Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.4
CVE-2025-34124
A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m m…
No fix yet
HIGH 8.4
CVE-2025-34123
A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The …
No fix yet
CRITICAL 9.8
CVE-2025-37105
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
Autopass License Server
9.18+
CRITICAL 9.8
CVE-2025-53890
pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code a…
Patch available
HIGH 8.8
CVE-2025-53836
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)…
Xwiki
13.10.11 / 14.4.7+
MEDIUM 5.4
CVE-2025-7601
A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vulnerability affects unknown c…
Online Library Management System
No fix yet
HIGH 8.0
CVE-2024-51768
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
Autopass License Server
9.17+
HIGH 7.2
CVE-2024-58258EPSS 13%
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
Mitigation only
HIGH 7.2
CVE-2025-50123
A
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote
command execution by a privileged a…
Mitigation only
CRITICAL 9.8
CVE-2025-5392
The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front()…
Mitigation only
MEDIUM 6.1
CVE-2025-53626
pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabili…
Patch available
MEDIUM 5.4
CVE-2025-7408
A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerability affects unknown code of …
Zoo Management System
No fix yet
MEDIUM 6.3
CVE-2024-7650
Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The
vulnerabili…
Mitigation only
CRITICAL 10.0
CVE-2025-34077EPSS 10%
An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arb…
Mitigation only
HIGH 8.6
CVE-2025-53547
Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock fi…
Helm
3.17.4 / 3.18.4+
HIGH 8.8
CVE-2025-49704 KEVEPSS 100%
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
Mitigation only
HIGH 7.5
CVE-2025-47988
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent net…
Azure Monitor Agent
1.35.1+
MEDIUM 6.1
CVE-2025-7182
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability…
Student Transcript Processing System
No fix yet
HIGH 7.3
CVE-2025-6744
The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the s…
Woodmart
8.2.4+
CRITICAL 9.9
CVE-2025-42967
SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to cre…
Mitigation only
MEDIUM 5.4
CVE-2025-7153
A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown …
Simple Hospital Management System
No fix yet
MEDIUM 5.4
CVE-2025-7148
A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown fu…
Simple Hospital Management System
No fix yet
MEDIUM 5.4
CVE-2025-7142
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is so…
Best Salon Management System
No fix yet
MEDIUM 5.4
CVE-2025-7143
A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of t…
Best Salon Management System
No fix yet
MEDIUM 5.4
CVE-2025-7140
A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the f…
Best Salon Management System
No fix yet
MEDIUM 5.4
CVE-2025-7141
A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown …
Best Salon Management System
No fix yet
MEDIUM 5.4
CVE-2025-7139
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This issue affects some unknown proce…
Best Salon Management System
No fix yet
MEDIUM 6.7
CVE-2025-36014
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.
Integration Bus
after 10.1.0.5
CRITICAL 9.8
CVE-2025-45479
Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted c…
Challenges
Mitigation only
MEDIUM 5.4
CVE-2025-7111
A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects unknown code of the file /intra…
I Educar
Mitigation only