Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Langflow HIGH 8.8
CVE-2026-17633

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17632

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17624

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.7
CVE-2026-70609

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.8
CVE-2026-70431

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowin…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71278

rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. Th…

No fix yet
Fix from $2,300 2026-08-05
Mojarra HIGH 7.5
CVE-2026-46581

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing a…

Fix: after 4.1.13
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-71235

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. T…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-71232

MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.7
CVE-2026-51401

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/sr…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-70553

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application co…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.5
CVE-2026-70477

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using …

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 8.4
CVE-2026-47781

PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plu…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.4
CVE-2026-69264

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.4
CVE-2026-69259

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/c…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.2
CVE-2026-69255

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/ag…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.4
CVE-2026-69256

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide P…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 10.0
CVE-2026-64633

A vulnerability allowing remote unauthenticated code execution on the agent host.

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 8.6
CVE-2026-58074

A vulnerability allowing a high-privileged user to execute arbitrary code on the server.

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.4
CVE-2026-69254

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-prov…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 8.8
CVE-2026-69100

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes u…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.0
CVE-2026-69251

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory node…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 7.3
CVE-2026-18770

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /c…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.0
CVE-2026-16623

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, al…

No fix yet
Fix from $1,950 2026-08-04
Edge Chromium MEDIUM 6.1
CVE-2026-65804

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over…

Fix: 151.0.4129.59+
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.6
CVE-2026-18667

A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sens…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.4
CVE-2026-66065

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions …

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.2
CVE-2026-61523

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arb…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.1
CVE-2026-69088

Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives bec…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-67340

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor …

Mitigation only
Fix from $2,300 2026-08-01