Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Enclave CRITICAL 10.0
CVE-2026-22686

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in…

Fix: 2.7.0+
Fix from $2,300 2026-01-14
4images HIGH 7.2
CVE-2022-50806

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template …

No fix yet
Fix from $1,950 2026-01-13
Eigent CRITICAL 9.8
CVE-2026-22869

Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution fr…

Fix: 0.0.78+
Fix from $2,300 2026-01-13
Unclassified HIGH 8.8
CVE-2025-41717

An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to cod…

Mitigation only
Fix from $1,950 2026-01-13
S\/4 Hana HIGH 7.2
CVE-2026-0498

SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC…

Patch available
Fix from $1,950 2026-01-13
Introscope Enterprise Manager HIGH 8.8
CVE-2026-0500

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could creat…

Patch available
Fix from $1,950 2026-01-13
Unclassified CRITICAL 9.1
CVE-2026-0491

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw en…

Mitigation only
Fix from $2,300 2026-01-13
Gateway HIGH 8.8
CVE-2026-22771

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, E…

Fix: 1.5.7 / 1.6.2+
Fix from $1,950 2026-01-12
Uni2ts CRITICAL 9.8
CVE-2026-22584

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code…

Fix: 2.0.0+
Fix from $2,300 2026-01-09
Unclassified CRITICAL 9.3
CVE-2020-36875

AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The pl…

Mitigation only
Fix from $2,300 2026-01-09
Jimureport CRITICAL 9.8
CVE-2025-66913

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacke…

Fix: after 2.1.3
Fix from $2,300 2026-01-08
Ruoyi Vue Plus CRITICAL 9.4
CVE-2025-66916

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expres…

Fix: after 5.5.1
Fix from $2,300 2026-01-08
Openmetadata HIGH 7.2
CVE-2026-22244

OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SST…

Fix: 1.11.4+
Fix from $1,950 2026-01-08
N8n CRITICAL 9.9
CVE-2026-21877EPSS 5%

n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us…

Fix: 1.121.3+
Fix from $2,300 2026-01-08
Pnpm HIGH 7.8
CVE-2025-69262

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .np…

Fix: 10.27.0+
Fix from $1,950 2026-01-07
House Rental And Property Listing Project MEDIUM 6.1
CVE-2026-0642

A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/comp…

No fix yet
Fix from $1,600 2026-01-07
Unclassified MEDIUM 5.0
CVE-2024-14020

A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/…

Patch available
Fix from $1,600 2026-01-07
Muffon CRITICAL 9.6
CVE-2025-55204

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in.…

Fix: 2.3.0+
Fix from $2,300 2026-01-05
Rockoa MEDIUM 6.1
CVE-2026-0588

A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functionality of the file rockfun.p…

Fix: after 2.7.1
Fix from $1,600 2026-01-05
Online Product Reservation System MEDIUM 6.1
CVE-2026-0586

A vulnerability was detected in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file handgunn…

No fix yet
Fix from $1,600 2026-01-05
Rockoa MEDIUM 5.4
CVE-2026-0587

A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file rock_page_gong.php of the compo…

Fix: after 2.7.1
Fix from $1,600 2026-01-05
Api Key Manager App MEDIUM 6.1
CVE-2026-0580

A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Impo…

Mitigation only
Fix from $1,600 2026-01-05
Malware Remover CRITICAL 9.8
CVE-2025-11837

An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulner…

Fix: 6.6.8.20251023+
Fix from $2,300 2026-01-02
Ligerosmart MEDIUM 5.4
CVE-2025-15437

A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manip…

Fix: after 6.1.24
Fix from $1,600 2026-01-02
Wangmarket MEDIUM 5.4
CVE-2025-15416

A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Var…

Fix: after 6.4
Fix from $1,600 2026-01-01
Signal K Server HIGH 7.2
CVE-2025-68619

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators…

Fix: 2.19.0+
Fix from $1,950 2026-01-01
Kodicms HIGH 8.8
CVE-2025-15393

A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/…

Fix: after 13.82.135
Fix from $1,950 2025-12-31
Icms HIGH 7.2
CVE-2025-15394

A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parame…

Fix: after 8.0.0
Fix from $1,950 2025-12-31
Eyoucms MEDIUM 5.4
CVE-2025-15374

A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the co…

Fix: 1.7.8+
Fix from $1,600 2025-12-31
Simple Php Blog MEDIUM 6.1
CVE-2025-15223

A vulnerability was found in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. Impacted is an unknown function of the file /…

Fix: after 2025-01-22
Fix from $1,600 2025-12-31