Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Chrome MEDIUM 5.4
CVE-2026-11157

Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension t…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome HIGH 8.8
CVE-2026-10928

Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Ch…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10904

Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Unclassified HIGH 8.2
CVE-2026-41249

CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.ym…

Patch available
Fix from $1,950 2026-06-04
Unclassified MEDIUM 5.5
CVE-2026-10688

A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_b…

Mitigation only
Fix from $1,600 2026-06-02
Unclassified HIGH 8.8
CVE-2026-49143

BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjace…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.8
CVE-2026-1829

The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via th…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-47117

OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used …

Patch available
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-25879

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM…

Mitigation only
Fix from $2,300 2026-06-01
Websphere Application Server CRITICAL 9.0
CVE-2026-9311

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Unclassified CRITICAL 10.0
CVE-2026-45131

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes …

Patch available
Fix from $2,300 2026-06-01
Unclassified CRITICAL 10.0
CVE-2026-45132

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) expose…

Patch available
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.4
CVE-2026-8931

A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.

Mitigation only
Fix from $2,300 2026-06-01
Activemq HIGH 8.1
CVE-2026-42588

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Activemq HIGH 8.8
CVE-2026-45505

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10175

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of …

Mitigation only
Fix from $1,600 2026-05-31
Unclassified CRITICAL 9.8
CVE-2026-45697

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (wi…

Patch available
Fix from $2,300 2026-05-29
Unclassified MEDIUM 6.3
CVE-2026-44287

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks…

Mitigation only
Fix from $1,600 2026-05-29
Mermaid MEDIUM 5.3
CVE-2026-41159

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's defau…

Fix: 10.9.6 / 11.15.0+
Fix from $1,600 2026-05-29
Unclassified HIGH 7.8
CVE-2026-45555

Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagno…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified HIGH 8.3
CVE-2026-44698

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android,…

Mitigation only
Fix from $1,950 2026-05-29
Chrome HIGH 8.8
CVE-2026-9976

Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML p…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9938

Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Unclassified CRITICAL 9.6
CVE-2026-45311

CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalR…

Mitigation only
Fix from $2,300 2026-05-28
Electerm HIGH 7.8
CVE-2026-45353

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.

Fix: 3.9.0+
Fix from $1,950 2026-05-28
Unclassified CRITICAL 9.6
CVE-2026-45374

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure de…

Mitigation only
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.4
CVE-2026-45058

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code ex…

Mitigation only
Fix from $2,300 2026-05-28
Sandboxjs CRITICAL 10.0
CVE-2026-43898

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover th…

Fix: 0.9.6+
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.3
CVE-2026-45261

GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in t…

Mitigation only
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.3
CVE-2026-44672

mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3…

Mitigation only
Fix from $2,300 2026-05-28