Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified CRITICAL 9.8
CVE-2020-37186

Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration ins…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified HIGH 7.5
CVE-2020-37178

KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vu…

No fix yet
Fix from $1,950 2026-02-11
Unclassified CRITICAL 9.8
CVE-2025-69872

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can …

Mitigation only
Fix from $2,300 2026-02-11
Unclassified HIGH 7.0
CVE-2026-1226

CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintended code within the application…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified HIGH 8.8
CVE-2026-1560EPSS 9%

The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via mu…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified HIGH 7.2
CVE-2025-14541

The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.22 via the conditional…

Mitigation only
Fix from $1,950 2026-02-11
Defender For Endpoint HIGH 8.8
CVE-2026-21537

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adj…

Mitigation only
Fix from $1,950 2026-02-10
Visual Studio 2022 HIGH 8.8
CVE-2026-21256

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…

Fix: 17.14.26+
Fix from $1,950 2026-02-10
Zai Shell HIGH 8.8
CVE-2026-25807

ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing featu…

Fix: 9.0.3+
Fix from $1,950 2026-02-09
Online Reviewer System MEDIUM 5.4
CVE-2026-2224

A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users…

No fix yet
Fix from $1,600 2026-02-09
Unclassified CRITICAL 9.8
CVE-2026-1615

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions…

Patch available
Fix from $2,300 2026-02-09
Studentmanager MEDIUM 5.4
CVE-2026-2201

A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLea…

No fix yet
Fix from $1,600 2026-02-09
Simple Responsive Tourism Website MEDIUM 6.1
CVE-2026-2160

A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of…

No fix yet
Fix from $1,600 2026-02-08
Simple Responsive Tourism Website MEDIUM 6.1
CVE-2026-2159

A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.ph…

No fix yet
Fix from $1,600 2026-02-08
Patients Waiting Area Queue Management System MEDIUM 6.1
CVE-2026-2154

A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impacted is an unknown function of …

No fix yet
Fix from $1,600 2026-02-08
Patients Waiting Area Queue Management System MEDIUM 6.1
CVE-2026-2150

A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown funct…

No fix yet
Fix from $1,600 2026-02-08
Patients Waiting Area Queue Management System MEDIUM 6.1
CVE-2026-2149

A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an …

No fix yet
Fix from $1,600 2026-02-08
Nginxwebui MEDIUM 5.4
CVE-2026-2145

A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of th…

Fix: after 4.3.7
Fix from $1,600 2026-02-08
Calibre HIGH 7.8
CVE-2026-25636

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corru…

Fix: 9.2.0+
Fix from $1,950 2026-02-06
I Educar MEDIUM 5.4
CVE-2026-2064

A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/me…

Fix: after 2.10.0
Fix from $1,600 2026-02-06
Sandboxjs CRITICAL 10.0
CVE-2026-25587

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By over…

Fix: 0.8.29+
Fix from $2,300 2026-02-06
Fermat HIGH 8.8
CVE-2026-2008

A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability affects the function eqn_char…

Fix: after 2025-10-08
Fix from $1,950 2026-02-06
Unclassified MEDIUM 6.3
CVE-2026-1977

A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vul…

Mitigation only
Fix from $1,600 2026-02-06
Chestnutcms HIGH 7.2
CVE-2025-70073

An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function

Fix: after 1.5.8
Fix from $1,950 2026-02-05
Phpfusion CRITICAL 9.8
CVE-2020-37137

PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2026-02-05
Go HIGH 8.6
CVE-2025-61732

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

Fix: 1.24.13 / 1.25.7+
Fix from $1,950 2026-02-05
Langroid CRITICAL 9.6
CVE-2026-25481

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-4…

Fix: 0.59.32+
Fix from $2,300 2026-02-04
Ci4ms HIGH 8.8
CVE-2026-25510

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.28.5.0+
Fix from $1,950 2026-02-03
Claude Code HIGH 8.8
CVE-2026-24887

Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirm…

Fix: 2.0.72+
Fix from $1,950 2026-02-03
Unclassified HIGH 7.8
CVE-2026-24149

NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection iss…

Mitigation only
Fix from $1,950 2026-02-03