Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2025-5407 A vulnerability has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513 and classified as problematic. Affected by th… Blogbook after 2021-11-22 Fix from $1,6002025-06-01 MEDIUM 5.4 CVE-2025-5405 A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This i… Blogbook after 2021-11-22 Fix from $1,6002025-06-01 MEDIUM 6.1 CVE-2025-5378 A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown part of the file mycouncil2.a… Ishare Maps Mitigation only Fix from $1,6002025-05-31 MEDIUM 6.1 CVE-2025-5377 A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issue is some unknown functionali… Ishare Maps Mitigation only Fix from $1,6002025-05-31 HIGH 7.2 CVE-2025-48390 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code injection due to insufficient… Freescout 1.8.178+ Fix from $1,9502025-05-29 HIGH 7.8 CVE-2025-32801 Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry p… Mitigation only Fix from $1,9502025-05-28 HIGH 7.8 CVE-2025-5151 A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This affects the function execute_analysis_code_safely of t… Introspect after 0.1.4 Fix from $1,9502025-05-25 HIGH 8.8 CVE-2025-5150 A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /do… Docarray after 0.40.1 Fix from $1,9502025-05-25 HIGH 7.2 CVE-2025-5137 A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an unknown function of the file dede/sys_verifies.php?a… Dedecms No fix yet Fix from $1,9502025-05-25 MEDIUM 6.1 CVE-2025-5135 A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionali… Tmall Demo after 2025-05-05 Fix from $1,6002025-05-24 MEDIUM 6.1 CVE-2025-5134 A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the c… Tmall Demo after 2025-05-05 Fix from $1,6002025-05-24 MEDIUM 6.1 CVE-2025-5133 A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function of the component Search Box. T… Tmall Demo after 2025-05-05 Fix from $1,6002025-05-24 MEDIUM 5.4 CVE-2025-5127 A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. Executing manipu… Flir Ax8 Firmware after 1.46.16 Fix from $1,6002025-05-24 CRITICAL 9.8 CVE-2024-51360 An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file Hospital Management System No fix yet Fix from $2,3002025-05-23 HIGH 8.4 CVE-2024-13952 Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromis… Mitigation only Fix from $1,9502025-05-22 HIGH 8.0 CVE-2025-30172 Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterpr… No fix yet Fix from $1,9502025-05-22 HIGH 8.0 CVE-2024-9639 Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enter… No fix yet Fix from $1,9502025-05-22 HIGH 7.2 CVE-2024-13928 SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become… Mitigation only Fix from $1,9502025-05-22 HIGH 7.2 CVE-2024-13929 Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects A… Mitigation only Fix from $1,9502025-05-22 HIGH 7.2 CVE-2025-45753 A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP… Vtiger Crm Mitigation only Fix from $1,9502025-05-21 HIGH 7.2 CVE-2025-45752 A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality i… Seeddms No fix yet Fix from $1,9502025-05-21 HIGH 8.4 CVE-2025-27998 An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL. Mitigation only Fix from $1,9502025-05-21 CRITICAL 9.8 CVE-2025-44881 A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a c… Wl Wn579a3 Firmware No fix yet Fix from $2,3002025-05-20 CRITICAL 9.8 CVE-2025-46724 Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval… Langroid 0.53.15+ Fix from $2,3002025-05-20 CRITICAL 9.8 CVE-2025-46725 Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas ev… Langroid 0.53.15+ Fix from $2,3002025-05-20 MEDIUM 6.1 CVE-2025-4939 A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown c… Credit Card Application Management System No fix yet Fix from $1,6002025-05-19 MEDIUM 6.8 CVE-2025-26621 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with the capabi… Opencti 6.5.2+ Fix from $1,6002025-05-19 HIGH 8.8 CVE-2025-4866 A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown function of the component Manageme… Rill Flow No fix yet Fix from $1,9502025-05-18 MEDIUM 6.1 CVE-2025-4862 A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some un… Directory Management System No fix yet Fix from $1,6002025-05-18 MEDIUM 5.3 CVE-2025-48119 Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP Book Showcase rs-wp-books-showcase allows Code Injectio… Mitigation only Fix from $1,6002025-05-16