Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Langflow CRITICAL 9.9
CVE-2026-7873

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials,…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Db2 CRITICAL 9.8
CVE-2026-10109

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Fix: after 12.1.4
Fix from $2,300 2026-06-30
Langflow CRITICAL 10.0
CVE-2026-10134

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat…

Fix: after 1.9.3
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-58138EPSS 7%

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitra…

Patch available
Fix from $2,300 2026-06-30
Unclassified MEDIUM 5.4
CVE-2026-48192

A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), Mendix Studio Pro 10.13 (All v…

Mitigation only
Fix from $1,600 2026-06-30
Llama Factory HIGH 8.8
CVE-2026-58116

LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code b…

Fix: after 0.9.5
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.1
CVE-2026-37637

An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component

No fix yet
Fix from $2,300 2026-06-29
Snowflake Cli HIGH 8.8
CVE-2026-13749

Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code executi…

Fix: 3.19.0+
Fix from $1,950 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13500

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFi…

Mitigation only
Fix from $1,950 2026-06-28
Kestra CRITICAL 10.0
CVE-2026-53576

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/…

Fix: 1.0.45 / 1.3.21+
Fix from $2,300 2026-06-26
Unclassified HIGH 8.6
CVE-2026-55441

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.6
CVE-2026-33646

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template eng…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified HIGH 8.5
CVE-2026-57315

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.1
CVE-2025-7958

A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the…

Mitigation only
Fix from $1,950 2026-06-26
Revive Adserver HIGH 8.8
CVE-2026-50741

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sen…

Fix: 6.0.8+
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.4
CVE-2026-55413

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts…

Mitigation only
Fix from $2,300 2026-06-25
Vim HIGH 7.8
CVE-2026-57456

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy…

Fix: 9.2.0699+
Fix from $1,950 2026-06-25
Vim HIGH 7.8
CVE-2026-55895

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the ne…

Fix: 9.2.0663+
Fix from $1,950 2026-06-25
Unclassified HIGH 8.5
CVE-2026-56049

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified CRITICAL 9.9
CVE-2026-54823

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

Mitigation only
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.0
CVE-2026-55570

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, descri…

Mitigation only
Fix from $2,300 2026-06-24
Docling HIGH 8.2
CVE-2026-44016

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0…

Fix: 2.91.0+
Fix from $1,950 2026-06-24
Unclassified HIGH 8.8
CVE-2026-12242

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' at…

Mitigation only
Fix from $1,950 2026-06-24
Crawl4ai CRITICAL 10.0
CVE-2026-53753

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature us…

Fix: 0.8.7+
Fix from $2,300 2026-06-23
Langflow CRITICAL 9.6
CVE-2026-48519

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code)…

Fix: 1.9.2+
Fix from $2,300 2026-06-23
Unclassified HIGH 8.8
CVE-2026-44959

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an u…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified HIGH 8.8
CVE-2026-34916

A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified CRITICAL 9.8
CVE-2026-12866

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by su…

Mitigation only
Fix from $2,300 2026-06-23
Vllm HIGH 7.5
CVE-2026-41523

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation functi…

Fix: 0.22.0+
Fix from $1,950 2026-06-22
Unclassified HIGH 8.1
CVE-2026-55388

piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename optio…

Mitigation only
Fix from $1,950 2026-06-22