Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Sysak CRITICAL 9.8
CVE-2024-44722

SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.

Fix: after 2.0
Fix from $2,300 2026-03-20
Mesop CRITICAL 9.8
CVE-2026-33057EPSS 5%

Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai…

Fix: 1.2.3+
Fix from $2,300 2026-03-20
University Management System MEDIUM 6.1
CVE-2026-4474

A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php.…

No fix yet
Fix from $1,600 2026-03-20
Langflow CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

Fix: 1.8.2+
Fix from $2,300 2026-03-20
Suitecrm HIGH 8.8
CVE-2026-29102

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Auth…

Fix: 7.15.1 / 8.9.3+
Fix from $1,950 2026-03-19
Suitecrm HIGH 7.2
CVE-2026-29103

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vuln…

Fix: 7.15.1 / 8.9.3+
Fix from $1,950 2026-03-19
Dedecms CRITICAL 9.8
CVE-2026-30694

An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

Fix: after 5.7.118
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2025-67113

OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allo…

Mitigation only
Fix from $2,300 2026-03-19
Wgcloud CRITICAL 9.8
CVE-2026-30402

An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function

Fix: after 2.3.7
Fix from $2,300 2026-03-19
Jspdf MEDIUM 6.5
CVE-2026-31898

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to…

Fix: 4.2.1+
Fix from $1,600 2026-03-18
Bamboo HIGH 8.8
CVE-2026-21570

This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 1…

Fix: 9.6.24 / 10.2.16+
Fix from $1,950 2026-03-17
Unclassified CRITICAL 9.8
CVE-2025-69902

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified HIGH 8.8
CVE-2025-50881

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET re…

Mitigation only
Fix from $1,950 2026-03-16
Chamilo Lms HIGH 8.8
CVE-2026-30875

Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authen…

Fix: 1.11.36+
Fix from $1,950 2026-03-16
Librechat HIGH 7.5
CVE-2026-4276

LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.

Mitigation only
Fix from $1,950 2026-03-16
Solidworks HIGH 7.8
CVE-2026-3476

A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code …

Fix: 2026+
Fix from $1,950 2026-03-16
Anythingllm MEDIUM 6.4
CVE-2026-32719

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, Th…

Fix: after 1.11.1
Fix from $1,600 2026-03-16
Simpleeval CRITICAL 9.8
CVE-2026-32640

SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modul…

Fix: 1.0.5+
Fix from $2,300 2026-03-16
Mlflow HIGH 8.8
CVE-2025-14287

A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 16…

Fix: 3.7.0+
Fix from $1,950 2026-03-16
Raytha HIGH 8.8
CVE-2025-15540

"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or acc…

Fix: 1.4.6+
Fix from $1,950 2026-03-16
Chrome HIGH 8.8
CVE-2026-3910 KEV

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 146.0.7680.75+
Fix from $1,950 2026-03-13
Unclassified HIGH 7.2
CVE-2026-32414

Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified CRITICAL 9.1
CVE-2026-32367

Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.Th…

Mitigation only
Fix from $2,300 2026-03-13
Locutus CRITICAL 9.8
CVE-2026-32304

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) functi…

Fix: 3.0.14+
Fix from $2,300 2026-03-13
Sandboxjs CRITICAL 10.0
CVE-2026-26954

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox…

Fix: 0.8.34+
Fix from $2,300 2026-03-13
Unclassified HIGH 8.8
CVE-2026-25817

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improp…

Mitigation only
Fix from $1,950 2026-03-13
Veeam Backup \& Replication CRITICAL 9.9
CVE-2026-21669

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Fix: 13.0.1.2067+
Fix from $2,300 2026-03-12
Veeam Backup \& Replication CRITICAL 9.1
CVE-2026-21671

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) de…

Fix: after 13.0.1.1071
Fix from $2,300 2026-03-12
Openclaw HIGH 8.8
CVE-2026-4039

A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill E…

Fix: 2026.2.21+
Fix from $1,950 2026-03-12
Unclassified MEDIUM 6.3
CVE-2026-3968

A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of …

Mitigation only
Fix from $1,600 2026-03-12