Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.8 CVE-2026-75911 CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to e… Fix unknown Fix from $4,9002026-08-18 HIGH 7.8 CVE-2026-75858 CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. Th… Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-73073 Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgr… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-45117 MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configura… Fix unknown Fix from $5,7502026-08-18 CRITICAL 10.0 CVE-2026-73343 Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. Fix unknown Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-50187 Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh … Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-32444 Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. Fix unknown Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-75827 Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete deny… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-67919 An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginAppli… Fix unknown Fix from $5,7502026-08-17 HIGH 7.8 CVE-2026-67961 An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution. Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-38165 A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers t… Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67960 An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, C… Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67926 An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module Fix unknown Fix from $5,7502026-08-17 HIGH 7.0 CVE-2026-34789 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Rest… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.4 CVE-2026-19478 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef… Fix unknown Fix from $5,7502026-08-17 CRITICAL 10.0 CVE-2026-74253 Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer befor… Fix unknown Fix from $5,7502026-08-17 MEDIUM 6.2 CVE-2026-59894 sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quo… Fix unknown Fix from $4,0002026-08-17 CRITICAL 9.8 CVE-2026-50772 An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function. Fix unknown Fix from $5,7502026-08-17 HIGH 7.4 CVE-2026-19980 A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT50… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.5 CVE-2026-19964 A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the compone… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.3 CVE-2026-19958 A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts … No fix yet Fix from $4,0002026-08-16 HIGH 7.2 CVE-2026-17581 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all … No fix yet Fix from $4,9002026-08-16 MEDIUM 5.4 CVE-2026-18385 The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19932 A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /e… No fix yet Fix from $4,0002026-08-16 CRITICAL 10.0 CVE-2026-73678 MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attacke… No fix yet Fix from $5,7502026-08-14 HIGH 7.2 CVE-2026-73679 ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute… No fix yet Fix from $4,9002026-08-14 HIGH 7.8 CVE-2026-46439 compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (S… No fix yet Fix from $4,9002026-08-14 HIGH 8.1 CVE-2026-19768 Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an … No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-72819 Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users … No fix yet Fix from $4,9002026-08-14 MEDIUM 6.5 CVE-2026-72676 Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via … No fix yet Fix from $4,0002026-08-13