Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 7.2
CVE-2026-65693

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary O…

No fix yet
Fix from $1,950 2026-07-24
Powershell Universal HIGH 8.8
CVE-2026-16801

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an…

Fix: 2026.2.3.0+
Fix from $1,950 2026-07-24
Powershell Universal HIGH 8.8
CVE-2026-16800

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an …

Fix: 2026.2.3.0+
Fix from $1,950 2026-07-24
Unclassified CRITICAL 10.0
CVE-2025-71389

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Serv…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 7.8
CVE-2026-60122

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who cont…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.7
CVE-2026-47722

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86…

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-47668

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut…

No fix yet
Fix from $2,300 2026-07-23
Teamcity CRITICAL 10.0
CVE-2026-65906

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

Fix: 2025.11.6 / 2026.1.2+
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-65907

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

No fix yet
Fix from $2,300 2026-07-23
Intellij Idea CRITICAL 9.8
CVE-2026-64815

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

Fix: 2026.2+
Fix from $2,300 2026-07-23
Goland HIGH 7.8
CVE-2026-64802

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

Fix: 2026.2+
Fix from $1,950 2026-07-23
Goland HIGH 7.8
CVE-2026-64803

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

Fix: 2026.2+
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.9
CVE-2026-59543

Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-15011

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, an…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-16606

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote …

No fix yet
Fix from $2,300 2026-07-22
Unclassified MEDIUM 6.5
CVE-2025-13146

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ…

No fix yet
Fix from $1,600 2026-07-22
Maxicharger Single Charger Firmware CRITICAL 9.8
CVE-2026-8984

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafte…

Fix: after 1.03.51
Fix from $2,300 2026-07-21
Unclassified HIGH 8.9
CVE-2026-43945

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to ach…

Mitigation only
Fix from $1,950 2026-07-21
Sourcetree HIGH 8.0
CVE-2026-21575

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. T…

Fix: 3.4.13+
Fix from $1,950 2026-07-21
Unclassified HIGH 8.1
CVE-2026-47398

PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALL…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-65008

Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), w…

No fix yet
Fix from $2,300 2026-07-21
Unclassified MEDIUM 6.9
CVE-2026-51385

An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fet…

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-52656

An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary …

No fix yet
Fix from $2,300 2026-07-20
Unclassified HIGH 8.9
CVE-2026-60026

Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vul…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 10.0
CVE-2026-44359

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow i…

No fix yet
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-16204

A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 6.3
CVE-2026-16151

A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation …

No fix yet
Fix from $1,600 2026-07-18
Unclassified MEDIUM 6.3
CVE-2026-16150

A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliase…

No fix yet
Fix from $1,600 2026-07-18
Unclassified HIGH 7.8
CVE-2026-9147

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled stre…

No fix yet
Fix from $1,950 2026-07-18
Unclassified HIGH 8.7
CVE-2026-47867

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control p…

Mitigation only
Fix from $1,950 2026-07-18