Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Sharepoint Server MEDIUM 6.5
CVE-2026-65660

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a net…

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Unclassified HIGH 8.4
CVE-2026-73076

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-19546

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mit…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.7
CVE-2026-72765

n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create …

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain function…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-44758

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected fu…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.3
CVE-2026-72904

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in …

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 5.5
CVE-2026-18942

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by …

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 8.8
CVE-2026-66738

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-type…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.0
CVE-2026-72718

goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather t…

No fix yet
Fix from $4,900 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-42537

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-44416

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra…

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-55799

Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 10.0
CVE-2026-66915

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the aja…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-46409

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des…

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 8.7
CVE-2026-17603

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A us…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-50159

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulne…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.8
CVE-2026-48054

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to …

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19060

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. …

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19058

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-66709

Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 10.0
CVE-2026-65553

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-65548

Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-67531

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host …

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.6
CVE-2026-71319

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channe…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 8.1
CVE-2026-71320

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nux…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.8
CVE-2026-55522

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow…

No fix yet
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-9196

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to imp…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-8478

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-8182

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via …

Fix: 1.11.0+
Fix from $1,950 2026-08-05