Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2025-9306 A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.… Advanced School Management System No fix yet Fix from $1,6002025-08-21 MEDIUM 5.4 CVE-2025-9237 A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of t… Ecommerce Website No fix yet Fix from $1,6002025-08-20 MEDIUM 5.4 CVE-2025-9235 A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of … Scada Lts after 2.7.8.1 Fix from $1,6002025-08-20 MEDIUM 5.4 CVE-2025-9234 A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenance_events.shtm. The manipul… Scada Lts after 2.7.8.1 Fix from $1,6002025-08-20 MEDIUM 5.4 CVE-2025-9233 A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_edit.shtm. The manipulation o… Scada Lts after 2.7.8.1 Fix from $1,6002025-08-20 HIGH 8.8 CVE-2025-51991 XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Met… Xwiki after 17.3.0 Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-54019 Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: f… Mitigation only Fix from $1,6002025-08-20 CRITICAL 10.0 CVE-2025-53577 Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Code Inclusion.This issue affect… Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.9 CVE-2025-48169 Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Remote Code Inclusion.This issue… Mitigation only Fix from $2,3002025-08-20 HIGH 7.5 CVE-2025-30975 Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issu… Mitigation only Fix from $1,9502025-08-20 MEDIUM 5.4 CVE-2025-9171 A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Cl… Solidinvoice after 2.4.0 Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-9169 A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This m… Solidinvoice after 2.4.0 Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-9170 A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax R… Solidinvoice after 2.4.0 Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-9168 A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creat… Solidinvoice after 2.4.0 Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-9167 A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component R… Solidinvoice after 2.4.0 Fix from $1,6002025-08-19 CRITICAL 9.6 CVE-2025-55733 DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerab… Deepchat Patch available Fix from $2,3002025-08-19 MEDIUM 6.1 CVE-2025-9147 A vulnerability has been found in jasonclark getsemantic up to 040c96eb8cf9947488bd01b8de99b607b0519f7d. The impacted element is an unknown function … Getsemantic No fix yet Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-9145 A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file view_edit.shtm of the compone… Scada Lts No fix yet Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-9143 A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. The manipulation of the argume… Scada Lts No fix yet Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-9144 A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit.shtm. This manipulation of th… Scada Lts No fix yet Fix from $1,6002025-08-19 CRITICAL 10.0 CVE-2025-50567 Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (e… Mitigation only Fix from $2,3002025-08-19 MEDIUM 5.4 CVE-2025-9138 A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Performing manipulation of the argum… Scada Lts No fix yet Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2025-8723EPSS 15% The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization… Mitigation only Fix from $2,3002025-08-19 MEDIUM 6.1 CVE-2025-9107 A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/search_autocomplete. Executin… I Diario after 1.5.0 Fix from $1,6002025-08-18 MEDIUM 5.4 CVE-2025-9106 A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the c… I Diario after 1.5.0 Fix from $1,6002025-08-18 MEDIUM 5.4 CVE-2025-9105 A vulnerability has been found in Portabilis i-Diario up to 1.5.0. The impacted element is an unknown function of the file /planos-de-ensino-por-area… I Diario after 1.5.0 Fix from $1,6002025-08-18 MEDIUM 5.4 CVE-2025-9104 A flaw has been found in Portabilis i-Diario up to 1.5.0. The affected element is an unknown function of the file /planos-de-aulas-por-disciplina/ of… I Diario after 1.5.0 Fix from $1,6002025-08-18 MEDIUM 5.4 CVE-2025-9101 A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the comp… My Blog No fix yet Fix from $1,6002025-08-18 MEDIUM 6.5 CVE-2025-8878 The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is… Mitigation only Fix from $1,6002025-08-16 HIGH 7.3 CVE-2025-8105 The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the so… Mitigation only Fix from $1,9502025-08-16