Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 8.8
CVE-2021-47939

Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitr…

No fix yet
Fix from $1,950 2026-05-10
Sentry HIGH 8.8
CVE-2021-47935

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious…

No fix yet
Fix from $1,950 2026-05-10
Unclassified HIGH 7.8
CVE-2026-42301

pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the su…

Mitigation only
Fix from $1,950 2026-05-09
Postiz CRITICAL 9.8
CVE-2026-42298

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflo…

Fix: 2.21.7+
Fix from $2,300 2026-05-08
Ray HIGH 8.8
CVE-2026-41486

Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ra…

Patch available
Fix from $1,950 2026-05-08
Unclassified HIGH 8.8
CVE-2026-29202

Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already aut…

Mitigation only
Fix from $1,950 2026-05-08
Praisonai HIGH 8.4
CVE-2026-44334

PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISO…

Fix: 4.6.32+
Fix from $1,950 2026-05-08
Praisonai CRITICAL 9.6
CVE-2026-44336

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou…

Fix: 4.6.34+
Fix from $2,300 2026-05-08
Math Codegen CRITICAL 9.8
CVE-2026-41507

math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim i…

Fix: 0.4.3+
Fix from $2,300 2026-05-08
0din Scanner CRITICAL 9.9
CVE-2026-41512

ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerab…

Fix: 1.4.1+
Fix from $2,300 2026-05-08
Cloudstack HIGH 8.8
CVE-2026-25077

Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hyp…

Fix: 4.20.3.0 / 4.22.0.1+
Fix from $1,950 2026-05-08
Unclassified CRITICAL 9.8
CVE-2025-67887

1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and exec…

Mitigation only
Fix from $2,300 2026-05-08
Yeti HIGH 7.3
CVE-2024-46507

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to …

Fix: 2.1.12+
Fix from $1,950 2026-05-08
Electerm CRITICAL 9.6
CVE-2026-43944

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerabl…

Fix: 3.8.15+
Fix from $2,300 2026-05-08
Litellm HIGH 8.8
CVE-2026-42203

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts…

Fix: 1.83.7+
Fix from $1,950 2026-05-08
Nuclei MEDIUM 5.3
CVE-2026-41645

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expressio…

Fix: 3.8.0+
Fix from $1,600 2026-05-08
Openlearnx CRITICAL 10.0
CVE-2026-41900

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was…

Patch available
Fix from $2,300 2026-05-08
Gitpython HIGH 7.8
CVE-2026-44244

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's …

Fix: 3.1.49+
Fix from $1,950 2026-05-07
Notepad Next HIGH 7.8
CVE-2026-42214

Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpol…

Fix: 0.14+
Fix from $1,950 2026-05-07
Unclassified CRITICAL 9.8
CVE-2026-36458

ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injec…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.8
CVE-2025-63706

NPM package next-npm-version1.0.1 is vulnerable to Command injection.

Mitigation only
Fix from $2,300 2026-05-07
Firefox CRITICAL 9.8
CVE-2026-8094

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

Fix: 140.10.2+
Fix from $2,300 2026-05-07
Virtual Storage One Block CRITICAL 9.8
CVE-2025-1978

Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G3…

Mitigation only
Fix from $2,300 2026-05-07
Mathjs HIGH 8.8
CVE-2026-41139

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed v…

Fix: 15.2.0+
Fix from $1,950 2026-05-07
Cloud Native Environment Command Line Interface MEDIUM 6.6
CVE-2026-35255

Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is af…

Mitigation only
Fix from $1,600 2026-05-06
Unclassified HIGH 8.8
CVE-2026-7841

A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissi…

Mitigation only
Fix from $1,950 2026-05-06
Erpnext CRITICAL 9.8
CVE-2026-38431

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates ca…

Fix: after 15.103.1
Fix from $2,300 2026-05-05
Erpnext HIGH 8.8
CVE-2023-54345

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role …

No fix yet
Fix from $1,950 2026-05-05
Nginx Ui CRITICAL 9.8
CVE-2026-42238

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) tha…

Fix: 2.3.8+
Fix from $2,300 2026-05-04
N8n HIGH 8.8
CVE-2026-42234

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create o…

Fix: 1.123.32 / 2.17.4+
Fix from $1,950 2026-05-04