Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2025-7112 A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown processing of the file /intrane… I Educar Mitigation only Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-7113 A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown function of the file /module/Co… I Educar Mitigation only Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-7110 A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown part of the file /intranet/educ… I Educar Mitigation only Fix from $1,6002025-07-07 MEDIUM 5.4 CVE-2025-7109 A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionali… I Educar Mitigation only Fix from $1,6002025-07-07 CRITICAL 9.8 CVE-2025-7101 A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of the file /install/install_ok.… Boyuncms after 1.4.20 Fix from $2,3002025-07-07 CRITICAL 9.5 CVE-2025-5333 Remote attackers can execute arbitrary code in the context of the vulnerable service process. No fix yet Fix from $2,3002025-07-06 HIGH 7.2 CVE-2025-52718 Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code Inclusion.This issue affects A… Mitigation only Fix from $1,9502025-07-04 CRITICAL 10.0 CVE-2025-49302 Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows Remote Code Inclusion.This i… Mitigation only Fix from $2,3002025-07-04 MEDIUM 6.1 CVE-2025-7053 A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/u… Cockpit after 2.11.3 Fix from $1,6002025-07-04 CRITICAL 9.3 CVE-2025-34089 An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in version… No fix yet Fix from $2,3002025-07-03 HIGH 8.8 CVE-2025-34086 Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A … Bolt after 3.7.0 Fix from $1,9502025-07-03 CRITICAL 9.3 CVE-2025-34061 A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. Th… Mitigation only Fix from $2,3002025-07-03 CRITICAL 9.4 CVE-2025-34074 An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task function… Mitigation only Fix from $2,3002025-07-02 HIGH 7.8 CVE-2025-34079 An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and ExternalScripts module are enab… Nsclient\+\+ No fix yet Fix from $1,9502025-07-02 CRITICAL 9.8 CVE-2025-37099 A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. Insight Remote Support 7.15.0.646+ Fix from $2,3002025-07-01 CRITICAL 9.1 CVE-2025-49029 Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget a… Mitigation only Fix from $2,3002025-07-01 HIGH 8.8 CVE-2025-49521 A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 te… Mitigation only Fix from $1,9502025-06-30 HIGH 8.6 CVE-2025-28993 Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-cache allows Code Injection.Th… Mitigation only Fix from $1,9502025-06-27 MEDIUM 6.1 CVE-2025-6700 A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/log… Xxl Sso No fix yet Fix from $1,6002025-06-26 CRITICAL 9.8 CVE-2025-53002 LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and… Llama Factory 0.9.4+ Fix from $2,3002025-06-26 MEDIUM 5.4 CVE-2025-6613 A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability is an unknown functi… Hospital Management System No fix yet Fix from $1,6002025-06-25 CRITICAL 9.8 CVE-2024-37743 An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component. Knowledgegpt Mitigation only Fix from $2,3002025-06-24 HIGH 7.8 CVE-2025-23265 NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a… Megatron Lm 0.12.1+ Fix from $1,9502025-06-24 HIGH 7.8 CVE-2025-23264 NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a… Megatron Lm 0.12.1+ Fix from $1,9502025-06-24 MEDIUM 6.1 CVE-2025-6569 A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vulnerability is an unknown fun… School Fees Payment System No fix yet Fix from $1,6002025-06-24 MEDIUM 5.4 CVE-2025-6551 A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/j… Hope Boot No fix yet Fix from $1,6002025-06-24 CRITICAL 9.8 CVE-2023-47030 An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a U… Terminal Handler Mitigation only Fix from $2,3002025-06-23 CRITICAL 9.8 CVE-2023-47032 Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOA… Terminal Handler Mitigation only Fix from $2,3002025-06-23 CRITICAL 9.8 CVE-2023-48978 An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL com… Itm Web Terminal Mitigation only Fix from $2,3002025-06-23 CRITICAL 10.0 CVE-2025-6512 On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administra… Mitigation only Fix from $2,3002025-06-23