Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 8.1
CVE-2026-16144

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-68770

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logi…

Mitigation only
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-51785

An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request

No fix yet
Fix from $2,300 2026-07-31
Unclassified HIGH 8.1
CVE-2026-53510

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby so…

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-17561

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign…

No fix yet
Fix from $2,300 2026-07-31
Unclassified HIGH 7.2
CVE-2026-13392

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative cap…

No fix yet
Fix from $1,950 2026-07-31
Langflow CRITICAL 9.9
CVE-2026-12946

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…

Fix: 1.10.1+
Fix from $2,300 2026-07-30
Unclassified HIGH 7.5
CVE-2026-61536

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered…

No fix yet
Fix from $1,950 2026-07-30
Amplify Codegen Ui HIGH 8.8
CVE-2026-18245

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrar…

Fix: 2.20.6+
Fix from $1,950 2026-07-30
Langflow CRITICAL 9.9
CVE-2026-13435

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

Fix: 1.10.2+
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.0
CVE-2026-14602

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attack…

No fix yet
Fix from $2,300 2026-07-30
Chrome HIGH 8.8
CVE-2026-17922

Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a crafted …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Unclassified HIGH 8.3
CVE-2026-54661

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-ht…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.3
CVE-2026-54662

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfi…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.3
CVE-2026-54664

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parser…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.3
CVE-2026-54666

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts p…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-14900

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-13423

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which …

No fix yet
Fix from $2,300 2026-07-29
Datamodel Code Generator HIGH 7.5
CVE-2026-55415

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.64.0+
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 8.8
CVE-2026-54653

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.60.2+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.8
CVE-2026-54654

datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is r…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.8
CVE-2026-54655

datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel…

No fix yet
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 7.8
CVE-2026-54656

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.60.2+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.8
CVE-2026-54621

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_cod…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-66745

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated at…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-66748

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage p…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified CRITICAL 10.0
CVE-2026-65880

Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code exec…

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 8.8
CVE-2026-56747

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker …

No fix yet
Fix from $1,950 2026-07-27
Unclassified CRITICAL 9.0
CVE-2026-14289

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection i…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 7.5
CVE-2026-63720

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve r…

No fix yet
Fix from $1,950 2026-07-26