Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 8.7
CVE-2026-47869

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and…

No fix yet
Fix from $1,950 2026-07-18
Langflow CRITICAL 9.9
CVE-2026-8635

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute a…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow HIGH 8.8
CVE-2026-8056

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw ex…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8481

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/va…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.1
CVE-2026-52199

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

Mitigation only
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-9135

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulner…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9198 KEVEPSS 17%

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Db2 HIGH 7.8
CVE-2026-9762

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.

Fix: 12.1.5+
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-16008

A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the fi…

No fix yet
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.9
CVE-2026-46512

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, de…

No fix yet
Fix from $2,300 2026-07-16
Yamcs CRITICAL 9.1
CVE-2026-46621

Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated us…

Fix: 5.12.7+
Fix from $2,300 2026-07-16
Yamcs CRITICAL 9.1
CVE-2026-44632

Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine or…

Fix: 5.12.7+
Fix from $2,300 2026-07-16
Yamcs CRITICAL 9.8
CVE-2026-46562

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-cor…

Fix: 5.12.7+
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-59865

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.d…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-59866

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceNa…

No fix yet
Fix from $2,300 2026-07-16
Unclassified HIGH 8.7
CVE-2026-53597

Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/t…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.7
CVE-2026-59859

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields,…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.7
CVE-2026-59860

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in t…

Mitigation only
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-59861

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property na…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-59862

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descrip…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.8
CVE-2026-55576

MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inline…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-30618

xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker …

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.0
CVE-2026-45534

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-control…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified HIGH 7.2
CVE-2026-62350

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.4
CVE-2026-61446

PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Py…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.8
CVE-2026-61433

PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inje…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.8
CVE-2026-58655

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. …

Mitigation only
Fix from $1,950 2026-07-15
Twig HIGH 8.8
CVE-2026-46640

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker…

Fix: 3.26.0+
Fix from $1,950 2026-07-14
Twig CRITICAL 9.8
CVE-2026-46633

Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is p…

Fix: 3.26.0+
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-38450

An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of…

Mitigation only
Fix from $2,300 2026-07-14