Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Unclassified HIGH 7.3
CVE-2026-5678

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cst…

Mitigation only
Fix from $1,950 2026-04-06
Bentoml HIGH 7.8
CVE-2026-35043

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path…

Fix: 1.4.38+
Fix from $1,950 2026-04-06
Aperisolve CRITICAL 9.8
CVE-2026-34977

Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user can specify an optional passw…

Fix: after 3.2.0
Fix from $2,300 2026-04-06
Vim HIGH 8.2
CVE-2026-34982

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution wh…

Fix: 9.2.0276+
Fix from $1,950 2026-04-06
Kubeai HIGH 8.8
CVE-2026-34940

KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/modelcontroller/engine_ollama…

Fix: 0.23.2+
Fix from $1,950 2026-04-06
Dcmtk CRITICAL 9.8
CVE-2026-5663

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/a…

Fix: after 3.7.0
Fix from $2,300 2026-04-06
520w Firmware MEDIUM 6.8
CVE-2026-31067

A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7.7-180627 allows attackers to…

No fix yet
Fix from $1,600 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5621

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.t…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5619

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of t…

Mitigation only
Fix from $1,600 2026-04-06
Unclassified MEDIUM 5.3
CVE-2026-5603

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/…

Patch available
Fix from $1,600 2026-04-05
Unclassified MEDIUM 5.3
CVE-2026-5602

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_…

Patch available
Fix from $1,600 2026-04-05
Ac10 Firmware HIGH 8.8
CVE-2026-5547

A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such mani…

Mitigation only
Fix from $1,950 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5532

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file s…

Mitigation only
Fix from $1,600 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5528

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Inter…

Mitigation only
Fix from $1,600 2026-04-05
Electron HIGH 7.8
CVE-2026-34779

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and…

Fix: 38.8.6 / 39.8.1+
Fix from $1,950 2026-04-04
Praisonai CRITICAL 10.0
CVE-2026-34955

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.r…

Fix: 4.5.97+
Fix from $2,300 2026-04-04
Praisonaiagents CRITICAL 9.8
CVE-2026-34937

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-c…

Fix: 1.5.90+
Fix from $2,300 2026-04-03
Praisonai CRITICAL 9.8
CVE-2026-34935

PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and…

Fix: 4.5.69+
Fix from $2,300 2026-04-03
Icx35 Hwc Firmware CRITICAL 9.8
CVE-2017-20236

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows…

Fix: 1.3+
Fix from $2,300 2026-04-03
Ragflow HIGH 8.8
CVE-2026-28797

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerab…

Fix: after 0.24.0
Fix from $1,950 2026-04-03
Athena Odbc HIGH 7.8
CVE-2026-5485

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to…

Fix: 2.0.5.1+
Fix from $1,950 2026-04-03
Budibase CRITICAL 9.0
CVE-2026-35216EPSS 12%

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Bud…

Fix: 3.33.4+
Fix from $2,300 2026-04-03
Budibase HIGH 8.8
CVE-2026-25044

Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync withou…

Fix: 3.33.4+
Fix from $1,950 2026-04-03
Fastmcp HIGH 7.8
CVE-2025-64340

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can c…

Fix: 3.2.0+
Fix from $1,950 2026-04-03
Tew 657brm Firmware HIGH 8.8
CVE-2026-5353

A vulnerability was detected in Trendnet TEW-657BRM 1.00.1. Affected is the function ping_test of the file /setup.cgi. Performing a manipulation of t…

No fix yet
Fix from $1,950 2026-04-02
Tew 657brm Firmware HIGH 8.8
CVE-2026-5354

A flaw has been found in Trendnet TEW-657BRM 1.00.1. Affected by this vulnerability is the function vpn_connect of the file /setup.cgi. Executing a m…

No fix yet
Fix from $1,950 2026-04-02
Tew 657brm Firmware HIGH 8.8
CVE-2026-5355

A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the file /setup.cgi. The manipulatio…

No fix yet
Fix from $1,950 2026-04-02
Tew 657brm Firmware HIGH 8.8
CVE-2026-5352

A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /setup.cgi. Such manipulation of…

No fix yet
Fix from $1,950 2026-04-02
Tew 657brm Firmware HIGH 8.8
CVE-2026-5351

A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setup.cgi. This manipulation of t…

No fix yet
Fix from $1,950 2026-04-02
Firewall Community HIGH 8.8
CVE-2026-34796

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.c…

Fix: after 3.3.25
Fix from $1,950 2026-04-02