Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.2 CVE-2020-36870 Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management s… Mitigation only Fix from $2,3002025-11-07 CRITICAL 10.0 CVE-2025-49372 Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code I… Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.1 CVE-2025-47588 Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynami… Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.9 CVE-2025-32222 Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic allows Code Injection.This issue… Mitigation only Fix from $2,3002025-11-06 HIGH 7.2 CVE-2025-11093 An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Media… Api Control Plane 3.1.0.345 / 3.2.0.446+ Fix from $1,9502025-11-05 CRITICAL 9.8 CVE-2025-12735 The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variable… Javascript Expression Evaluator after 2.0.2 Fix from $2,3002025-11-05 HIGH 8.8 CVE-2025-64108 Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to ci… Cursor 2.0+ Fix from $1,9502025-11-04 HIGH 7.2 CVE-2025-62369 Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution … Xibo 4.3.1+ Fix from $1,9502025-11-04 MEDIUM 5.3 CVE-2025-64318 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Conf… Mulesoft Anypoint Code Builder 1.12.1+ Fix from $1,6002025-11-04 MEDIUM 6.5 CVE-2025-64320 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affec… Agentforce Vibes 3.2.0+ Fix from $1,6002025-11-04 MEDIUM 5.3 CVE-2025-64321 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configur… Agentforce Vibes 3.3.0+ Fix from $1,6002025-11-04 MEDIUM 6.5 CVE-2025-10875 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue a… Mulesoft Anypoint Code Builder 1.11.6+ Fix from $1,6002025-11-04 HIGH 8.8 CVE-2025-60785 A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary cod… Icescrum No fix yet Fix from $1,9502025-11-03 HIGH 8.8 CVE-2025-6990 The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via the `TH_PhpCode` pagebuilder… Mitigation only Fix from $1,9502025-11-01 HIGH 7.3 CVE-2025-10487 The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.12 via … Mitigation only Fix from $1,9502025-11-01 MEDIUM 5.4 CVE-2025-12546 A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This m… Logicaldoc after 9.2.1 Fix from $1,6002025-10-31 HIGH 8.8 CVE-2025-48984 A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. Veeam Backup \& Replication 12.3.2.4165+ Fix from $1,9502025-10-31 CRITICAL 9.8 CVE-2025-34277 Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated … Log Server 2024+ Fix from $2,3002025-10-30 HIGH 8.8 CVE-2025-61196 An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter. Mitigation only Fix from $1,9502025-10-30 CRITICAL 9.8 CVE-2025-50739 iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization. Mitigation only Fix from $2,3002025-10-30 HIGH 8.8 CVE-2025-56399 alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload… Mitigation only Fix from $1,9502025-10-28 MEDIUM 6.1 CVE-2025-12335 A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages… E Commerce Website No fix yet Fix from $1,6002025-10-28 MEDIUM 6.1 CVE-2025-12334 A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulati… E Commerce Website No fix yet Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-12333 A vulnerability has been found in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/supplier_add.php. The man… E Commerce Website No fix yet Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-12302 A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.p… Simple Food Ordering System No fix yet Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-12300 A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addcategory.… Simple Food Ordering System No fix yet Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-12298 A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the file /editcategory.php. The mani… Simple Food Ordering System No fix yet Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-12299 A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct… Simple Food Ordering System No fix yet Fix from $1,6002025-10-27 MEDIUM 5.4 CVE-2025-12280 A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Per… Client Details System No fix yet Fix from $1,6002025-10-27 MEDIUM 5.4 CVE-2025-12281 A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executi… Client Details System No fix yet Fix from $1,6002025-10-27