Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.8 CVE-2019-8900EPSS 69% A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting t… Securerom Mitigation only Fix from $1,6002025-02-21 MEDIUM 6.5 CVE-2025-25507 There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command executi… Ac6 Firmware No fix yet Fix from $1,6002025-02-21 CRITICAL 9.8 CVE-2025-26014 A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter. Loggrove No fix yet Fix from $2,3002025-02-21 HIGH 7.2 CVE-2024-13900 The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes… Head\, Footer\, And Post Injections 3.3.1+ Fix from $1,9502025-02-21 CRITICAL 9.8 CVE-2025-25675 Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput pa… Ac10 Firmware Mitigation only Fix from $2,3002025-02-20 CRITICAL 9.8 CVE-2024-54756 A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via suppl… Mitigation only Fix from $2,3002025-02-20 CRITICAL 9.8 CVE-2025-24893 KEVEPSS 100% XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code … Xwiki 15.10.11 / 16.4.1+ Fix from $2,3002025-02-20 HIGH 7.8 CVE-2025-0161 IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restri… Security Verify Access after 10.0.0.9 Fix from $1,9502025-02-20 MEDIUM 6.5 CVE-2023-51324 PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnera… Shared Asset Booking System No fix yet Fix from $1,6002025-02-20 MEDIUM 6.5 CVE-2023-51331 PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerab… Cleaning Business Software No fix yet Fix from $1,6002025-02-20 MEDIUM 6.5 CVE-2023-51317 PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, … Restaurant Booking System No fix yet Fix from $1,6002025-02-20 MEDIUM 5.3 CVE-2023-51320 PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnera… Night Club Booking Software No fix yet Fix from $1,6002025-02-20 CRITICAL 9.8 CVE-2024-57401 SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password func… Mitigation only Fix from $2,3002025-02-20 HIGH 8.8 CVE-2023-51313 PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerabi… Restaurant Booking System No fix yet Fix from $1,9502025-02-20 CRITICAL 9.8 CVE-2024-13792 The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… Woocommerce Food 3.3.3+ Fix from $2,3002025-02-20 MEDIUM 5.3 CVE-2025-27218EPSS 65% Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization. Mitigation only Fix from $1,6002025-02-20 HIGH 7.8 CVE-2025-25943 Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component lo… Bento4 No fix yet Fix from $1,9502025-02-19 HIGH 7.3 CVE-2025-25944 Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_Rtp… Bento4 No fix yet Fix from $1,9502025-02-19 MEDIUM 6.6 CVE-2025-1465 A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the compone… Lmxcms No fix yet Fix from $1,6002025-02-19 CRITICAL 9.8 CVE-2025-25467 Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted … Mitigation only Fix from $2,3002025-02-18 MEDIUM 6.3 CVE-2024-13689 The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the… Mitigation only Fix from $1,6002025-02-18 CRITICAL 9.8 CVE-2024-13797 The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to… Pressmart 1.2.17+ Fix from $2,3002025-02-18 MEDIUM 5.4 CVE-2025-1392EPSS 8% A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of … Dir 816 Firmware Mitigation only Fix from $1,6002025-02-17 CRITICAL 9.8 CVE-2025-1302EPSS 10% Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can… Patch available Fix from $2,3002025-02-15 CRITICAL 9.8 CVE-2024-13346 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… Avada 7.11.14+ Fix from $2,3002025-02-13 CRITICAL 9.8 CVE-2024-13345 The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to t… Avada Builder 3.11.14+ Fix from $2,3002025-02-13 MEDIUM 5.4 CVE-2025-1213 A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the fi… Maxair No fix yet Fix from $1,6002025-02-12 MEDIUM 5.4 CVE-2025-1209 A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_… Wazifa System No fix yet Fix from $1,6002025-02-12 MEDIUM 5.4 CVE-2025-1208 A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the fil… Wazifa System No fix yet Fix from $1,6002025-02-12 MEDIUM 5.4 CVE-2025-1195 A vulnerability, which was classified as problematic, has been found in code-projects Real Estate Property Management System 1.0. This issue affects … Real Estate Property Management System No fix yet Fix from $1,6002025-02-12