Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified HIGH 8.4
CVE-2026-42049

jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest into the generated app/build.gra…

Mitigation only
Fix from $1,950 2026-07-14
Coldfusion CRITICAL 9.9
CVE-2026-48322

ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in…

Mitigation only
Fix from $2,300 2026-07-14
.net Framework HIGH 7.8
CVE-2026-50650

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
Sma6210 Firmware HIGH 7.2
CVE-2026-15410 KEVEPSS 76%

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

Mitigation only
Fix from $1,950 2026-07-14
Windows Admin Center MEDIUM 6.5
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

Fix: 2511+
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15702

A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Su…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15697

A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm P…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15698

A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Execu…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15699

A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the …

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15598

A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipula…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 8.8
CVE-2026-55771

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-55773

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified CRITICAL 9.5
CVE-2026-6875EPSS 27%

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an …

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-12257

Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 10.0
CVE-2026-57811

Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allo…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.2
CVE-2026-13014

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrari…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.6
CVE-2026-14453

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15538

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component AP…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15512

A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the file \pig-master\pig-visual\p…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15497

A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/mai…

Mitigation only
Fix from $1,950 2026-07-12
Unclassified CRITICAL 10.0
CVE-2026-61447

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without…

Mitigation only
Fix from $2,300 2026-07-11
Unclassified HIGH 8.8
CVE-2026-13353

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all vers…

No fix yet
Fix from $1,950 2026-07-11
Unclassified CRITICAL 9.1
CVE-2026-61444

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated int…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-61450

Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrat…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 10.0
CVE-2026-54769

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape …

Mitigation only
Fix from $2,300 2026-07-10
Vim HIGH 7.8
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a…

Fix: 9.2.0736+
Fix from $1,950 2026-07-09
Vim HIGH 7.8
CVE-2026-59858

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the t…

Fix: 9.2.0735+
Fix from $1,950 2026-07-09
Unclassified HIGH 8.6
CVE-2026-59833

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engin…

Patch available
Fix from $1,950 2026-07-09
Metabase CRITICAL 9.1
CVE-2026-59826

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase di…

Fix: 1.58.15.1 / 1.59.12+
Fix from $2,300 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-15195

A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/…

Patch available
Fix from $1,600 2026-07-09