Vulnerability index

Browse CVEs

6,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.2 CVE-2025-0530 A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the fil… Job Recruitment No fix yet Fix from $1,9502025-01-17 CRITICAL 9.8 CVE-2025-22905 RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp. Re11s Firmware No fix yet Fix from $2,3002025-01-16 CRITICAL 9.8 CVE-2025-22906 RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN. Re11s Firmware No fix yet Fix from $2,3002025-01-16 MEDIUM 5.4 CVE-2024-10970 The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc… Motors Car Dealer\, Classifieds \& Listing 1.4.44+ Fix from $1,6002025-01-16 MEDIUM 6.1 CVE-2025-0485 A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been classified as problematic. Affected is an unknown function of the file /fladmi… Native Php Cms No fix yet Fix from $1,6002025-01-15 HIGH 7.8 CVE-2024-27856 The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonom… Safari 1.2 / 10.5+ Fix from $1,9502025-01-15 CRITICAL 9.8 CVE-2025-22968 An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions Dwr M972v Firmware No fix yet Fix from $2,3002025-01-15 CRITICAL 9.8 CVE-2025-23061EPSS 7% Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because… Mongoose 6.13.6 / 7.8.4+ Fix from $2,3002025-01-15 HIGH 7.4 CVE-2024-42911 ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vulnerability. Mitigation only Fix from $1,9502025-01-14 CRITICAL 9.0 CVE-2024-49375 Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciousl… Mitigation only Fix from $2,3002025-01-14 HIGH 7.2 CVE-2025-23051 An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful… Mitigation only Fix from $1,9502025-01-14 HIGH 8.8 CVE-2025-21292 Windows Search Service Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.6775 / 10.0.19044.5371+ Fix from $1,9502025-01-14 HIGH 7.8 CVE-2025-21187 Microsoft Power Automate Remote Code Execution Vulnerability Power Automate For Desktop 2.46.184.25013 / 2.47.126.25010+ Fix from $1,9502025-01-14 HIGH 8.7 CVE-2024-53561 A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary code via a crafted … Mitigation only Fix from $1,9502025-01-14 MEDIUM 6.5 CVE-2025-0060 SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sen… Businessobjects Business Intelligence Platform Patch available Fix from $1,6002025-01-14 MEDIUM 6.5 CVE-2024-54999 MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module. Monica No fix yet Fix from $1,6002025-01-13 MEDIUM 6.5 CVE-2024-57487 In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload… Online Car Rental System Mitigation only Fix from $1,6002025-01-13 MEDIUM 5.4 CVE-2025-0400 A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /ad… Starsea Mall Mitigation only Fix from $1,6002025-01-12 CRITICAL 9.8 CVE-2024-9132 The administrator is able to configure an insecure captive portal script Ng Firewall after 17.1.1 Fix from $2,3002025-01-10 MEDIUM 5.4 CVE-2024-54997 MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit. Monica No fix yet Fix from $1,6002025-01-10 HIGH 8.8 CVE-2024-54996 MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /p… Monica No fix yet Fix from $1,9502025-01-10 CRITICAL 9.1 CVE-2025-22152 Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple component… Mitigation only Fix from $2,3002025-01-10 CRITICAL 9.8 CVE-2023-28354 An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying kno… Mitigation only Fix from $2,3002025-01-09 CRITICAL 9.8 CVE-2024-54724 PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion. Mitigation only Fix from $2,3002025-01-09 MEDIUM 5.4 CVE-2025-0348 A vulnerability was found in CampCodes DepEd Equipment Inventory System 1.0. It has been rated as problematic. This issue affects some unknown proces… Deped Equipment Inventory System No fix yet Fix from $1,6002025-01-09 MEDIUM 5.4 CVE-2025-0342 A vulnerability, which was classified as problematic, was found in CampCodes Computer Laboratory Management System 1.0. This affects an unknown part … Computer Laboratory Management System No fix yet Fix from $1,6002025-01-09 MEDIUM 6.1 CVE-2025-0339 A vulnerability classified as problematic has been found in code-projects Online Bike Rental 1.0. Affected is an unknown function of the file /vehica… Online Bike Rental System No fix yet Fix from $1,6002025-01-09 MEDIUM 5.4 CVE-2024-13213 A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHouseP… Houserent Mitigation only Fix from $1,6002025-01-09 MEDIUM 5.4 CVE-2024-13209 A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=st… Redaxo No fix yet Fix from $1,6002025-01-09 MEDIUM 5.4 CVE-2024-13202 A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the function modifiyArticle of the file… Springboot Blog No fix yet Fix from $1,6002025-01-09