Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2024-13808 The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.9 via the custo… Xpro Addons For Elementor 1.4.10+ Fix from $1,9502025-04-26 HIGH 7.3 CVE-2025-2801 The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode exe… Mitigation only Fix from $1,9502025-04-26 HIGH 8.8 CVE-2025-3642 A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to … Moodle 4.1.18 / 4.3.12+ Fix from $1,9502025-04-25 HIGH 8.8 CVE-2025-3641 A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to … Moodle 4.1.18 / 4.3.12+ Fix from $1,9502025-04-25 CRITICAL 10.0 CVE-2025-32432 KEVEPSS 100% Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.1… Craft Cms 3.9.15 / 4.14.15+ Fix from $2,3002025-04-25 HIGH 8.3 CVE-2025-3776 The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via… Mitigation only Fix from $1,9502025-04-24 MEDIUM 6.7 CVE-2025-1976 KEV Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary… Fabric Operating System 9.1.1d7+ Fix from $1,6002025-04-24 MEDIUM 6.5 CVE-2025-0618 A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protecti… Mitigation only Fix from $1,6002025-04-23 CRITICAL 9.8 CVE-2023-43958 An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthe… Hospital Management System No fix yet Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2025-23251 NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A success… Nemo 25.02+ Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2024-40446 An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script Mimetex 1.77+ Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2025-3472 The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the s… Ocean Extra 2.4.7+ Fix from $2,3002025-04-22 CRITICAL 9.8 CVE-2025-3842 A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUserPic.action of the file src/c… Ds Java No fix yet Fix from $2,3002025-04-21 CRITICAL 9.8 CVE-2025-3841 A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an … Jam 2018-03-27+ Fix from $2,3002025-04-21 MEDIUM 5.4 CVE-2025-3822 A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects so… Web Based Pharmacy Product Management System No fix yet Fix from $1,6002025-04-20 MEDIUM 5.4 CVE-2025-3821 A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability… Web Based Pharmacy Product Management System No fix yet Fix from $1,6002025-04-20 CRITICAL 9.8 CVE-2025-29058 An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component. Qimou Cms Mitigation only Fix from $2,3002025-04-18 MEDIUM 5.4 CVE-2025-3789 A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /a… Jsite No fix yet Fix from $1,6002025-04-18 MEDIUM 5.4 CVE-2025-3788 A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of th… Jsite No fix yet Fix from $1,6002025-04-18 HIGH 7.2 CVE-2025-3509 A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting… Enterprise Server 3.13.16 / 3.14.13+ Fix from $1,9502025-04-17 CRITICAL 9.8 CVE-2024-53924 Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with t… Pycel No fix yet Fix from $2,3002025-04-17 HIGH 7.2 CVE-2025-29661 Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run. Litepubl Cms after 7.09 Fix from $1,9502025-04-17 CRITICAL 9.8 CVE-2025-29662 A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network acces… Landchat No fix yet Fix from $2,3002025-04-17 HIGH 7.2 CVE-2025-29039 An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8 Dir 823x Firmware No fix yet Fix from $1,9502025-04-17 HIGH 7.3 CVE-2025-32596 Improper Control of Generation of Code ('Code Injection') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Code Injection… No fix yet Fix from $1,9502025-04-17 CRITICAL 9.9 CVE-2025-32583EPSS 16% Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.8 CVE-2024-56518 Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka … Management Center after 6.0 Fix from $2,3002025-04-17 CRITICAL 9.1 CVE-2025-1532 Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and… Phoneservice 11.0.0.276+ Fix from $2,3002025-04-17 HIGH 8.8 CVE-2024-53303 A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 allows authenticated attackers … Mitigation only Fix from $1,9502025-04-16 MEDIUM 5.4 CVE-2025-3692 A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by this vulnerability is an unknow… Online Eyewear Shop No fix yet Fix from $1,6002025-04-16