Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 7.8
CVE-2026-75911

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to e…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-75858

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. Th…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-73073

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgr…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-45117

MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configura…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 10.0
CVE-2026-73343

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-50187

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh …

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-32444

Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-75827

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete deny…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-67919

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginAppli…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.8
CVE-2026-67961

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-38165

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers t…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67960

An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, C…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67926

An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.0
CVE-2026-34789

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Rest…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.4
CVE-2026-19478

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 10.0
CVE-2026-74253

Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer befor…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-59894

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quo…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50772

An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.4
CVE-2026-19980

A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT50…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-19964

A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the compone…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-19958

A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts …

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.2
CVE-2026-17581

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all …

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 5.4
CVE-2026-18385

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19932

A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /e…

No fix yet
Fix from $4,000 2026-08-16
Unclassified CRITICAL 10.0
CVE-2026-73678

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attacke…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 7.2
CVE-2026-73679

ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.8
CVE-2026-46439

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (S…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.1
CVE-2026-19768

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-72819

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users …

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-72676

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via …

No fix yet
Fix from $4,000 2026-08-13