Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2025-34159 Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platf… Coolify 4.0.0+ Fix from $1,9502025-08-27 CRITICAL 9.8 CVE-2025-52122 Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code… Freeform 5.10.16+ Fix from $2,3002025-08-27 CRITICAL 9.4 CVE-2025-30056 The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on … Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.4 CVE-2025-30057 In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF func… Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.0 CVE-2025-30055 The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code pr… Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.4 CVE-2025-2313 In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter. Mitigation only Fix from $2,3002025-08-27 HIGH 7.8 CVE-2025-23315 NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious data created by an attacker coul… Nemo 2.4.0+ Fix from $1,9502025-08-26 HIGH 7.8 CVE-2025-23307 NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. A successful… Nemo Curator 25.07+ Fix from $1,9502025-08-26 HIGH 7.8 CVE-2025-23312 NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker cou… Nemo 2.4.0+ Fix from $1,9502025-08-26 HIGH 7.8 CVE-2025-23313 NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code… Nemo 2.4.0+ Fix from $1,9502025-08-26 HIGH 7.8 CVE-2025-23314 NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code… Nemo 2.4.0+ Fix from $1,9502025-08-26 HIGH 7.5 CVE-2025-52218 SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified param… Selectzero 2025.5.2+ Fix from $1,9502025-08-26 HIGH 7.8 CVE-2025-53419 Delta Electronics COMMGR has Code Injection vulnerability. No fix yet Fix from $1,9502025-08-26 MEDIUM 6.1 CVE-2025-9439 A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this vulnerability is an unkno… Online Student Project Report Submission And Evaluation System No fix yet Fix from $1,6002025-08-26 MEDIUM 6.1 CVE-2025-9440 A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some… Online Student Project Report Submission And Evaluation System No fix yet Fix from $1,6002025-08-26 MEDIUM 6.1 CVE-2025-9433 A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin… Mblog after 3.5.0 Fix from $1,6002025-08-26 MEDIUM 6.1 CVE-2025-9434 A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects an unknown function of the fi… Online Student Project Report Submission And Evaluation System No fix yet Fix from $1,6002025-08-26 MEDIUM 6.1 CVE-2025-9438 A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected is an unknown function of th… Online Student Project Report Submission And Evaluation System No fix yet Fix from $1,6002025-08-26 MEDIUM 6.1 CVE-2025-9431 A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cr… Mblog after 3.5.0 Fix from $1,6002025-08-26 MEDIUM 6.1 CVE-2025-9432 A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component … Mblog after 3.5.0 Fix from $1,6002025-08-26 MEDIUM 5.4 CVE-2025-9429 A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the compon… Mblog after 3.5.0 Fix from $1,6002025-08-26 MEDIUM 5.4 CVE-2025-9422 A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team of the component Team Image H… Samarium after 0.9.6 Fix from $1,6002025-08-25 CRITICAL 9.8 CVE-2025-57772EPSS 9% DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If… Dataease 2.10.12+ Fix from $2,3002025-08-25 CRITICAL 9.8 CVE-2025-57773EPSS 8% DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JN… Dataease 2.10.12+ Fix from $2,3002025-08-25 MEDIUM 5.4 CVE-2025-9407 A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing… Mblog after 3.5.0 Fix from $1,6002025-08-25 MEDIUM 5.4 CVE-2025-9404 A vulnerability was identified in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file /pointHierarchySLTS of the compone… Scada Lts after 2.7.8.1 Fix from $1,6002025-08-25 MEDIUM 5.4 CVE-2025-9388 A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of th… Scada Lts after 2.7.8.1 Fix from $1,6002025-08-24 CRITICAL 10.0 CVE-2022-31491 Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to… Mitigation only Fix from $2,3002025-08-22 CRITICAL 9.8 CVE-2024-52786 An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted U… Mitigation only Fix from $2,3002025-08-22 HIGH 8.4 CVE-2010-20120 Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .maplet file is opened. This be… No fix yet Fix from $1,9502025-08-21