Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
E Commerce MEDIUM 5.4
CVE-2025-15583

A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file utility/function.php. Executing …

No fix yet
Fix from $1,600 2026-02-20
Unclassified CRITICAL 9.9
CVE-2025-67979

Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows …

Mitigation only
Fix from $2,300 2026-02-20
Unclassified HIGH 7.7
CVE-2025-52744

Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Inpersttion For Theme err-our-team allows Code Injection.This …

No fix yet
Fix from $1,950 2026-02-20
Semantic Kernel CRITICAL 9.9
CVE-2026-26030

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…

Fix: 1.39.4+
Fix from $2,300 2026-02-19
Saisies CRITICAL 9.8
CVE-2025-71243EPSS 5%

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. …

Fix: 5.11.1+
Fix from $2,300 2026-02-19
Jspdf HIGH 8.8
CVE-2026-25755

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject ar…

Fix: 4.2.0+
Fix from $1,950 2026-02-19
Invoiceplane CRITICAL 9.1
CVE-2026-25548

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil…

Fix: 1.7.1+
Fix from $2,300 2026-02-18
Majordomo CRITICAL 9.8
CVE-2026-27174EPSS 7%

MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in…

Patch available
Fix from $2,300 2026-02-18
Nltk HIGH 8.8
CVE-2025-14009

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py…

Fix: 3.9.3+
Fix from $1,950 2026-02-18
Unclassified HIGH 7.8
CVE-2025-61982

An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A specially crafted OpenFOAM si…

Mitigation only
Fix from $1,950 2026-02-18
Nemo HIGH 7.8
CVE-2025-33250

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might …

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Nemo HIGH 7.8
CVE-2025-33251

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might …

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Nemo HIGH 7.8
CVE-2025-33236

NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit of this v…

Fix: 2.6.1+
Fix from $1,950 2026-02-18
Nemo Megatron Bridge HIGH 7.8
CVE-2025-33239

NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection. A successful exploit …

Fix: 0.2.2+
Fix from $1,950 2026-02-18
Nemo Megatron Bridge HIGH 7.8
CVE-2025-33240

NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection. A successful exploi…

Fix: 0.2.2+
Fix from $1,950 2026-02-18
Unclassified HIGH 7.2
CVE-2026-2296

The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, a…

Mitigation only
Fix from $1,950 2026-02-18
Blossom MEDIUM 5.4
CVE-2026-2622

A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blossom-backend/backend/src/main/ja…

Fix: after 1.17.1
Fix from $1,600 2026-02-17
Unclassified CRITICAL 9.9
CVE-2025-70830

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execu…

Mitigation only
Fix from $2,300 2026-02-17
Coderunner HIGH 7.8
CVE-2025-65715

An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when …

No fix yet
Fix from $1,950 2026-02-16
Markdown Preview Enhanced HIGH 8.8
CVE-2025-65716

An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md fi…

No fix yet
Fix from $1,950 2026-02-16
Cskefu MEDIUM 5.4
CVE-2026-2557

A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller/resource/MediaController.jav…

Fix: after 8.0.1
Fix from $1,600 2026-02-16
Ligerosmart MEDIUM 6.1
CVE-2026-2546

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such …

Fix: after 6.1.26
Fix from $1,600 2026-02-16
Ligerosmart MEDIUM 6.1
CVE-2026-2547

A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing …

Fix: after 6.1.26
Fix from $1,600 2026-02-16
Ligerosmart MEDIUM 6.1
CVE-2026-2545

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This…

Fix: after 6.1.26
Fix from $1,600 2026-02-16
Avro HIGH 7.3
CVE-2025-33042

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro …

Fix: 1.11.5+
Fix from $1,950 2026-02-13
Yoke HIGH 8.8
CVE-2026-26056

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (A…

Fix: after 0.19.0
Fix from $1,950 2026-02-12
Authentik HIGH 7.2
CVE-2026-25227

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User t…

Fix: 2025.8.6 / 2025.10.4+
Fix from $1,950 2026-02-12
Unclassified HIGH 7.8
CVE-2025-63421

An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file

No fix yet
Fix from $1,950 2026-02-12
Crawl4ai CRITICAL 10.0
CVE-2026-26216

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks para…

Fix: 0.8.0+
Fix from $2,300 2026-02-12
Unclassified HIGH 8.8
CVE-2026-0969

The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX conte…

Mitigation only
Fix from $1,950 2026-02-12