Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.9 CVE-2025-7961 Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This issue affects KAP: 3.6.0. Mitigation only Fix from $1,6002025-08-15 CRITICAL 9.8 CVE-2025-54466EPSS 15% Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects A… Ofbiz 24.09.02+ Fix from $2,3002025-08-15 MEDIUM 6.3 CVE-2025-8905 The Inpersttion For Theme plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0 via the theme_section… Mitigation only Fix from $1,6002025-08-15 MEDIUM 6.1 CVE-2025-9017 A vulnerability has been found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-foreigner-tick… Zoo Management System No fix yet Fix from $1,6002025-08-15 MEDIUM 5.4 CVE-2025-9003 A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsc_lan.php of the component DHCP Reser… Dir 818lw Firmware No fix yet Fix from $1,6002025-08-15 MEDIUM 5.4 CVE-2025-8975 A vulnerability was identified in givanz Vvveb up to 1.0.5. This affects an unknown part of the file admin/template/content/edit.tpl. The manipulatio… Vvveb 1.0.6+ Fix from $1,6002025-08-14 MEDIUM 5.4 CVE-2025-8976 A vulnerability has been found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/index.php?module=content/p… Vvveb 1.0.6+ Fix from $1,6002025-08-14 HIGH 8.6 CVE-2025-55192 HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerab… Patch available Fix from $1,9502025-08-14 CRITICAL 9.9 CVE-2025-49887 Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-w… Mitigation only Fix from $2,3002025-08-14 MEDIUM 6.5 CVE-2025-39483 Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injection.This issue affects Eventer… Mitigation only Fix from $1,6002025-08-14 CRITICAL 9.8 CVE-2025-55346EPSS 18% User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS… Mitigation only Fix from $2,3002025-08-14 MEDIUM 6.1 CVE-2025-8934 A vulnerability has been found in 1000 Projects Sales Management System 1.0. Affected is an unknown function of the file /sales.php. The manipulation… Sales Management System No fix yet Fix from $1,6002025-08-14 MEDIUM 6.1 CVE-2025-8933 A vulnerability was identified in 1000 Projects Sales Management System 1.0. This issue affects some unknown processing of the file /superstore/admin… Sales Management System No fix yet Fix from $1,6002025-08-14 CRITICAL 9.8 CVE-2011-10018 myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitr… Mybb Mitigation only Fix from $2,3002025-08-13 CRITICAL 9.8 CVE-2011-10019 Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to proper… Spree 0.60.2+ Fix from $2,3002025-08-13 CRITICAL 10.0 CVE-2011-10011 WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request… Mitigation only Fix from $2,3002025-08-13 CRITICAL 10.0 CVE-2011-10013 Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to… Mitigation only Fix from $2,3002025-08-13 MEDIUM 5.4 CVE-2025-8920 A vulnerability was identified in Portabilis i-Diario 1.6. Affected by this vulnerability is an unknown functionality of the file /dicionario-de-term… I Diario No fix yet Fix from $1,6002025-08-13 HIGH 7.8 CVE-2025-23305 NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a code injection issue. A success… Megatron Lm 0.12.2+ Fix from $1,9502025-08-13 HIGH 7.8 CVE-2025-23306 NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an attacker could cause a code i… Megatron Lm 0.12.2+ Fix from $1,9502025-08-13 HIGH 7.8 CVE-2025-23295 NVIDIA Apex for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue by providing a mali… Apex after 25.07 Fix from $1,9502025-08-13 HIGH 7.8 CVE-2025-23296 NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue. A successfu… Mitigation only Fix from $1,9502025-08-13 HIGH 7.8 CVE-2025-23298 NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection issu… Mitigation only Fix from $1,9502025-08-13 CRITICAL 9.8 CVE-2025-23304 NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loadin… Nemo 2.3.2+ Fix from $2,3002025-08-13 CRITICAL 9.8 CVE-2025-52385 An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process module Mitigation only Fix from $2,3002025-08-13 CRITICAL 9.9 CVE-2025-42957 SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injectio… Mitigation only Fix from $2,3002025-08-12 MEDIUM 6.1 CVE-2025-42945 SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload a… Mitigation only Fix from $1,6002025-08-12 CRITICAL 9.9 CVE-2025-42950 SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This fl… Mitigation only Fix from $2,3002025-08-12 CRITICAL 9.6 CVE-2025-54063 Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution … Cherry Studio 1.5.1+ Fix from $2,3002025-08-11 MEDIUM 5.4 CVE-2025-8847 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /system/notice/edit. Th… Ruoyi after 4.8.1 Fix from $1,6002025-08-11