Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Dwoo CRITICAL 9.8
CVE-2026-30457

An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.

Mitigation only
Fix from $2,300 2026-03-26
Simple Laundry System MEDIUM 6.1
CVE-2026-4849

A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component …

No fix yet
Fix from $1,600 2026-03-26
N8n HIGH 8.8
CVE-2026-33660

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create o…

Fix: 1.123.27 / 2.13.3+
Fix from $1,950 2026-03-25
Unclassified CRITICAL 9.1
CVE-2026-32573

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.9
CVE-2026-32525

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.9
CVE-2026-27044

Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.Thi…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.1
CVE-2026-25447

Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.9
CVE-2026-25366

Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue af…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified HIGH 8.5
CVE-2026-25001

Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This i…

Mitigation only
Fix from $1,950 2026-03-25
Textract CRITICAL 9.8
CVE-2026-26831

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious…

Fix: after 2.5.0
Fix from $2,300 2026-03-25
Thumbler CRITICAL 9.8
CVE-2026-26833

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is c…

Fix: after 1.1.2
Fix from $2,300 2026-03-25
Pdf Image CRITICAL 9.8
CVE-2026-26830

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructCon…

Fix: after 2.0.0
Fix from $2,300 2026-03-25
Vikunja CRITICAL 9.6
CVE-2026-33334

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w…

Fix: 2.2.2+
Fix from $2,300 2026-03-24
Vikunja HIGH 8.8
CVE-2026-33336

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w…

Fix: 2.2.2+
Fix from $1,950 2026-03-24
Intake HIGH 8.8
CVE-2026-33310

Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default v…

Fix: 2.0.9+
Fix from $1,950 2026-03-24
Langflow CRITICAL 9.9
CVE-2026-33309EPSS 11%

Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6…

Fix: 1.9.0+
Fix from $2,300 2026-03-24
Unclassified CRITICAL 10.0
CVE-2026-4745

Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This vulnerability is as…

Patch available
Fix from $2,300 2026-03-24
Online Lawyer Management System MEDIUM 5.4
CVE-2026-4626

A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The m…

No fix yet
Fix from $1,600 2026-03-24
Unclassified CRITICAL 9.3
CVE-2026-4681

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t…

Mitigation only
Fix from $2,300 2026-03-23
Connect Cms HIGH 8.8
CVE-2026-32276

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi…

Fix: 1.41.1 / 2.41.1+
Fix from $1,950 2026-03-23
Online Lawyer Management System MEDIUM 5.4
CVE-2026-4596

A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. Th…

No fix yet
Fix from $1,600 2026-03-23
Unclassified HIGH 8.8
CVE-2026-24516

A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshootin…

Mitigation only
Fix from $1,950 2026-03-23
Avideo HIGH 8.8
CVE-2026-33479

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsaniti…

Fix: after 26.0
Fix from $1,950 2026-03-23
Unclassified HIGH 7.3
CVE-2025-10679

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to a…

Mitigation only
Fix from $1,950 2026-03-23
Metagpt MEDIUM 6.3
CVE-2026-4515

A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the file metagpt/ext/aflow/script…

Fix: after 0.8.1
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.5
CVE-2026-4004

The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and includin…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 5.6
CVE-2024-13785

The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified CRITICAL 9.8
CVE-2026-3584EPSS 7%

The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' functio…

Mitigation only
Fix from $2,300 2026-03-20
Unclassified MEDIUM 6.3
CVE-2026-4506

A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core/mindsql_core.py. Performing …

Mitigation only
Fix from $1,600 2026-03-20
Dynaconf HIGH 8.1
CVE-2026-33154

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due …

Fix: 3.2.13+
Fix from $1,950 2026-03-20