Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.8 CVE-2025-33183 NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successf… Mitigation only Fix from $1,9502025-11-18 HIGH 7.8 CVE-2025-33184 NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successf… Mitigation only Fix from $1,9502025-11-18 MEDIUM 5.4 CVE-2025-13349 A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown processing of the file /grades… Student Grades Management System No fix yet Fix from $1,6002025-11-18 MEDIUM 5.4 CVE-2025-13343 A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function of the file /editQuestion.php.… Interview Management System No fix yet Fix from $1,6002025-11-18 MEDIUM 5.4 CVE-2025-7711 The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve… Mitigation only Fix from $1,6002025-11-17 MEDIUM 6.1 CVE-2025-13244 A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown function of the file /register.php… Student Information System No fix yet Fix from $1,6002025-11-16 MEDIUM 5.4 CVE-2025-13245 A vulnerability was identified in code-projects Student Information System 2.0. The impacted element is an unknown function of the file /editprofile.… Student Information System No fix yet Fix from $1,6002025-11-16 MEDIUM 5.4 CVE-2025-13202 A security flaw has been discovered in code-projects Simple Cafe Ordering System 1.0. This affects an unknown part of the file /add_to_cart. Performi… Simple Cafe Ordering System No fix yet Fix from $1,6002025-11-15 MEDIUM 5.4 CVE-2025-13186 A weakness has been identified in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution up to 4.0. This impacts an unknown function o… Isshue after 4.0 Fix from $1,6002025-11-14 CRITICAL 9.8 CVE-2025-12762EPSS 12% pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restore… Pgadmin 4 9.10+ Fix from $2,3002025-11-13 HIGH 8.8 CVE-2025-12733 The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… Mitigation only Fix from $1,9502025-11-13 MEDIUM 5.4 CVE-2025-13058 A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler… Extplorer after 2.1.15 Fix from $1,6002025-11-12 MEDIUM 6.7 CVE-2024-48829 Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A hig… Smartfabric Os10 10.6.1.0+ Fix from $1,6002025-11-12 HIGH 7.8 CVE-2025-33178 NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause… Nemo 2.5.0+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-23357 NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection iss… Mitigation only Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-23361 NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause improper control… Nemo 2.5.0+ Fix from $1,9502025-11-11 CRITICAL 9.8 CVE-2025-12813 The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'conten… Mitigation only Fix from $2,3002025-11-11 HIGH 8.8 CVE-2025-12637 The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation feature in the process_theme f… Mitigation only Fix from $1,9502025-11-11 MEDIUM 6.9 CVE-2025-42895 Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply c… Mitigation only Fix from $1,6002025-11-11 CRITICAL 9.9 CVE-2025-42887 Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled functio… Mitigation only Fix from $2,3002025-11-11 HIGH 8.8 CVE-2025-9334 The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and includin… Mitigation only Fix from $1,9502025-11-08 CRITICAL 9.2 CVE-2020-36870 Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management s… Mitigation only Fix from $2,3002025-11-07 CRITICAL 10.0 CVE-2025-49372 Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code I… Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.1 CVE-2025-47588 Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynami… Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.9 CVE-2025-32222 Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic allows Code Injection.This issue… Mitigation only Fix from $2,3002025-11-06 HIGH 7.2 CVE-2025-11093 An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Media… Api Control Plane 3.1.0.345 / 3.2.0.446+ Fix from $1,9502025-11-05 CRITICAL 9.8 CVE-2025-12735 The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variable… Javascript Expression Evaluator after 2.0.2 Fix from $2,3002025-11-05 HIGH 8.8 CVE-2025-64108 Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to ci… Cursor 2.0+ Fix from $1,9502025-11-04 HIGH 7.2 CVE-2025-62369 Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution … Xibo 4.3.1+ Fix from $1,9502025-11-04 MEDIUM 5.3 CVE-2025-64318 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Conf… Mulesoft Anypoint Code Builder 1.12.1+ Fix from $1,6002025-11-04