Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Zebra HIGH 7.5
CVE-2026-34202

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction p…

Fix: 4.3.0 / 6.0.1+
Fix from $1,950 2026-03-31
Ruby Lsp CRITICAL 9.8
CVE-2026-34060

Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rub…

Fix: 0.10.2 / 0.26.9+
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.8
CVE-2026-3300EPSS 41%

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12…

Mitigation only
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.8
CVE-2026-4257EPSS 41%

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in a…

Mitigation only
Fix from $2,300 2026-03-30
Hai Build CRITICAL 9.8
CVE-2026-30308

In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands. …

Fix: after 3.13.3
Fix from $2,300 2026-03-30
Cline CRITICAL 9.8
CVE-2026-30313

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple…

Fix: after 1.1.2
Fix from $2,300 2026-03-30
Sakadev CRITICAL 9.8
CVE-2026-30306

In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The description f…

Fix: 4.0.6+
Fix from $2,300 2026-03-30
Syntx CRITICAL 9.8
CVE-2026-30305

Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely …

Fix: after 2.5.0
Fix from $2,300 2026-03-30
Roo Code CRITICAL 9.8
CVE-2026-30307

Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism complete…

Fix: after 3.46.1
Fix from $2,300 2026-03-30
Tautulli CRITICAL 10.0
CVE-2026-28505

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handl…

Fix: 2.17.0+
Fix from $2,300 2026-03-30
Crewai CRITICAL 9.8
CVE-2026-2287

CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.

Mitigation only
Fix from $2,300 2026-03-30
Unclassified MEDIUM 6.3
CVE-2026-5011

A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the file /webhook of the component J…

Mitigation only
Fix from $1,600 2026-03-28
Unclassified HIGH 7.3
CVE-2026-4998

A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai…

Mitigation only
Fix from $1,950 2026-03-28
Notesnook Desktop HIGH 8.6
CVE-2026-33955

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison vi…

Fix: 3.3.11+
Fix from $1,950 2026-03-27
Notesnook Desktop CRITICAL 9.6
CVE-2026-33976

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can …

Fix: 3.3.11 / 3.3.17+
Fix from $2,300 2026-03-27
Handlebars HIGH 8.1
CVE-2026-33940

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the templa…

Fix: 4.7.9+
Fix from $1,950 2026-03-27
Handlebars HIGH 8.2
CVE-2026-33941

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/…

Fix: 4.7.9+
Fix from $1,950 2026-03-27
Happy Dom CRITICAL 9.8
CVE-2026-33943

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection …

Fix: 20.8.8+
Fix from $2,300 2026-03-27
Handlebars CRITICAL 9.8
CVE-2026-33937

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-…

Fix: 4.7.9+
Fix from $2,300 2026-03-27
Handlebars HIGH 8.1
CVE-2026-33938

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable…

Fix: 4.7.9+
Fix from $1,950 2026-03-27
Windmill HIGH 7.2
CVE-2026-33881

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are …

Fix: 1.664.0+
Fix from $1,950 2026-03-27
Langflow CRITICAL 9.9
CVE-2026-33873

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow exec…

Fix: 1.9.0+
Fix from $2,300 2026-03-27
Nanobot CRITICAL 9.8
CVE-2026-33654

nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module …

Fix: 0.1.4+
Fix from $2,300 2026-03-27
Letta CRITICAL 9.8
CVE-2026-4965

A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the…

Mitigation only
Fix from $2,300 2026-03-27
Smolagents CRITICAL 10.0
CVE-2026-4963

A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the…

Mitigation only
Fix from $2,300 2026-03-27
Wazuh HIGH 7.2
CVE-2025-15616

Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow…

Fix: 4.8.0+
Fix from $1,950 2026-03-27
Grafana CRITICAL 9.1
CVE-2026-27876

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a…

Fix: 11.6.0 / 12.0.0+
Fix from $2,300 2026-03-27
Wcr 1166dhpl Firmware CRITICAL 9.8
CVE-2026-32669

Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the pr…

Fix: 1.01 / 2.53+
Fix from $2,300 2026-03-27
Bentoml HIGH 7.8
CVE-2026-33744

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.37, the `docker.system_packag…

Fix: 1.4.37+
Fix from $1,950 2026-03-27
Pinchtab HIGH 8.8
CVE-2026-33622

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary Ja…

Fix: after 0.8.5
Fix from $1,950 2026-03-26