Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Fuxa CRITICAL 9.8
CVE-2025-69983

FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-suppl…

Mitigation only
Fix from $2,300 2026-02-03
Sandboxjs CRITICAL 10.0
CVE-2026-25142

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain proto…

Fix: 0.8.27+
Fix from $2,300 2026-02-02
Unclassified CRITICAL 9.8
CVE-2020-37052

AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system …

Mitigation only
Fix from $2,300 2026-01-30
Backstage HIGH 8.8
CVE-2026-25153

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDo…

Fix: 1.13.11 / 1.14.1+
Fix from $1,950 2026-01-30
Orval CRITICAL 9.8
CVE-2026-25141

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7…

Fix: 7.21.0 / 8.2.0+
Fix from $2,300 2026-01-30
Unclassified HIGH 8.1
CVE-2025-24293

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transfo…

Mitigation only
Fix from $1,950 2026-01-30
Unclassified HIGH 7.8
CVE-2025-62348

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead t…

Mitigation only
Fix from $1,950 2026-01-30
House Rental And Property Listing Project MEDIUM 5.4
CVE-2026-1700

A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.p…

No fix yet
Fix from $1,600 2026-01-30
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-1281 KEVEPSS 82%

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Fix: after 12.5.0.0
Fix from $2,300 2026-01-29
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-1340 KEVEPSS 86%

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Fix: after 12.7.0.0
Fix from $2,300 2026-01-29
Autogpt Platform HIGH 8.8
CVE-2026-24780

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.44+
Fix from $1,950 2026-01-29
Bhojon MEDIUM 5.4
CVE-2026-1598

A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknown function of the file /dashb…

Fix: after 2026-01-16
Fix from $1,600 2026-01-29
Erugo HIGH 8.8
CVE-2026-24897

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files…

Fix: after 0.2.14
Fix from $1,950 2026-01-28
Unclassified HIGH 8.8
CVE-2025-69517

An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject arbitrary HTML content during t…

Mitigation only
Fix from $1,950 2026-01-28
Browserstack Local HIGH 7.8
CVE-2025-57283

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly san…

Mitigation only
Fix from $1,950 2026-01-28
Sandboxjs CRITICAL 10.0
CVE-2026-23830

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated …

Fix: 0.8.26+
Fix from $2,300 2026-01-28
Pytorch HIGH 8.8
CVE-2026-24747

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows a…

Fix: 2.10.0+
Fix from $1,950 2026-01-27
Mobile Shop Management System CRITICAL 9.8
CVE-2025-69564

code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password,…

Mitigation only
Fix from $2,300 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24871

Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Mana…

Patch available
Fix from $2,300 2026-01-27
Unclassified MEDIUM 5.3
CVE-2026-24806

Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org…

Patch available
Fix from $1,600 2026-01-27
Vm2 CRITICAL 10.0
CVE-2026-22709

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitizatio…

Fix: 3.10.2+
Fix from $2,300 2026-01-26
Online Examination System MEDIUM 5.4
CVE-2026-1421

A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the component Add Pages. Such manip…

No fix yet
Fix from $1,600 2026-01-26
Unclassified MEDIUM 5.3
CVE-2026-24474

Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a, `use_an…

Patch available
Fix from $1,600 2026-01-24
Unclassified HIGH 7.3
CVE-2024-11976

The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to t…

Mitigation only
Fix from $1,950 2026-01-23
Moodle HIGH 8.8
CVE-2025-67847

A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to in…

Fix: 4.1.22 / 4.4.12+
Fix from $1,950 2026-01-23
Langflow HIGH 7.1
CVE-2026-0771

Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…

Mitigation only
Fix from $1,950 2026-01-23
Open Webui HIGH 8.8
CVE-2026-0766EPSS 27%

Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-01-23
Langflow CRITICAL 9.8
CVE-2026-0768

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…

Mitigation only
Fix from $2,300 2026-01-23
Metagpt CRITICAL 9.8
CVE-2026-0761

Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers …

Mitigation only
Fix from $2,300 2026-01-23
Orval CRITICAL 9.8
CVE-2026-24132

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 th…

Fix: 7.20.0 / 8.0.3+
Fix from $2,300 2026-01-23