Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Open Webui CRITICAL 9.0
CVE-2026-59216

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and ex…

Fix: 0.10.0+
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-52200

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint …

Mitigation only
Fix from $2,300 2026-07-08
Opencti MEDIUM 6.5
CVE-2026-35211

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exp…

Fix: 7.260401.0+
Fix from $1,600 2026-07-08
Litellm HIGH 7.2
CVE-2026-59821

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails produc…

Fix: 1.82.0+
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-53951

Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_setti…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.4
CVE-2026-55408

Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files becau…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 8.5
CVE-2026-53511

calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by cali…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 8.7
CVE-2026-53751

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with spe…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 8.9
CVE-2026-43921

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOS…

Mitigation only
Fix from $1,950 2026-07-06
Crawl4ai CRITICAL 10.0
CVE-2026-57572

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra…

Fix: 0.9.0+
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.9
CVE-2026-48614

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in …

Mitigation only
Fix from $2,300 2026-07-06
Unclassified HIGH 7.3
CVE-2026-14749

A vulnerability was identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. Impacted is the function eval of the file appli…

Mitigation only
Fix from $1,950 2026-07-05
Unclassified HIGH 7.3
CVE-2026-14722

A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impacts an unknown function of the file src/services/wiki/wikiWorker/load…

Mitigation only
Fix from $1,950 2026-07-05
Unclassified MEDIUM 6.3
CVE-2026-14691

A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_sett…

Mitigation only
Fix from $1,600 2026-07-05
Nltk HIGH 7.8
CVE-2026-12252

In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyPar…

Fix: after 3.9.3
Fix from $1,950 2026-07-04
Unclassified MEDIUM 5.4
CVE-2026-11778

The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in a…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified CRITICAL 10.0
CVE-2026-57624

Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.1
CVE-2026-27436

Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified HIGH 8.7
CVE-2026-55794

Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can…

Patch available
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.4
CVE-2026-14439

A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence …

Mitigation only
Fix from $2,300 2026-07-01
Chrome HIGH 8.8
CVE-2026-14407

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Chrome HIGH 8.8
CVE-2026-14383

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 150.0.7871.46+
Fix from $1,950 2026-07-01
Unclassified HIGH 7.8
CVE-2026-54074

Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-T…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-58454

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that allows authenticated attacker…

Mitigation only
Fix from $1,950 2026-07-01
Mediawiki HIGH 8.8
CVE-2026-8857

A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Ph…

Fix: 1.43.9 / 1.44.6+
Fix from $1,950 2026-07-01
Mediawiki CRITICAL 9.8
CVE-2026-58025

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Imp…

Fix: 1.43.9 / 1.44.6+
Fix from $2,300 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24248

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of …

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Nemo Megatron Bridge HIGH 7.8
CVE-2026-24249

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th…

Fix: 0.4.1+
Fix from $1,950 2026-07-01
Crawl4ai MEDIUM 6.1
CVE-2026-56264

Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and exe…

Fix: 0.8.7+
Fix from $1,600 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-58449

txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver…

Patch available
Fix from $2,300 2026-06-30