Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2025-12269 A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unknown function of the file /dash… Learnhouse after 2025-09-21 Fix from $1,6002025-10-27 MEDIUM 6.3 CVE-2025-12266 A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the functio… Mitigation only Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-12246 A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/… Chatwoot after 4.7.0 Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-12244 A vulnerability was determined in code-projects Simple E-Banking System 1.0. This affects an unknown part of the file /eBank/register.php. Executing … Simple E Banking System No fix yet Fix from $1,6002025-10-27 MEDIUM 5.4 CVE-2025-12227 A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.ph… Gate Pass Management System No fix yet Fix from $1,6002025-10-27 CRITICAL 9.1 CVE-2025-62959 Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Remote Co… Mitigation only Fix from $2,3002025-10-27 MEDIUM 6.3 CVE-2025-8483 The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl… Mitigation only Fix from $1,6002025-10-25 HIGH 7.1 CVE-2025-61136 A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset… Mitigation only Fix from $1,9502025-10-23 CRITICAL 9.0 CVE-2025-62023 Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a t… Mitigation only Fix from $2,3002025-10-22 CRITICAL 10.0 CVE-2025-60206 Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: f… Mitigation only Fix from $2,3002025-10-22 HIGH 7.4 CVE-2025-52756 Improper Control of Generation of Code ('Code Injection') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Remote Code… Mitigation only Fix from $1,9502025-10-22 HIGH 7.2 CVE-2025-49926 Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection.This issue affects Kalium: f… No fix yet Fix from $1,9502025-10-22 MEDIUM 5.4 CVE-2025-8848 A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP … Librechat No fix yet Fix from $1,6002025-10-22 HIGH 7.6 CVE-2025-61488 An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php com… Mitigation only Fix from $1,9502025-10-20 HIGH 7.2 CVE-2025-62429 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbitrary PHP code execution. In … Clipbucket 5.5.2-147+ Fix from $1,9502025-10-20 MEDIUM 5.4 CVE-2025-11946 A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp… Logicaldoc after 9.2.1 Fix from $1,6002025-10-19 CRITICAL 9.1 CVE-2025-57567 A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default them… Mitigation only Fix from $2,3002025-10-17 HIGH 8.8 CVE-2025-11905 A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\control… Chancms after 3.3.2 Fix from $1,9502025-10-17 MEDIUM 6.8 CVE-2025-62416 Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user i… Bagisto No fix yet Fix from $1,6002025-10-16 CRITICAL 9.3 CVE-2025-11548 A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to … Mitigation only Fix from $2,3002025-10-14 HIGH 7.1 CVE-2025-31365 An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may al… Forticlient 7.2.9 / 7.4.4+ Fix from $1,9502025-10-14 CRITICAL 9.8 CVE-2025-46581 ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands wit… Mitigation only Fix from $2,3002025-10-14 HIGH 8.8 CVE-2025-41699 An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as … Mitigation only Fix from $1,9502025-10-14 MEDIUM 5.4 CVE-2025-42901 SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's brow… Mitigation only Fix from $1,6002025-10-14 HIGH 7.2 CVE-2025-61927 Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower contains a security vulnerabi… Patch available Fix from $1,9502025-10-10 CRITICAL 9.6 CVE-2025-61929 Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When … Cherry Studio 1.6.4+ Fix from $2,3002025-10-10 HIGH 8.1 CVE-2025-61773 pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient … Patch available Fix from $1,9502025-10-09 CRITICAL 9.9 CVE-2025-11539 Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/… Mitigation only Fix from $2,3002025-10-09 MEDIUM 6.1 CVE-2025-11512 A vulnerability was found in code-projects Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/voters_add.php.… Voting System No fix yet Fix from $1,6002025-10-09 MEDIUM 6.1 CVE-2025-11435 A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /sh… Opnform after 1.9.3 Fix from $1,6002025-10-08