Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2025-2623 A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality … Cicadascms No fix yet Fix from $1,6002025-03-22 HIGH 8.8 CVE-2025-2303 The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… Mitigation only Fix from $1,9502025-03-22 MEDIUM 5.4 CVE-2025-2590 A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic. Affected is the function Up… Human Resource Management No fix yet Fix from $1,6002025-03-21 MEDIUM 6.1 CVE-2025-2583 A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php… Simple Machines Forum No fix yet Fix from $1,6002025-03-21 MEDIUM 5.4 CVE-2025-2582 A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file… Simple Machines Forum No fix yet Fix from $1,6002025-03-21 HIGH 8.8 CVE-2025-29807 Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. Dataverse Mitigation only Fix from $1,9502025-03-21 HIGH 8.8 CVE-2025-0185 A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vuln… Dify No fix yet Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-9439 SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters… Superagi No fix yet Fix from $1,9502025-03-20 HIGH 8.4 CVE-2024-6982 A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Pytho… Patch available Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-6825 BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules'… Litellm 1.65.4+ Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-12215 In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, … Mitigation only Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-10950 In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause… Gpt Academic after 3.83 Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-10954 In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided promp… Gpt Academic No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-10572 In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGB… H2o No fix yet Fix from $1,9502025-03-20 HIGH 7.2 CVE-2024-10252 A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerabi… Dify after 0.9.1 Fix from $1,9502025-03-20 CRITICAL 9.8 CVE-2024-57061 An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses c… Mitigation only Fix from $2,3002025-03-19 CRITICAL 9.8 CVE-2025-29401 An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploadin… Emlog No fix yet Fix from $2,3002025-03-19 MEDIUM 5.4 CVE-2025-2491 A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cm… Ujcms No fix yet Fix from $1,6002025-03-18 MEDIUM 5.4 CVE-2025-2490 A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the fi… Ujcms No fix yet Fix from $1,6002025-03-18 HIGH 8.4 CVE-2024-21760 An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versio… Fortisoar after 7.4.5 Fix from $1,9502025-03-18 MEDIUM 5.4 CVE-2025-2377 A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown funct… Vehicle Management System No fix yet Fix from $1,6002025-03-17 MEDIUM 5.4 CVE-2025-2375 A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unk… Human Metapneumovirus Testing Management System No fix yet Fix from $1,6002025-03-17 MEDIUM 5.4 CVE-2025-2371 A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as problematic. Affected by this issue… Human Metapneumovirus Testing Management System No fix yet Fix from $1,6002025-03-17 MEDIUM 5.4 CVE-2025-2364 A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the f… Vblog Mitigation only Fix from $1,6002025-03-17 MEDIUM 5.4 CVE-2025-2352 A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the… Starsea Mall Mitigation only Fix from $1,6002025-03-16 MEDIUM 6.5 CVE-2025-26924 Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Oh… Mitigation only Fix from $1,6002025-03-15 HIGH 7.2 CVE-2024-54448 The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account … Logicaldoc 9.1+ Fix from $1,9502025-03-14 MEDIUM 5.5 CVE-2024-29409 File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header. Nest No fix yet Fix from $1,6002025-03-14 HIGH 7.3 CVE-2025-1119 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in… Mitigation only Fix from $1,9502025-03-13 CRITICAL 9.0 CVE-2025-27407 graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, … Patch available Fix from $2,3002025-03-12