Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2025-48120
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Code Injection…
No fix yet
MEDIUM 5.3
CVE-2025-47562
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg allows Code Injection.This issue affects MapSVG: f…
No fix yet
CRITICAL 9.8
CVE-2025-47916EPSS 84%
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeed…
Invisioncommunity
5.0.7+
MEDIUM 5.3
CVE-2025-4767
A vulnerability was found in defog-ai introspect up to 0.1.4. It has been rated as critical. Affected by this issue is the function test_custom_tool …
Mitigation only
MEDIUM 5.4
CVE-2025-4745
A vulnerability, which was classified as problematic, was found in code-projects Employee Record System 1.0. This affects an unknown part of the file…
Employee Record System
No fix yet
HIGH 8.8
CVE-2025-3053
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions u…
Mitigation only
CRITICAL 9.8
CVE-2025-32363
mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.
Mitigation only
MEDIUM 6.5
CVE-2025-0134
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privi…
Mitigation only
HIGH 8.8
CVE-2024-54780EPSS 12%
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to impro…
Pfsense Ce
2.8.0 / 25.03+
CRITICAL 9.8
CVE-2024-24780
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious fu…
Iotdb
1.3.4+
HIGH 8.8
CVE-2025-4428 KEVEPSS 86%
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t…
Endpoint Manager Mobile
11.12.0.5 / 12.3.0.2+
CRITICAL 9.8
CVE-2025-45857
EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.
Cv 7428ns Firmware
No fix yet
HIGH 8.3
CVE-2025-43010
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to exe…
Mitigation only
CRITICAL 9.8
CVE-2025-44022
An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.
Vvveb
Patch available
MEDIUM 6.3
CVE-2025-47271
The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In vers…
Patch available
MEDIUM 5.4
CVE-2025-4551
A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/c…
Continew Admin
after 3.6.0
HIGH 8.8
CVE-2025-4531
A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected by this issue is the function …
Oa Web Application System
Mitigation only
MEDIUM 5.4
CVE-2025-4495
A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of…
Jadmin
No fix yet
CRITICAL 9.8
CVE-2025-46191
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbit…
Client Database Management System
Mitigation only
HIGH 8.8
CVE-2025-28203
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
Rx1800 Firmware
No fix yet
CRITICAL 9.3
CVE-2025-1087
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vuln…
Mitigation only
MEDIUM 5.4
CVE-2025-4469
A vulnerability classified as problematic has been found in SourceCodester Online Student Clearance System 1.0. Affected is an unknown function of th…
Online Student Clearance System
No fix yet
MEDIUM 5.4
CVE-2025-4470
A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by this vulnerability is an unkno…
Online Student Clearance System
No fix yet
MEDIUM 5.4
CVE-2025-4461
A vulnerability classified as problematic was found in TOTOLINK N150RT 3.4.0-B20190525. This vulnerability affects unknown code of the component Virt…
N150rt Firmware
No fix yet
CRITICAL 9.8
CVE-2025-26845
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command e…
Znuny
after 7.1.3
MEDIUM 6.3
CVE-2025-4208
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up t…
Nex Forms
after 8.9.2
HIGH 7.3
CVE-2024-13793
The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an…
Wolmart
1.8.12+
MEDIUM 5.5
CVE-2025-47691
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This…
Mitigation only
MEDIUM 5.3
CVE-2025-47481
Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Code Injection.This…
Mitigation only
MEDIUM 5.4
CVE-2025-4326
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of …
Mrcms
No fix yet