Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified MEDIUM 5.7
CVE-2026-73651

TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Pri…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-73649

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constr…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.8
CVE-2026-73505

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/p…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.4
CVE-2026-67986

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-61962

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-27544

Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73487

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73485

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73486

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.2
CVE-2026-0298

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ …

No fix yet
Fix from $4,000 2026-08-13
I Access Client Solutions HIGH 7.8
CVE-2026-13094

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publi…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73268

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurat…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 10.0
CVE-2026-73299

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.8
CVE-2026-65941

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.1
CVE-2026-73291

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/im…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 10.0
CVE-2026-67282

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code …

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-16051

The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, no…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.5
CVE-2026-73248

calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or …

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.4
CVE-2026-66147

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66148

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.8
CVE-2026-66149

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.8
CVE-2026-66150

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.5
CVE-2026-73233

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.6
CVE-2026-73032

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning maliciou…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-18708

An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be exe…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-73084

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied c…

No fix yet
Fix from $4,000 2026-08-11
Visual Studio Code HIGH 8.8
CVE-2026-70336

Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

Fix: 1.132.1+
Fix from $4,900 2026-08-11
Powershell HIGH 7.8
CVE-2026-70338

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locall…

Fix: 7.4.19.0 / 7.5.10.0+
Fix from $4,900 2026-08-11