Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.0 CVE-2024-23963 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must fi… Ilx F509 Firmware Mitigation only Fix from $1,9502025-01-31 HIGH 7.2 CVE-2024-11600 The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Remote Code Execution in al… Borderless after 1.5.9 Fix from $1,9502025-01-30 HIGH 7.3 CVE-2024-13453 The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions u… Mitigation only Fix from $1,9502025-01-30 MEDIUM 6.1 CVE-2025-0844 A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown fun… Library Card System No fix yet Fix from $1,6002025-01-30 HIGH 7.1 CVE-2024-10001 A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via… Enterprise Server 3.11.6 / 3.12.10+ Fix from $1,9502025-01-29 MEDIUM 6.1 CVE-2025-0806 A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the f… Job Recruitment No fix yet Fix from $1,6002025-01-29 MEDIUM 6.1 CVE-2025-0795 A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the file /todolistjump.jsp. The … Cdg No fix yet Fix from $1,6002025-01-29 MEDIUM 6.1 CVE-2025-0794 A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown functionality of the file /todoDet… Cdg No fix yet Fix from $1,6002025-01-29 MEDIUM 6.1 CVE-2025-0790 A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the file /doneDetail.jsp. The mani… Cdg No fix yet Fix from $1,6002025-01-29 MEDIUM 6.1 CVE-2025-0785 A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing of the file /SysConfig.jsp. Th… Cdg Mitigation only Fix from $1,6002025-01-28 MEDIUM 5.4 CVE-2025-0787 A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the … Cdg Mitigation only Fix from $1,6002025-01-28 HIGH 7.0 CVE-2025-24482 A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and al… No fix yet Fix from $1,9502025-01-28 MEDIUM 6.5 CVE-2024-40673 In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper inp… Android Mitigation only Fix from $1,6002025-01-28 CRITICAL 9.9 CVE-2025-23211 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to e… Recipes 1.5.24+ Fix from $2,3002025-01-28 HIGH 7.8 CVE-2025-24159 A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonom… Ipados 2.3 / 11.3+ Fix from $1,9502025-01-27 MEDIUM 6.1 CVE-2025-0721 A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.ph… Image Gallery Management System No fix yet Fix from $1,6002025-01-27 MEDIUM 5.4 CVE-2025-0710 A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /no… School Management Software No fix yet Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2025-0708 A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/mode… Opencms Mitigation only Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2025-0706 A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this issue … Bootplus after 2020-08-24 Fix from $1,6002025-01-24 HIGH 7.3 CVE-2024-13495 The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary s… Gamipress 7.2.2+ Fix from $1,9502025-01-22 HIGH 7.3 CVE-2024-13499 The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary s… Gamipress 7.2.2+ Fix from $1,9502025-01-22 CRITICAL 9.8 CVE-2024-49747 In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote … Android Mitigation only Fix from $2,3002025-01-21 HIGH 8.8 CVE-2024-43770 In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/… Android Mitigation only Fix from $1,9502025-01-21 HIGH 8.8 CVE-2024-43771 In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/a… Android Mitigation only Fix from $1,9502025-01-21 CRITICAL 9.8 CVE-2024-24421 A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attacker… Magma after 1.8.0 Fix from $2,3002025-01-21 HIGH 8.8 CVE-2024-51941 A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbit… Ambari after 2.7.8 Fix from $1,9502025-01-21 CRITICAL 9.8 CVE-2024-42936 The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT b… Reyee Os No fix yet Fix from $2,3002025-01-21 MEDIUM 5.5 CVE-2024-55504 An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and… Mitigation only Fix from $1,6002025-01-21 MEDIUM 5.4 CVE-2025-0581 A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. This affects an unknown part of the file /chat/… School Management Software No fix yet Fix from $1,6002025-01-20 HIGH 8.1 CVE-2025-23209 KEV Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerab… Craft Cms 4.13.8 / 5.5.8+ Fix from $1,9502025-01-18