Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Flowise HIGH 8.8
CVE-2026-41138

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerabili…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Contour HIGH 8.1
CVE-2026-41246

Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting featur…

Fix: 1.31.6 / 1.32.5+
Fix from $1,950 2026-04-23
Unclassified MEDIUM 6.4
CVE-2026-39087

ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.

Mitigation only
Fix from $1,600 2026-04-23
Unclassified CRITICAL 9.9
CVE-2026-39440

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue aff…

Mitigation only
Fix from $2,300 2026-04-23
H2o CRITICAL 9.8
CVE-2026-3960

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior…

Fix: 3.46.0.10+
Fix from $2,300 2026-04-23
Froxlor CRITICAL 9.1
CVE-2026-41229

Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quo…

Fix: 2.3.6+
Fix from $2,300 2026-04-23
Minetest CRITICAL 10.0
CVE-2026-41196

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can…

Fix: 5.15.2+
Fix from $2,300 2026-04-23
Rclone CRITICAL 9.8
CVE-2026-41179EPSS 9%

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to…

Fix: 1.73.5+
Fix from $2,300 2026-04-23
Kiota HIGH 7.8
CVE-2026-41134

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnera…

Fix: 1.31.1+
Fix from $1,950 2026-04-22
Authoritative CRITICAL 9.8
CVE-2026-33608

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its confi…

Fix: 4.9.14 / 5.0.4+
Fix from $2,300 2026-04-22
Avideo CRITICAL 10.0
CVE-2026-40911

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON messa…

Fix: after 29.0
Fix from $2,300 2026-04-21
Home Assistant Command Line Interface MEDIUM 5.6
CVE-2026-40602

The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted envi…

Fix: 1.0.0+
Fix from $1,600 2026-04-21
Dolibarr Erp\/crm HIGH 8.8
CVE-2026-31018

In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input…

Fix: after 22.0.4
Fix from $1,950 2026-04-21
Spinnaker CRITICAL 9.9
CVE-2026-32613

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to proce…

Fix: 2025.3.2 / 2025.4.2+
Fix from $2,300 2026-04-20
Unclassified CRITICAL 9.8
CVE-2026-39918

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized in…

Patch available
Fix from $2,300 2026-04-20
Sglang CRITICAL 9.8
CVE-2026-5760

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is load…

Fix: 0.5.11+
Fix from $2,300 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6621

A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulatio…

No fix yet
Fix from $1,950 2026-04-20
Nuclei HIGH 7.5
CVE-2026-41282

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targ…

Fix: 3.8.0+
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6603

A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shel…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6594

A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constru…

No fix yet
Fix from $1,950 2026-04-20
Protobufjs CRITICAL 9.8
CVE-2026-41242

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in…

Fix: 7.5.5+
Fix from $2,300 2026-04-18
Firebird CRITICAL 9.9
CVE-2026-40342

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader con…

Fix: 3.0.14 / 4.0.7+
Fix from $2,300 2026-04-17
Siyuan CRITICAL 9.0
CVE-2026-40322

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "…

Fix: 3.6.4+
Fix from $2,300 2026-04-16
Owasp Blt HIGH 8.8
CVE-2026-40316

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 …

Fix: after 2.1
Fix from $1,950 2026-04-15
Weblate HIGH 8.0
CVE-2026-33435

Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which cou…

Fix: 5.17+
Fix from $1,950 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-30993

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnera…

Mitigation only
Fix from $2,300 2026-04-15
Openremote CRITICAL 9.9
CVE-2026-39842

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engin…

Fix: 1.22.0+
Fix from $2,300 2026-04-15
Unclassified MEDIUM 5.4
CVE-2026-1509

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up to, and including, 3.15.1. T…

Mitigation only
Fix from $1,600 2026-04-15
Airflow HIGH 8.1
CVE-2025-54550

The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be ex…

Fix: 3.2.0+
Fix from $1,950 2026-04-15
Podman HIGH 7.8
CVE-2026-33414

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine b…

Fix: 5.8.2+
Fix from $1,950 2026-04-14