Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2025-4324 A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file /admin/link/edit.do of the c… Mrcms No fix yet Fix from $1,6002025-05-06 MEDIUM 5.4 CVE-2025-4323 A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the comp… Mrcms No fix yet Fix from $1,6002025-05-06 HIGH 7.3 CVE-2025-2802 The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.3.1. This is due to the so… Mitigation only Fix from $1,9502025-05-06 MEDIUM 5.4 CVE-2025-4292 A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /… Mrcms No fix yet Fix from $1,6002025-05-05 MEDIUM 5.4 CVE-2025-4293 A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group… Mrcms No fix yet Fix from $1,6002025-05-05 CRITICAL 9.8 CVE-2025-44071 SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attacker… Seacms No fix yet Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-43845 Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. T… Retrieval Based Voice Conversion Webui after 2.2.231006 Fix from $2,3002025-05-05 CRITICAL 9.1 CVE-2025-24977 OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute… Opencti 6.4.11+ Fix from $2,3002025-05-05 MEDIUM 5.3 CVE-2025-4261 A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as critical. This affects the fu… Mitigation only Fix from $1,6002025-05-05 MEDIUM 6.1 CVE-2025-4257 A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pa… Seacms No fix yet Fix from $1,6002025-05-05 MEDIUM 5.4 CVE-2025-4256 A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipu… Seacms No fix yet Fix from $1,6002025-05-05 HIGH 7.3 CVE-2024-13738 The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up t… Mitigation only Fix from $1,9502025-05-03 HIGH 7.8 CVE-2025-4218 A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulnerability is the function GPTS… Browserpilot after 0.2.51 Fix from $1,9502025-05-02 CRITICAL 9.8 CVE-2025-2421 Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection. This issue affects S… Sambabox 5.1+ Fix from $2,3002025-05-02 HIGH 7.4 CVE-2025-46569 Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API … Patch available Fix from $1,9502025-05-01 CRITICAL 9.8 CVE-2025-45947 An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the … Online Banquet Booking System No fix yet Fix from $2,3002025-04-28 CRITICAL 9.8 CVE-2024-32499 Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. Project Center after 2023.3.0.32259 Fix from $2,3002025-04-28 CRITICAL 9.8 CVE-2023-42404 OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution. Workspace Mitigation only Fix from $2,3002025-04-28 HIGH 8.8 CVE-2015-2079 Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argume… Usermin 1.660+ Fix from $1,9502025-04-28 HIGH 8.8 CVE-2025-4022 A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentE… Webarena after 0.2.0 Fix from $1,9502025-04-28 CRITICAL 9.8 CVE-2025-46661 IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template ex… Metazo after 8.1.13 Fix from $2,3002025-04-28 MEDIUM 5.4 CVE-2025-4000 A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function … Oa Web Application System Mitigation only Fix from $1,6002025-04-28 MEDIUM 5.4 CVE-2025-3999 A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unk… Oa Web Application System Mitigation only Fix from $1,6002025-04-28 HIGH 7.5 CVE-2025-3984 A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\we… Central Authentication Service Mitigation only Fix from $1,9502025-04-27 HIGH 8.8 CVE-2025-3982 A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sve… Sverchok No fix yet Fix from $1,9502025-04-27 MEDIUM 5.4 CVE-2025-3970 A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. Th… Jsite after 1.0 Fix from $1,6002025-04-27 MEDIUM 5.4 CVE-2025-3965 A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality … Paicoding No fix yet Fix from $1,6002025-04-27 HIGH 7.8 CVE-2025-46579 There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users d… Zxcloud Goldendb 6.1.03.11+ Fix from $1,9502025-04-27 MEDIUM 6.5 CVE-2024-13812 The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.1.1. This is du… Mitigation only Fix from $1,6002025-04-26 HIGH 7.2 CVE-2025-3491 The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and inc… Mitigation only Fix from $1,9502025-04-26