Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Fuel Cms HIGH 8.8
CVE-2026-30460

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.

No fix yet
Fix from $1,950 2026-04-07
Unclassified CRITICAL 9.8
CVE-2024-36057

Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $…

Mitigation only
Fix from $2,300 2026-04-07
Dolibarr Erp\/crm HIGH 7.2
CVE-2026-22666EPSS 16%

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails…

Fix: 23.0.2+
Fix from $1,950 2026-04-07
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Dye CRITICAL 9.8
CVE-2026-35197

dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbit…

Mitigation only
Fix from $2,300 2026-04-06
Forceworkbench CRITICAL 9.8
CVE-2026-35178

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0…

Fix: 65.0.0+
Fix from $2,300 2026-04-06
Kedro CRITICAL 9.8
CVE-2026-35171

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN…

Fix: 1.3.0+
Fix from $2,300 2026-04-06
Glpi HIGH 7.2
CVE-2026-26026EPSS 11%

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulne…

Fix: 11.0.6+
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5631

A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/s…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5594

A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.p…

No fix yet
Fix from $1,600 2026-04-05
Agenticseek CRITICAL 9.8
CVE-2026-5584

A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py…

Mitigation only
Fix from $2,300 2026-04-05
Ui CRITICAL 9.8
CVE-2026-5562

A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutio…

Fix: after 0.7.2
Fix from $2,300 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5556

A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function discoverAndLoadExtensions of the…

Mitigation only
Fix from $1,600 2026-04-05
Unclassified MEDIUM 6.5
CVE-2026-3309

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…

Mitigation only
Fix from $1,600 2026-04-04
Ragflow HIGH 8.8
CVE-2026-28797

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerab…

Fix: after 0.24.0
Fix from $1,950 2026-04-03
Casdoor MEDIUM 5.4
CVE-2026-5468

A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument …

Mitigation only
Fix from $1,600 2026-04-03
Unclassified HIGH 8.2
CVE-2026-34725

DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-c…

Patch available
Fix from $1,950 2026-04-02
Panel MEDIUM 6.1
CVE-2026-5332

A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. Th…

Mitigation only
Fix from $1,600 2026-04-02
Sharefile Storage Zones Controller HIGH 8.8
CVE-2026-2701EPSS 57%

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Fix: 5.12.4+
Fix from $1,950 2026-04-02
Unclassified HIGH 7.2
CVE-2026-1540

The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to …

Mitigation only
Fix from $1,950 2026-04-02
Dedecms CRITICAL 9.8
CVE-2026-30643

An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

Fix: after 5.7.118
Fix from $2,300 2026-04-01
Jeecg Boot CRITICAL 9.8
CVE-2024-40489

There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary…

Fix: after 3.5.3
Fix from $2,300 2026-04-01
Fedora HIGH 8.8
CVE-2026-35093

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directorie…

Fix: 1.30.3 / 1.31.1+
Fix from $1,950 2026-04-01
Metinfo CRITICAL 9.8
CVE-2026-29014EPSS 42%

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary …

Mitigation only
Fix from $2,300 2026-04-01
Simple Laundry System MEDIUM 6.1
CVE-2026-5255

A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component …

No fix yet
Fix from $1,600 2026-04-01
Xenforo HIGH 7.2
CVE-2026-35056

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel …

Fix: 2.2.18 / 2.3.9+
Fix from $1,950 2026-04-01
Xenforo CRITICAL 9.8
CVE-2025-71281

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-wor…

Fix: 2.3.7+
Fix from $2,300 2026-04-01
Siyuan HIGH 8.2
CVE-2026-34585

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side…

Fix: 3.6.2+
Fix from $1,950 2026-03-31
Siyuan CRITICAL 9.0
CVE-2026-34448

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field …

Fix: 3.6.2+
Fix from $2,300 2026-03-31
Lodash CRITICAL 9.8
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but di…

Fix: 4.18.0+
Fix from $2,300 2026-03-31