Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 7.3
CVE-2026-37713

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/clas…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-37711

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/acti…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-37712

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/clas…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.8
CVE-2026-8832

The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution i…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.2
CVE-2026-6169

The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plu…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-48962

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob(…

Patch available
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.0
CVE-2026-9568

A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /…

Patch available
Fix from $1,600 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-8855

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-9170

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

Mitigation only
Fix from $2,300 2026-05-26
Websphere Application Server CRITICAL 9.8
CVE-2026-8633

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se…

Fix: after 9.0.5.27
Fix from $2,300 2026-05-26
Babel HIGH 7.8
CVE-2026-44728

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was spe…

Fix: 7.29.4+
Fix from $1,950 2026-05-26
Unclassified HIGH 7.2
CVE-2026-42785

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code throug…

No fix yet
Fix from $1,950 2026-05-26
Unclassified HIGH 7.2
CVE-2026-24937

Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue a…

Mitigation only
Fix from $1,950 2026-05-25
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2018-25357

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PH…

Fix: after 7.0.3
Fix from $2,300 2026-05-23
Unclassified MEDIUM 6.3
CVE-2026-9302

A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function …

Mitigation only
Fix from $1,600 2026-05-23
Unclassified MEDIUM 5.3
CVE-2026-41148

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.…

Patch available
Fix from $1,600 2026-05-22
Unclassified MEDIUM 5.3
CVE-2026-41149

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.…

Patch available
Fix from $1,600 2026-05-22
Unclassified CRITICAL 9.3
CVE-2026-9264

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration thr…

Mitigation only
Fix from $2,300 2026-05-22
Authoritative MEDIUM 6.5
CVE-2026-42396

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

Fix: 4.9.15 / 5.0.5+
Fix from $1,600 2026-05-21
Unclassified MEDIUM 6.8
CVE-2026-39311

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prio…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified CRITICAL 9.5
CVE-2026-8467

Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpol…

Patch available
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.0
CVE-2026-22314

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component en…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-30117

scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpo…

Mitigation only
Fix from $2,300 2026-05-19
Glassfish CRITICAL 9.1
CVE-2026-2586

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can …

Fix: 8.0.2+
Fix from $2,300 2026-05-19
Unclassified HIGH 7.3
CVE-2025-51427

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mi…

Patch available
Fix from $1,950 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-35086

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 2…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz HIGH 8.8
CVE-2026-46586

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vul…

Fix: 24.09.06+
Fix from $1,950 2026-05-19
Ofbiz MEDIUM 6.1
CVE-2026-31379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Unclassified HIGH 7.6
CVE-2026-33233

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified CRITICAL 9.8
CVE-2026-8838

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue serve…

Mitigation only
Fix from $2,300 2026-05-18