Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Protobufjs Cli HIGH 8.2
CVE-2026-54271

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-…

Fix: 1.3.2 / 2.5.0+
Fix from $1,950 2026-06-22
Fusion CRITICAL 9.6
CVE-2026-10789

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability…

Fix: 2703.1.20+
Fix from $2,300 2026-06-22
I CRITICAL 9.8
CVE-2026-9072

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i…

Fix: after 7.6
Fix from $2,300 2026-06-22
I HIGH 8.8
CVE-2026-8858

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the We…

Fix: after 7.6
Fix from $1,950 2026-06-22
Angular Language Service HIGH 8.8
CVE-2026-50178

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS …

Fix: 21.2.4+
Fix from $1,950 2026-06-22
Angular Language Service HIGH 8.8
CVE-2026-49241

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Lan…

Fix: 21.2.4+
Fix from $1,950 2026-06-22
Misp HIGH 7.2
CVE-2026-56446

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can inc…

Fix: 2.5.42+
Fix from $1,950 2026-06-22
Langflow CRITICAL 10.0
CVE-2026-10561

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass tha…

Fix: after 1.9.3
Fix from $2,300 2026-06-22
Langflow HIGH 7.8
CVE-2026-12822

A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipula…

Fix: 1.9.3+
Fix from $1,950 2026-06-22
Unclassified HIGH 7.2
CVE-2026-56382

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::acti…

Mitigation only
Fix from $1,950 2026-06-21
Prefect CRITICAL 9.9
CVE-2026-5366

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class.…

Mitigation only
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.8
CVE-2024-58351

Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the fro…

Mitigation only
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.8
CVE-2022-50972

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands thro…

Mitigation only
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.1
CVE-2026-36418

JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSel…

Mitigation only
Fix from $2,300 2026-06-17
Python Statemachine CRITICAL 9.8
CVE-2026-47103

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by sup…

Fix: 3.2.0+
Fix from $2,300 2026-06-17
Unclassified HIGH 7.5
CVE-2026-54816

Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affect…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.5
CVE-2026-49113

Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40783

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 10.0
CVE-2026-25470

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Cod…

Mitigation only
Fix from $2,300 2026-06-17
Mysql Shell CRITICAL 9.9
CVE-2026-46850

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. …

Mitigation only
Fix from $2,300 2026-06-17
Peoplesoft Enterprise Campus Software Campus Community HIGH 8.1
CVE-2026-46851

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is af…

Mitigation only
Fix from $1,950 2026-06-17
Nemo HIGH 7.8
CVE-2026-24155

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execut…

Fix: 2.7.3+
Fix from $1,950 2026-06-16
Unclassified CRITICAL 9.9
CVE-2026-49774

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects R…

Mitigation only
Fix from $2,300 2026-06-16
Unclassified HIGH 8.8
CVE-2026-48017

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName param…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified CRITICAL 10.0
CVE-2026-48836

Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 8.5
CVE-2026-48124

Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook com…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified CRITICAL 9.1
CVE-2026-39465

Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50880

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted req…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50871

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to …

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50872

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensit…

Mitigation only
Fix from $2,300 2026-06-15