Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.9 CVE-2026-7873 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials,… Langflow after 1.10.0 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-10109 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling. Db2 after 12.1.4 Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-10134 IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat… Langflow after 1.9.3 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-58138EPSS 7% Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitra… Patch available Fix from $2,3002026-06-30 MEDIUM 5.4 CVE-2026-48192 A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), Mendix Studio Pro 10.13 (All v… Mitigation only Fix from $1,6002026-06-30 HIGH 8.8 CVE-2026-58116 LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code b… Llama Factory after 0.9.5 Fix from $1,9502026-06-30 CRITICAL 9.1 CVE-2026-37637 An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component No fix yet Fix from $2,3002026-06-29 HIGH 8.8 CVE-2026-13749 Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code executi… Snowflake Cli 3.19.0+ Fix from $1,9502026-06-29 HIGH 7.3 CVE-2026-13500 A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFi… Mitigation only Fix from $1,9502026-06-28 CRITICAL 10.0 CVE-2026-53576 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/… Kestra 1.0.45 / 1.3.21+ Fix from $2,3002026-06-26 HIGH 8.6 CVE-2026-55441 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions… Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.6 CVE-2026-33646 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template eng… Mitigation only Fix from $2,3002026-06-26 HIGH 8.5 CVE-2026-57315 Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2025-7958 A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the… Mitigation only Fix from $1,9502026-06-26 HIGH 8.8 CVE-2026-50741 Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sen… Revive Adserver 6.0.8+ Fix from $1,9502026-06-26 CRITICAL 9.4 CVE-2026-55413 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts… Mitigation only Fix from $2,3002026-06-25 HIGH 7.8 CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy… Vim 9.2.0699+ Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-55895 Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the ne… Vim 9.2.0663+ Fix from $1,9502026-06-25 HIGH 8.5 CVE-2026-56049 Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. Mitigation only Fix from $1,9502026-06-25 CRITICAL 9.9 CVE-2026-54823 Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.0 CVE-2026-55570 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, descri… Mitigation only Fix from $2,3002026-06-24 HIGH 8.2 CVE-2026-44016 Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0… Docling 2.91.0+ Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-12242 The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' at… Mitigation only Fix from $1,9502026-06-24 CRITICAL 10.0 CVE-2026-53753 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature us… Crawl4ai 0.8.7+ Fix from $2,3002026-06-23 CRITICAL 9.6 CVE-2026-48519 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code)… Langflow 1.9.2+ Fix from $2,3002026-06-23 HIGH 8.8 CVE-2026-44959 A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an u… Mitigation only Fix from $1,9502026-06-23 HIGH 8.8 CVE-2026-34916 A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the… Mitigation only Fix from $1,9502026-06-23 CRITICAL 9.8 CVE-2026-12866 All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by su… Mitigation only Fix from $2,3002026-06-23 HIGH 7.5 CVE-2026-41523 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation functi… Vllm 0.22.0+ Fix from $1,9502026-06-22 HIGH 8.1 CVE-2026-55388 piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename optio… Mitigation only Fix from $1,9502026-06-22