Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.8 CVE-2025-23349 NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code inje… Megatron Lm 0.12.3+ Fix from $1,9502025-09-24 HIGH 7.2 CVE-2025-5717 An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor a… Api Control Plane Mitigation only Fix from $1,9502025-09-23 CRITICAL 9.8 CVE-2025-9321 The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input valida… Mitigation only Fix from $2,3002025-09-23 MEDIUM 5.4 CVE-2025-10837 A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerability is an unknown functionali… Simple Food Ordering System Mitigation only Fix from $1,6002025-09-23 MEDIUM 6.1 CVE-2025-10827 A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /previ… Restaurant Menu Maker No fix yet Fix from $1,6002025-09-23 CRITICAL 10.0 CVE-2025-59528EPSS 91% Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execu… Flowise Mitigation only Fix from $2,3002025-09-22 MEDIUM 5.4 CVE-2025-58673 Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue … Mitigation only Fix from $1,6002025-09-22 HIGH 8.8 CVE-2025-57439 Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacke… Creabox Manager No fix yet Fix from $1,9502025-09-22 MEDIUM 6.1 CVE-2025-10794 A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the file /carrental/search.php. E… Car Rental Project No fix yet Fix from $1,6002025-09-22 HIGH 8.8 CVE-2025-54815 Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes. Ppress No fix yet Fix from $1,9502025-09-19 CRITICAL 9.1 CVE-2025-57644 Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can exe… Automation Platform Mitigation only Fix from $2,3002025-09-19 MEDIUM 5.4 CVE-2025-10632 A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file ava… Online Petshop Management System No fix yet Fix from $1,6002025-09-18 MEDIUM 5.4 CVE-2025-10631 A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the co… Online Petshop Management System No fix yet Fix from $1,6002025-09-18 MEDIUM 6.1 CVE-2025-10614 A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of… E Logbook With Health Monitoring System For Covid 19 No fix yet Fix from $1,6002025-09-17 CRITICAL 9.0 CVE-2025-58766 Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows att… Patch available Fix from $2,3002025-09-17 MEDIUM 6.1 CVE-2025-10605 A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. … I Educar after 2.10.0 Fix from $1,6002025-09-17 MEDIUM 6.1 CVE-2025-10606 A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/Configu… I Educar after 2.10.0 Fix from $1,6002025-09-17 MEDIUM 6.1 CVE-2025-10590 A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuar… I Educar after 2.10.0 Fix from $1,6002025-09-17 MEDIUM 5.4 CVE-2025-10591 A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_funcao_cad.php of the… I Educar after 2.10.0 Fix from $1,6002025-09-17 HIGH 8.8 CVE-2025-10057 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includ… Mitigation only Fix from $1,9502025-09-17 MEDIUM 5.4 CVE-2025-10584 A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_ca… I Educar after 2.10.0 Fix from $1,6002025-09-17 MEDIUM 6.1 CVE-2025-10566 A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file … Grocery Sales And Inventory System No fix yet Fix from $1,6002025-09-16 CRITICAL 10.0 CVE-2025-41243 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable wh… Mitigation only Fix from $2,3002025-09-16 MEDIUM 6.1 CVE-2025-10411 A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of … E Logbook With Health Monitoring System For Covid 19 No fix yet Fix from $1,6002025-09-14 HIGH 7.2 CVE-2025-10394 A vulnerability has been found in fcba_zzm ics-park Smart Park Management System 2.0. Affected is an unknown function of the file ruoyi-quartz/src/ma… Smart Park Management System No fix yet Fix from $1,9502025-09-14 MEDIUM 6.1 CVE-2025-10373 A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /intranet/educa… I Educar after 2.10.0 Fix from $1,6002025-09-13 MEDIUM 5.4 CVE-2025-10372 A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This m… I Educar after 2.10.0 Fix from $1,6002025-09-13 MEDIUM 6.1 CVE-2025-10369 A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdocs/cardRegisterNew.php. Execut… Rpi Jukebox Rfid after 2.8.0 Fix from $1,6002025-09-13 MEDIUM 5.4 CVE-2025-10370 A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php.… Rpi Jukebox Rfid after 2.8.0 Fix from $1,6002025-09-13 MEDIUM 6.1 CVE-2025-10368 A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/manageFi… Rpi Jukebox Rfid after 2.8.0 Fix from $1,6002025-09-13