Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.3 CVE-2025-48120 Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Code Injection… No fix yet Fix from $1,6002025-05-16 MEDIUM 5.3 CVE-2025-47562 Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg allows Code Injection.This issue affects MapSVG: f… No fix yet Fix from $1,6002025-05-16 CRITICAL 9.8 CVE-2025-47916EPSS 84% Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeed… Invisioncommunity 5.0.7+ Fix from $2,3002025-05-16 MEDIUM 5.3 CVE-2025-4767 A vulnerability was found in defog-ai introspect up to 0.1.4. It has been rated as critical. Affected by this issue is the function test_custom_tool … Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.4 CVE-2025-4745 A vulnerability, which was classified as problematic, was found in code-projects Employee Record System 1.0. This affects an unknown part of the file… Employee Record System No fix yet Fix from $1,6002025-05-16 HIGH 8.8 CVE-2025-3053 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions u… Mitigation only Fix from $1,9502025-05-15 CRITICAL 9.8 CVE-2025-32363 mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data. Mitigation only Fix from $2,3002025-05-14 MEDIUM 6.5 CVE-2025-0134 A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privi… Mitigation only Fix from $1,6002025-05-14 HIGH 8.8 CVE-2024-54780EPSS 12% Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to impro… Pfsense Ce 2.8.0 / 25.03+ Fix from $1,9502025-05-14 CRITICAL 9.8 CVE-2024-24780 Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu… Iotdb 1.3.4+ Fix from $2,3002025-05-14 HIGH 8.8 CVE-2025-4428 KEVEPSS 86% Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t… Endpoint Manager Mobile 11.12.0.5 / 12.3.0.2+ Fix from $1,9502025-05-13 CRITICAL 9.8 CVE-2025-45857 EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function. Cv 7428ns Firmware No fix yet Fix from $2,3002025-05-13 HIGH 8.3 CVE-2025-43010 SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to exe… Mitigation only Fix from $1,9502025-05-13 CRITICAL 9.8 CVE-2025-44022 An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism. Vvveb Patch available Fix from $2,3002025-05-12 MEDIUM 6.3 CVE-2025-47271 The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In vers… Patch available Fix from $1,6002025-05-12 MEDIUM 5.4 CVE-2025-4551 A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/c… Continew Admin after 3.6.0 Fix from $1,6002025-05-11 HIGH 8.8 CVE-2025-4531 A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected by this issue is the function … Oa Web Application System Mitigation only Fix from $1,9502025-05-11 MEDIUM 5.4 CVE-2025-4495 A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of… Jadmin No fix yet Fix from $1,6002025-05-10 CRITICAL 9.8 CVE-2025-46191 Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbit… Client Database Management System Mitigation only Fix from $2,3002025-05-09 HIGH 8.8 CVE-2025-28203 Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability. Rx1800 Firmware No fix yet Fix from $1,9502025-05-09 CRITICAL 9.3 CVE-2025-1087 Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vuln… Mitigation only Fix from $2,3002025-05-09 MEDIUM 5.4 CVE-2025-4469 A vulnerability classified as problematic has been found in SourceCodester Online Student Clearance System 1.0. Affected is an unknown function of th… Online Student Clearance System No fix yet Fix from $1,6002025-05-09 MEDIUM 5.4 CVE-2025-4470 A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by this vulnerability is an unkno… Online Student Clearance System No fix yet Fix from $1,6002025-05-09 MEDIUM 5.4 CVE-2025-4461 A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unknown code of the component Virt… N150rt Firmware No fix yet Fix from $1,6002025-05-09 CRITICAL 9.8 CVE-2025-26845 An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command e… Znuny after 7.1.3 Fix from $2,3002025-05-08 MEDIUM 6.3 CVE-2025-4208 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up t… Nex Forms after 8.9.2 Fix from $1,6002025-05-08 HIGH 7.3 CVE-2024-13793 The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an… Wolmart 1.8.12+ Fix from $1,9502025-05-08 MEDIUM 5.5 CVE-2025-47691 Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.3 CVE-2025-47481 Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Code Injection.This… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2025-4326 A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of … Mrcms No fix yet Fix from $1,6002025-05-06