Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.1 CVE-2025-11433 A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/cont… Leave Management System No fix yet Fix from $1,6002025-10-08 MEDIUM 5.4 CVE-2025-11421 A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin/candidates_edit.php. This ma… Voting System No fix yet Fix from $1,6002025-10-08 MEDIUM 6.1 CVE-2025-11390 A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file… Cyber Cafe Management System No fix yet Fix from $1,6002025-10-07 CRITICAL 9.3 CVE-2025-61774 PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vul… Patch available Fix from $2,3002025-10-06 CRITICAL 9.8 CVE-2025-11344 A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate I… Ilias Mitigation only Fix from $2,3002025-10-06 MEDIUM 6.1 CVE-2025-11332 A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php of the component URL Handler.… Cmseasy after 7.7.7.0 Fix from $1,6002025-10-06 MEDIUM 6.1 CVE-2025-11306 A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The m… Foxcms after 1.2 Fix from $1,6002025-10-05 MEDIUM 5.4 CVE-2025-11289 A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the… Cicadascms No fix yet Fix from $1,6002025-10-05 MEDIUM 6.1 CVE-2025-11282 A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Pe… Learning after 2.35.0 Fix from $1,6002025-10-05 HIGH 8.8 CVE-2025-54374 Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code execution vulnerability. An … Eidos after 0.21.0 Fix from $1,9502025-10-03 HIGH 7.3 CVE-2025-46818 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu… Redis 6.2.20 / 7.2.11+ Fix from $1,9502025-10-03 HIGH 8.8 CVE-2025-61593 Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive … Cursor after 1.7 Fix from $1,9502025-10-03 HIGH 7.5 CVE-2025-61590 Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual St… Cursor 1.7+ Fix from $1,9502025-10-03 HIGH 8.8 CVE-2025-59536EPSS 33% Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementat… Claude Code 1.0.111+ Fix from $1,9502025-10-03 CRITICAL 9.3 CVE-2025-61588 RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below … Patch available Fix from $2,3002025-10-02 HIGH 8.8 CVE-2025-56588 Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed f… Dolibarr Erp\/crm Patch available Fix from $1,9502025-10-01 HIGH 7.5 CVE-2025-11153 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3. Firefox 143.0.3+ Fix from $1,9502025-09-30 CRITICAL 9.8 CVE-2025-59954 Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using a… Knowage 8.1.27+ Fix from $2,3002025-09-30 HIGH 8.7 CVE-2025-59952 MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service… Patch available Fix from $1,9502025-09-30 MEDIUM 5.4 CVE-2025-11124 A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/pos… Project Monitoring System No fix yet Fix from $1,6002025-09-28 MEDIUM 6.1 CVE-2025-11119 A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of … Hostel Management System No fix yet Fix from $1,6002025-09-28 MEDIUM 6.1 CVE-2025-11112 A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown function of the file /myprofi… Employee Record Management System No fix yet Fix from $1,6002025-09-28 MEDIUM 5.4 CVE-2025-11027 A vulnerability was identified in givanz Vvveb up to 1.0.7.2. Affected by this issue is some unknown functionality of the component SVG File Handler.… Vvveb after 1.0.7.2 Fix from $1,6002025-09-26 MEDIUM 6.6 CVE-2025-60114 Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Code Injection.This issue affec… Mitigation only Fix from $1,6002025-09-26 HIGH 7.2 CVE-2025-10993 A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the componen… Muyucms after 2.7 Fix from $1,9502025-09-26 CRITICAL 9.9 CVE-2025-59823 Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Ex… Mitigation only Fix from $2,3002025-09-25 HIGH 7.6 CVE-2025-59251 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Edge Chromium 140.0.3485.81+ Fix from $1,9502025-09-24 HIGH 7.8 CVE-2025-23353 NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause … Megatron Lm 0.12.3+ Fix from $1,9502025-09-24 HIGH 7.8 CVE-2025-23354 NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause … Megatron Lm 0.12.3+ Fix from $1,9502025-09-24 HIGH 7.8 CVE-2025-23348 NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a cod… Megatron Lm 0.12.3+ Fix from $1,9502025-09-24