Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.4 CVE-2025-34124 A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m m… No fix yet Fix from $1,9502025-07-16 HIGH 8.4 CVE-2025-34123 A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The … No fix yet Fix from $1,9502025-07-16 CRITICAL 9.8 CVE-2025-37105 An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. Autopass License Server 9.18+ Fix from $2,3002025-07-16 CRITICAL 9.8 CVE-2025-53890 pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code a… Patch available Fix from $2,3002025-07-15 HIGH 8.8 CVE-2025-53836 XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502025-07-15 MEDIUM 5.4 CVE-2025-7601 A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vulnerability affects unknown c… Online Library Management System No fix yet Fix from $1,6002025-07-14 HIGH 8.0 CVE-2024-51768 An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. Autopass License Server 9.17+ Fix from $1,9502025-07-14 HIGH 7.2 CVE-2024-58258EPSS 13% SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur. Mitigation only Fix from $1,9502025-07-13 HIGH 7.2 CVE-2025-50123 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged a… Mitigation only Fix from $1,9502025-07-11 CRITICAL 9.8 CVE-2025-5392 The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front()… Mitigation only Fix from $2,3002025-07-11 MEDIUM 6.1 CVE-2025-53626 pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabili… Patch available Fix from $1,6002025-07-10 MEDIUM 5.4 CVE-2025-7408 A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerability affects unknown code of … Zoo Management System No fix yet Fix from $1,6002025-07-10 MEDIUM 6.3 CVE-2024-7650 Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The vulnerabili… Mitigation only Fix from $1,6002025-07-10 CRITICAL 10.0 CVE-2025-34077EPSS 10% An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arb… Mitigation only Fix from $2,3002025-07-09 HIGH 8.6 CVE-2025-53547 Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock fi… Helm 3.17.4 / 3.18.4+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49704 KEVEPSS 100% Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server Mitigation only Fix from $1,9502025-07-08 HIGH 7.5 CVE-2025-47988 Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent net… Azure Monitor Agent 1.35.1+ Fix from $1,9502025-07-08 MEDIUM 6.1 CVE-2025-7182 A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability… Student Transcript Processing System No fix yet Fix from $1,6002025-07-08 HIGH 7.3 CVE-2025-6744 The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the s… Woodmart 8.2.4+ Fix from $1,9502025-07-08 CRITICAL 9.9 CVE-2025-42967 SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to cre… Mitigation only Fix from $2,3002025-07-08 MEDIUM 5.4 CVE-2025-7153 A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown … Simple Hospital Management System No fix yet Fix from $1,6002025-07-08 MEDIUM 5.4 CVE-2025-7148 A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown fu… Simple Hospital Management System No fix yet Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-7142 A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is so… Best Salon Management System No fix yet Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-7143 A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of t… Best Salon Management System No fix yet Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-7140 A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the f… Best Salon Management System No fix yet Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-7141 A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown … Best Salon Management System No fix yet Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-7139 A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This issue affects some unknown proce… Best Salon Management System No fix yet Fix from $1,6002025-07-07 MEDIUM 6.7 CVE-2025-36014 IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory. Integration Bus after 10.1.0.5 Fix from $1,6002025-07-07 CRITICAL 9.8 CVE-2025-45479 Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted c… Challenges Mitigation only Fix from $2,3002025-07-07 MEDIUM 5.4 CVE-2025-7111 A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects unknown code of the file /intra… I Educar Mitigation only Fix from $1,6002025-07-07