Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Edge Chromium CRITICAL 9.8
CVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 148.0.3967.70+
Fix from $2,300 2026-05-18
Unclassified CRITICAL 10.0
CVE-2026-45829EPSS 12%

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run…

Mitigation only
Fix from $2,300 2026-05-18
Unclassified HIGH 7.7
CVE-2026-6902

A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potenti…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified CRITICAL 9.8
CVE-2018-25320

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands …

Mitigation only
Fix from $2,300 2026-05-17
Unclassified CRITICAL 9.8
CVE-2021-47952

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing ma…

Mitigation only
Fix from $2,300 2026-05-16
Unclassified MEDIUM 6.3
CVE-2025-67031

ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant pro…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified HIGH 8.8
CVE-2021-47964

Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading mali…

No fix yet
Fix from $1,950 2026-05-15
Unclassified CRITICAL 9.8
CVE-2026-44717

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mat…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.1
CVE-2026-41258

OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateC…

Mitigation only
Fix from $2,300 2026-05-15
Flink HIGH 8.1
CVE-2026-35194

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr…

Fix: 1.20.4 / 2.0.2+
Fix from $1,950 2026-05-15
Unclassified MEDIUM 6.5
CVE-2026-39052

Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String,…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified CRITICAL 9.1
CVE-2026-8634

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repo…

Patch available
Fix from $2,300 2026-05-14
Chrome MEDIUM 5.4
CVE-2026-8539

Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (U…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Unclassified CRITICAL 9.4
CVE-2026-44670

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTM…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified HIGH 8.3
CVE-2026-44586

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metada…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 8.8
CVE-2025-15024

Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems …

Mitigation only
Fix from $1,950 2026-05-14
Diffusers HIGH 8.8
CVE-2026-44827

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_…

Fix: 0.38.0+
Fix from $1,950 2026-05-14
Diffusers HIGH 8.8
CVE-2026-44513

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows …

Fix: 0.38.0+
Fix from $1,950 2026-05-14
Unclassified CRITICAL 9.1
CVE-2026-42555

Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.6
CVE-2026-44482

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified MEDIUM 6.3
CVE-2025-69443

Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the us…

Mitigation only
Fix from $1,600 2026-05-14
GitLab MEDIUM 5.4
CVE-2025-12669

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that c…

Fix: 18.9.7 / 18.10.6+
Fix from $1,600 2026-05-14
Unclassified CRITICAL 9.1
CVE-2026-45714

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple m…

Mitigation only
Fix from $2,300 2026-05-13
Unclassified HIGH 7.2
CVE-2026-45708

CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. …

Mitigation only
Fix from $1,950 2026-05-13
Unclassified CRITICAL 9.1
CVE-2026-44377

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple m…

Patch available
Fix from $2,300 2026-05-13
Prisma Browser HIGH 7.8
CVE-2026-0236

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing…

Fix: 146.10.7.154+
Fix from $1,950 2026-05-13
Vm2 CRITICAL 10.0
CVE-2026-44005

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and…

Fix: 3.11.0+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 10.0
CVE-2026-44006

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary…

Fix: 3.11.0+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 10.0
CVE-2026-43997

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Objec…

Fix: 3.11.0+
Fix from $2,300 2026-05-13
Protobufjs HIGH 8.8
CVE-2026-44293

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conve…

Fix: 7.5.6 / 8.0.2+
Fix from $1,950 2026-05-13