Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified CRITICAL 9.0
CVE-2026-32999

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitr…

Mitigation only
Fix from $2,300 2026-05-28
Claude Code Cache Fix HIGH 7.8
CVE-2026-45136

claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) int…

Fix: 3.5.2+
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-44888

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplie…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-44887

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitra…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified MEDIUM 6.3
CVE-2026-42879

FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability e…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.5
CVE-2026-45719

Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request bo…

Mitigation only
Fix from $1,600 2026-05-27
Bentoml HIGH 8.8
CVE-2026-44346

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yam…

Fix: 1.4.39+
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-37713

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/clas…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-37711

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/acti…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-37712

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/clas…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.8
CVE-2026-8832

The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution i…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.2
CVE-2026-6169

The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plu…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob(…

Patch available
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.0
CVE-2026-9568

A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /…

Patch available
Fix from $1,600 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-8855

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-9170

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

Mitigation only
Fix from $2,300 2026-05-26
Websphere Application Server CRITICAL 9.8
CVE-2026-8633

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se…

Fix: after 9.0.5.27
Fix from $2,300 2026-05-26
Babel HIGH 7.8
CVE-2026-44728

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was spe…

Fix: 7.29.4+
Fix from $1,950 2026-05-26
Unclassified HIGH 7.2
CVE-2026-42785

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code throug…

No fix yet
Fix from $1,950 2026-05-26
Unclassified HIGH 7.2
CVE-2026-24937

Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue a…

Mitigation only
Fix from $1,950 2026-05-25
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2018-25357

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PH…

Fix: after 7.0.3
Fix from $2,300 2026-05-23
Unclassified MEDIUM 6.3
CVE-2026-9302

A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function …

Mitigation only
Fix from $1,600 2026-05-23
Unclassified MEDIUM 5.3
CVE-2026-41148

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.…

Patch available
Fix from $1,600 2026-05-22
Unclassified MEDIUM 5.3
CVE-2026-41149

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.…

Patch available
Fix from $1,600 2026-05-22
Unclassified CRITICAL 9.3
CVE-2026-9264

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration thr…

Mitigation only
Fix from $2,300 2026-05-22
Authoritative MEDIUM 6.5
CVE-2026-42396

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

Fix: 4.9.15 / 5.0.5+
Fix from $1,600 2026-05-21
Unclassified MEDIUM 6.8
CVE-2026-39311

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prio…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified CRITICAL 9.5
CVE-2026-8467

Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpol…

Patch available
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.0
CVE-2026-22314

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component en…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-30117

scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpo…

Mitigation only
Fix from $2,300 2026-05-19