Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2025-26260 Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript… Plenti 0.7.17+ Fix from $1,9502025-03-12 MEDIUM 6.1 CVE-2025-2214 A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/mo… Microweber No fix yet Fix from $1,6002025-03-12 MEDIUM 6.1 CVE-2025-2212 A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an unknown part of the file /RgS… Cbw383g2n Firmware after 2025-03-01 Fix from $1,6002025-03-11 HIGH 7.7 CVE-2025-25680 LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The … Ptz Dual Band Camera Firmware No fix yet Fix from $1,9502025-03-11 MEDIUM 6.1 CVE-2025-2196 A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /adm… Mrcms No fix yet Fix from $1,6002025-03-11 MEDIUM 6.1 CVE-2025-2194 A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the c… Mrcms No fix yet Fix from $1,6002025-03-11 MEDIUM 6.1 CVE-2025-2195 A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of… Mrcms No fix yet Fix from $1,6002025-03-11 CRITICAL 9.8 CVE-2025-1550 The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras arch… Keras 3.8.0+ Fix from $2,3002025-03-11 HIGH 7.3 CVE-2025-2169 The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an… Mitigation only Fix from $1,9502025-03-11 CRITICAL 10.0 CVE-2025-26936 Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework allows Code Injection.This issue… Mitigation only Fix from $2,3002025-03-10 CRITICAL 9.8 CVE-2025-1497 A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attack… Plotai 0.0.7+ Fix from $2,3002025-03-10 MEDIUM 5.4 CVE-2025-2130 A vulnerability was found in OpenXE up to 1.12. It has been declared as problematic. This vulnerability affects unknown code of the component Ticket … Openxe after 1.12 Fix from $1,6002025-03-09 MEDIUM 6.1 CVE-2025-2127 A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the … Jux Real Estate No fix yet Fix from $1,6002025-03-09 MEDIUM 6.1 CVE-2025-2123 A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is the function get_var of the fi… Geshi after 1.0.9.1 Fix from $1,6002025-03-09 MEDIUM 6.3 CVE-2024-13895 The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is du… Code Snippets Cpt after 2.1.0 Fix from $1,6002025-03-08 HIGH 7.2 CVE-2024-13890 The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP… Allow Php Execute Mitigation only Fix from $1,9502025-03-08 CRITICAL 9.8 CVE-2024-42733 An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script to the UNC path input Tornado after 2.9.7 Fix from $2,3002025-03-07 MEDIUM 5.5 CVE-2024-50405 An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If … Qts Mitigation only Fix from $1,6002025-03-07 HIGH 7.1 CVE-2024-53693 An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If … Qts Mitigation only Fix from $1,9502025-03-07 MEDIUM 6.1 CVE-2025-2087 A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the… Starsea Mall No fix yet Fix from $1,6002025-03-07 MEDIUM 6.1 CVE-2025-2086 A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown code of the file /admin/indexCo… Starsea Mall No fix yet Fix from $1,6002025-03-07 MEDIUM 6.1 CVE-2025-2085 A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of the file /admin/carousels/sav… Starsea Mall No fix yet Fix from $1,6002025-03-07 MEDIUM 6.1 CVE-2025-2084 A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as problematic. Affected is an un… Human Metapneumovirus No fix yet Fix from $1,6002025-03-07 MEDIUM 6.1 CVE-2025-2061 A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unkn… Online Ticket Reservation System No fix yet Fix from $1,6002025-03-07 MEDIUM 5.4 CVE-2024-13902 A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown part of the component Edit a … Student Manage No fix yet Fix from $1,6002025-03-06 CRITICAL 9.8 CVE-2025-25362 A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload … Mitigation only Fix from $2,3002025-03-05 MEDIUM 6.5 CVE-2024-13815 The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the s… Mitigation only Fix from $1,6002025-03-05 CRITICAL 9.8 CVE-2025-27678 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001. Vasion Print 20.0.1923 / 22.0.843+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27657 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008. Vasion Print 20.0.1923 / 22.0.843+ Fix from $2,3002025-03-05 MEDIUM 5.4 CVE-2025-1955 A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is s… Online Class And Exam Scheduling System No fix yet Fix from $1,6002025-03-04