Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 7.5
CVE-2025-69319

Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Code Inje…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified MEDIUM 5.3
CVE-2025-69001

Improper Control of Generation of Code ('Code Injection') vulnerability in Shahjahan Jewel FluentForm fluentform allows Code Injection.This issue aff…

No fix yet
Fix from $1,600 2026-01-22
Unclassified CRITICAL 9.0
CVE-2025-68015

Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scan…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.1
CVE-2025-67944

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi…

Mitigation only
Fix from $2,300 2026-01-22
Tendenci MEDIUM 6.8
CVE-2026-23946

Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions 15.3.11 and below include a …

Fix: 15.3.12+
Fix from $1,600 2026-01-22
Vllm CRITICAL 9.8
CVE-2026-22807

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging …

Fix: 0.14.0+
Fix from $2,300 2026-01-21
5ire CRITICAL 9.6
CVE-2026-22793

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsi…

Fix: 0.15.3+
Fix from $2,300 2026-01-21
Unclassified HIGH 8.8
CVE-2021-47770

OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code throug…

No fix yet
Fix from $1,950 2026-01-21
Getsimplecms HIGH 7.2
CVE-2021-47778

GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code …

No fix yet
Fix from $1,950 2026-01-21
Unified Communications Manager CRITICAL 9.8
CVE-2026-20045 KEV

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME…

Fix: 14su5+
Fix from $2,300 2026-01-21
Binary Parser MEDIUM 6.5
CVE-2026-1245

A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values a…

Fix: 2.3.0+
Fix from $1,600 2026-01-20
N104s R1 Firmware CRITICAL 9.8
CVE-2025-55423

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port…

Fix: after 12.07.6
Fix from $2,300 2026-01-20
Unclassified HIGH 7.8
CVE-2025-33233

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. A successful exploit of this …

Mitigation only
Fix from $1,950 2026-01-20
Orval CRITICAL 9.8
CVE-2026-23947

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul…

Fix: 7.19.0 / 8.0.2+
Fix from $2,300 2026-01-20
Siyuan CRITICAL 9.6
CVE-2026-23852

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attac…

Fix: 3.5.4+
Fix from $2,300 2026-01-19
Mpay MEDIUM 5.4
CVE-2026-1151

A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This ma…

Fix: after 1.2.4
Fix from $1,600 2026-01-19
Patients Waiting Area Queue Management System MEDIUM 5.4
CVE-2026-1147

A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file…

Mitigation only
Fix from $1,600 2026-01-19
Patients Waiting Area Queue Management System MEDIUM 5.4
CVE-2026-1146

A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unkn…

Mitigation only
Fix from $1,600 2026-01-19
Society Management System MEDIUM 6.1
CVE-2026-1135

A security flaw has been discovered in itsourcecode Society Management System 1.0. This impacts an unknown function of the file /admin/activity.php. …

No fix yet
Fix from $1,600 2026-01-19
Society Management System MEDIUM 6.1
CVE-2026-1134

A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown function of the file /admin/expenses.php. The m…

No fix yet
Fix from $1,600 2026-01-19
Unclassified MEDIUM 6.4
CVE-2026-23733

LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Merma…

Mitigation only
Fix from $1,600 2026-01-18
N8n CRITICAL 9.9
CVE-2026-0863EPSS 9%

Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted…

Fix: after 2.4.2
Fix from $2,300 2026-01-18
Ligerosmart MEDIUM 5.4
CVE-2026-1049

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such …

Fix: after 6.1.26
Fix from $1,600 2026-01-17
Ligerosmart MEDIUM 5.4
CVE-2026-1048

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This m…

Fix: after 6.1.26
Fix from $1,600 2026-01-17
Skipper HIGH 8.8
CVE-2026-23742

Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. Th…

Fix: 0.23.0+
Fix from $1,950 2026-01-16
Dive HIGH 8.8
CVE-2026-23523EPSS 6%

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can instal…

Fix: 0.13.0+
Fix from $1,950 2026-01-16
Process Optimization HIGH 8.8
CVE-2025-64691

The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges…

Fix: 2025+
Fix from $1,950 2026-01-16
Process Optimization CRITICAL 10.0
CVE-2025-61937

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” s…

Fix: 2025+
Fix from $2,300 2026-01-16
Shopware HIGH 7.2
CVE-2026-23498

Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure …

Fix: 6.7.6.1+
Fix from $1,950 2026-01-14
Cursor CRITICAL 9.8
CVE-2026-22708

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce…

Fix: 2.3+
Fix from $2,300 2026-01-14