Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.1 CVE-2025-3391 A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function … Oa System 2025.01.01+ Fix from $1,6002025-04-08 MEDIUM 6.1 CVE-2025-3389 A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMes… Oa System 2025.01.01+ Fix from $1,6002025-04-08 MEDIUM 6.1 CVE-2025-3390 A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of … Oa System 2025.01.01+ Fix from $1,6002025-04-08 MEDIUM 6.1 CVE-2025-3388 A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of th… Oa System 2025.01.01+ Fix from $1,6002025-04-07 MEDIUM 5.4 CVE-2025-3387 A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknown part of the component JSON … Renren Security after 5.4.0 Fix from $1,6002025-04-07 CRITICAL 9.8 CVE-2025-3248 KEVEPSS 100% Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can … Langflow 1.3.0+ Fix from $2,3002025-04-07 MEDIUM 6.1 CVE-2025-3327 A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown processing of the file /comm… Iboot No fix yet Fix from $1,6002025-04-07 MEDIUM 6.1 CVE-2025-3252 A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unknown code of the file /resourc… Admintwo No fix yet Fix from $1,6002025-04-04 MEDIUM 6.1 CVE-2025-3253 A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown processing of the file /ztree/ins… Admintwo No fix yet Fix from $1,6002025-04-04 MEDIUM 6.1 CVE-2025-3251 A vulnerability, which was classified as problematic, was found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet.… Admintwo No fix yet Fix from $1,6002025-04-04 CRITICAL 9.8 CVE-2025-28146EPSS 11% Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm… Br 6478ac V3 Firmware No fix yet Fix from $2,3002025-04-04 MEDIUM 5.4 CVE-2025-3219 A vulnerability was found in CodeCanyon Perfex CRM 3.2.1. It has been classified as problematic. Affected is an unknown function of the file /perfex/… Perfex Crm No fix yet Fix from $1,6002025-04-04 CRITICAL 9.8 CVE-2024-13645 The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. Th… Mitigation only Fix from $2,3002025-04-04 HIGH 8.8 CVE-2024-45199 insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, trig… Mitigation only Fix from $1,9502025-04-03 CRITICAL 9.8 CVE-2025-29064 An issue in TOTOLINK x18 v.9.1.0cu.2024_B20220329 allows a remote attacker to execute arbitrary code via the sub_410E54 function of the cstecgi.cgi. X18 Firmware Mitigation only Fix from $2,3002025-04-03 HIGH 8.8 CVE-2024-45198 insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering … Mitigation only Fix from $1,9502025-04-03 CRITICAL 9.8 CVE-2025-26818 Netwrix Password Secure through 9.2 allows command injection. Password Secure 9.2.2+ Fix from $2,3002025-04-03 HIGH 7.8 CVE-2025-3163 A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of … Lmdeploy after 0.7.1 Fix from $1,9502025-04-03 CRITICAL 9.8 CVE-2025-3164 A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknow… Supersonic after 0.9.8 Fix from $2,3002025-04-03 HIGH 8.8 CVE-2025-2945EPSS 47% Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POS… Pgadmin 4 9.2+ Fix from $1,9502025-04-03 HIGH 8.8 CVE-2025-31722 In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with It… Templating Engine 2.5.4+ Fix from $1,9502025-04-02 CRITICAL 10.0 CVE-2025-30580 Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidgets-image-editor allows Remote … Mitigation only Fix from $2,3002025-04-01 CRITICAL 9.9 CVE-2025-30911 Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This iss… Mitigation only Fix from $2,3002025-04-01 HIGH 7.8 CVE-2025-24243 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sono… Ipados 2.4 / 13.7.5+ Fix from $1,9502025-03-31 MEDIUM 6.1 CVE-2025-3036 A vulnerability, which was classified as problematic, was found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b60a77a2c85f52d2102f5/d4d7a064… Studentservlet Jsp No fix yet Fix from $1,6002025-03-31 CRITICAL 9.8 CVE-2024-54807 In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInterna… Wnr854t Firmware No fix yet Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2024-54803 Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the … Wnr854t Firmware No fix yet Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2024-54804 Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the … Wnr854t Firmware No fix yet Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2024-54805 Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the … Wnr854t Firmware No fix yet Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2024-54806 Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via t… Wnr854t Firmware No fix yet Fix from $2,3002025-03-31