Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2025-3005 A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is some unknown functionality of … Forestblog 2025-03-21+ Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-3004 A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functi… Forestblog 2025-03-21+ Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-2979 A vulnerability classified as problematic has been found in WCMS 11. This affects an unknown part of the file /index.php?anonymous/setregister of the… Wcms No fix yet Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-2976 A vulnerability was found in GFI KerioConnect 10.0.6. It has been classified as problematic. Affected is an unknown function of the component File Up… Kerio Connect No fix yet Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-2977 A vulnerability was found in GFI KerioConnect 10.0.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality… Kerio Connect No fix yet Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-2974 A vulnerability has been found in CodeCanyon Perfex CRM up to 3.2.1 and classified as problematic. This vulnerability affects unknown code of the fil… Perfex Crm after 3.2.1 Fix from $1,6002025-03-31 MEDIUM 5.4 CVE-2025-2975 A vulnerability was found in GFI KerioConnect 10.0.6 and classified as problematic. This issue affects some unknown processing of the file Settings/E… Kerio Connect No fix yet Fix from $1,6002025-03-31 HIGH 7.3 CVE-2025-2803 The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due t… Mitigation only Fix from $1,9502025-03-29 MEDIUM 6.5 CVE-2024-13557 The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6. This… Mitigation only Fix from $1,6002025-03-29 CRITICAL 9.8 CVE-2025-29306EPSS 46% An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component. Foxcms 1.2+ Fix from $2,3002025-03-27 HIGH 7.2 CVE-2025-30067 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project adm… Kylin 5.0.2+ Fix from $1,9502025-03-27 MEDIUM 6.5 CVE-2025-2867 An issue has been discovered in the GitLab Duo with Amazon Q affecting all versions from 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.… GitLab 17.8.6 / 17.9.3+ Fix from $1,6002025-03-27 HIGH 8.8 CVE-2025-2787 KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component.… Business Hub 1.10.4 / 1.11.4+ Fix from $1,9502025-03-26 CRITICAL 9.8 CVE-2024-55964EPSS 6% An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command executio… Appsmith 1.52+ Fix from $2,3002025-03-26 CRITICAL 9.8 CVE-2025-26003 Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest. Tlr 2005ksh Firmware Mitigation only Fix from $2,3002025-03-26 MEDIUM 6.8 CVE-2024-41643 An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component. Mitigation only Fix from $1,6002025-03-26 CRITICAL 9.9 CVE-2025-28893 Improper Control of Generation of Code ('Code Injection') vulnerability in Govind Visual Text Editor visual-text-editor allows Remote Code Inclusion.… Mitigation only Fix from $2,3002025-03-26 CRITICAL 9.8 CVE-2024-55028 A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file. Fprime No fix yet Fix from $2,3002025-03-25 CRITICAL 9.8 CVE-2024-48818 An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code. No fix yet Fix from $2,3002025-03-25 CRITICAL 9.2 CVE-2024-45480 An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an una… Mitigation only Fix from $2,3002025-03-25 MEDIUM 6.1 CVE-2025-2712 A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality… Ufida Erp Nc No fix yet Fix from $1,6002025-03-24 MEDIUM 6.1 CVE-2025-2710 A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown processing of the file /menu.jsp.… Ufida Erp Nc No fix yet Fix from $1,6002025-03-24 MEDIUM 6.1 CVE-2025-2711 A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop… Ufida Erp Nc No fix yet Fix from $1,6002025-03-24 MEDIUM 6.1 CVE-2025-2709 A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.j… Ufida Erp Nc No fix yet Fix from $1,6002025-03-24 MEDIUM 5.4 CVE-2025-2700 A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert … Dante3 after 0.4.4 Fix from $1,6002025-03-24 MEDIUM 5.4 CVE-2025-2699 A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionalit… Contenttools after 1.6.16 Fix from $1,6002025-03-24 MEDIUM 5.4 CVE-2025-2673 A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file … Payroll Management System No fix yet Fix from $1,6002025-03-24 MEDIUM 6.5 CVE-2025-29806 No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 129.0.2792.52+ Fix from $1,6002025-03-23 MEDIUM 6.1 CVE-2025-2650 A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknow… Medical Card Generation System No fix yet Fix from $1,6002025-03-23 MEDIUM 6.1 CVE-2025-2645 A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. Affected is an unknown function of … Art Gallery Management System No fix yet Fix from $1,6002025-03-23