Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Chartbrew HIGH 7.2
CVE-2026-25887

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1…

Fix: 4.8.1+
Fix from $1,950 2026-03-06
Chartbrew HIGH 8.8
CVE-2026-25888

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1…

Fix: 4.8.1+
Fix from $1,950 2026-03-06
Unclassified HIGH 8.8
CVE-2025-70995

An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified HIGH 8.5
CVE-2026-28134

Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue af…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified CRITICAL 9.0
CVE-2026-27984

Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This is…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.9
CVE-2026-22390

Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allo…

Mitigation only
Fix from $2,300 2026-03-05
Craft Cms CRITICAL 9.1
CVE-2026-28783

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerou…

Fix: 4.17.0 / 5.9.0+
Fix from $2,300 2026-03-04
Arubaos HIGH 8.1
CVE-2026-23808

A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled…

Fix: after 10.7.2.2
Fix from $1,950 2026-03-04
App Auto Patch HIGH 7.8
CVE-2025-70341

Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.

Fix: after 3.4.2
Fix from $1,950 2026-03-04
Easyweb HIGH 8.8
CVE-2024-55022

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name paramet…

Mitigation only
Fix from $1,950 2026-03-03
Impact Mobile HIGH 8.8
CVE-2023-31044

An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functio…

Fix: after 23
Fix from $1,950 2026-03-03
Ranger CRITICAL 9.8
CVE-2025-59059

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to…

Fix: 2.8.0+
Fix from $2,300 2026-03-03
Affine HIGH 8.8
CVE-2026-21853

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerabi…

Fix: 0.25.4+
Fix from $1,950 2026-03-02
Unclassified HIGH 8.8
CVE-2026-3132

The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via t…

Mitigation only
Fix from $1,950 2026-03-02
Ac15 Firmware CRITICAL 9.8
CVE-2026-24105

An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a …

Mitigation only
Fix from $2,300 2026-03-02
Personnel Property Equipment System HIGH 7.2
CVE-2026-26699

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.

No fix yet
Fix from $1,950 2026-03-02
Twenty CRITICAL 9.8
CVE-2026-26720

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

Fix: after 1.15.0
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24107

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`…

Mitigation only
Fix from $2,300 2026-03-02
University Management System MEDIUM 6.1
CVE-2026-3412

A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file /att_single_view.php. The man…

No fix yet
Fix from $1,600 2026-03-02
Unclassified HIGH 7.3
CVE-2026-3409

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the fi…

Mitigation only
Fix from $1,950 2026-03-02
Maxsite Cms CRITICAL 9.8
CVE-2026-3395

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe…

Fix: 109.2+
Fix from $2,300 2026-03-01
Statamic HIGH 8.0
CVE-2026-28425

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with…

Fix: 5.73.11 / 6.4.0+
Fix from $1,950 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21656

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21657

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21658

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls …

Fix: after 10.22
Fix from $2,300 2026-02-27
Doctor Appointment System MEDIUM 6.1
CVE-2026-3302

A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown functionality of the file /reg…

No fix yet
Fix from $1,600 2026-02-27
Fastcms HIGH 7.8
CVE-2026-26682

An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java component

Fix: 0.1.6+
Fix from $1,950 2026-02-26
Langflow CRITICAL 9.8
CVE-2026-27966EPSS 34%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allo…

Fix: 1.8.0+
Fix from $2,300 2026-02-26
Agenta CRITICAL 9.9
CVE-2026-27952

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom cod…

Fix: 0.48.1+
Fix from $2,300 2026-02-26
Unclassified HIGH 8.0
CVE-2026-27830

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instanc…

Patch available
Fix from $1,950 2026-02-26