Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Protobufjs Cli HIGH 8.7
CVE-2026-44295

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identif…

Fix: 1.2.1 / 2.0.2+
Fix from $1,950 2026-05-13
Protobufjs HIGH 8.1
CVE-2026-44291

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited proto…

Fix: 7.5.6 / 8.0.2+
Fix from $1,950 2026-05-13
Unclassified CRITICAL 10.0
CVE-2026-42288

ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code ex…

Mitigation only
Fix from $2,300 2026-05-12
Filemaker Cloud HIGH 7.2
CVE-2026-43680

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS …

Fix: 2.22.0.5+
Fix from $1,950 2026-05-12
Unclassified MEDIUM 6.5
CVE-2025-15463

The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified CRITICAL 9.4
CVE-2026-44262EPSS 6%

Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and val…

Mitigation only
Fix from $2,300 2026-05-12
Wing Ftp Server HIGH 7.2
CVE-2026-44403

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authent…

Fix: 8.1.3+
Fix from $1,950 2026-05-12
Unclassified HIGH 8.8
CVE-2026-8429

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in t…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.1
CVE-2026-8430

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allo…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.8
CVE-2026-43892

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal fo…

Mitigation only
Fix from $1,950 2026-05-12
Dynamics 365 CRITICAL 9.9
CVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …

Fix: 9.1.45.11+
Fix from $2,300 2026-05-12
Data Formulator HIGH 8.8
CVE-2026-41094

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.

Fix: 0.7+
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31230

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_e…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31231

Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to e…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31233

Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packag…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31236

The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2025-65719

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted H…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified HIGH 8.8
CVE-2026-31225

The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() func…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31228

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluat…

Mitigation only
Fix from $2,300 2026-05-12
Optimate CRITICAL 9.8
CVE-2026-31217

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31220

PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of use…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified HIGH 7.2
CVE-2026-43874

WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the YPTSocket autoEvalCodeOnHTML e…

Patch available
Fix from $1,950 2026-05-11
Unclassified HIGH 7.3
CVE-2026-37630

An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 8.8
CVE-2026-42603

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 7.3
CVE-2026-31251

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC …

Mitigation only
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.7
CVE-2026-31252

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified HIGH 7.3
CVE-2026-31253

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnera…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.1
CVE-2026-42607

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE…

Patch available
Fix from $2,300 2026-05-11
Unclassified HIGH 8.8
CVE-2022-50944

Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious f…

No fix yet
Fix from $1,950 2026-05-10
Unclassified HIGH 8.8
CVE-2021-47938

ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to exec…

No fix yet
Fix from $1,950 2026-05-10