Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.2 CVE-2026-54271 protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-… Protobufjs Cli 1.3.2 / 2.5.0+ Fix from $1,9502026-06-22 CRITICAL 9.6 CVE-2026-10789 A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability… Fusion 2703.1.20+ Fix from $2,3002026-06-22 CRITICAL 9.8 CVE-2026-9072 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i… I after 7.6 Fix from $2,3002026-06-22 HIGH 8.8 CVE-2026-8858 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the We… I after 7.6 Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-50178 The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS … Angular Language Service 21.2.4+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-49241 The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Lan… Angular Language Service 21.2.4+ Fix from $1,9502026-06-22 HIGH 7.2 CVE-2026-56446 MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can inc… Misp 2.5.42+ Fix from $1,9502026-06-22 CRITICAL 10.0 CVE-2026-10561 IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass tha… Langflow after 1.9.3 Fix from $2,3002026-06-22 HIGH 7.8 CVE-2026-12822 A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipula… Langflow 1.9.3+ Fix from $1,9502026-06-22 HIGH 7.2 CVE-2026-56382 Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::acti… Mitigation only Fix from $1,9502026-06-21 CRITICAL 9.9 CVE-2026-5366 Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class.… Prefect Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2024-58351 Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the fro… Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2022-50972 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands thro… Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.1 CVE-2026-36418 JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSel… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-47103 Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by sup… Python Statemachine 3.2.0+ Fix from $2,3002026-06-17 HIGH 7.5 CVE-2026-54816 Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affect… Mitigation only Fix from $1,9502026-06-17 HIGH 8.5 CVE-2026-49113 Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.9 CVE-2026-40783 Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 10.0 CVE-2026-25470 Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Cod… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-46850 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. … Mysql Shell Mitigation only Fix from $2,3002026-06-17 HIGH 8.1 CVE-2026-46851 Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is af… Peoplesoft Enterprise Campus Software Campus Community Mitigation only Fix from $1,9502026-06-17 HIGH 7.8 CVE-2026-24155 NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execut… Nemo 2.7.3+ Fix from $1,9502026-06-16 CRITICAL 9.9 CVE-2026-49774 Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects R… Mitigation only Fix from $2,3002026-06-16 HIGH 8.8 CVE-2026-48017 DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName param… Mitigation only Fix from $1,9502026-06-15 CRITICAL 10.0 CVE-2026-48836 Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. Mitigation only Fix from $2,3002026-06-15 HIGH 8.5 CVE-2026-48124 Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook com… Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.1 CVE-2026-39465 Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-50880 An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted req… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-50871 An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to … Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-50872 An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensit… Mitigation only Fix from $2,3002026-06-15