Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2026-30120 remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. Remotion Mitigation only Fix from $2,3002026-06-15 CRITICAL 10.0 CVE-2026-52704 Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. … Mitigation only Fix from $2,3002026-06-15 HIGH 7.5 CVE-2026-11860 Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper … Mitigation only Fix from $1,9502026-06-15 MEDIUM 5.3 CVE-2026-12209 A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/ind… No fix yet Fix from $1,6002026-06-15 MEDIUM 5.3 CVE-2026-12208 A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the … Mitigation only Fix from $1,6002026-06-15 HIGH 7.8 CVE-2026-54057 Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled by… Kitty 0.47.3+ Fix from $1,9502026-06-12 HIGH 7.8 CVE-2026-42851 Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a d… Kitty 0.47.0+ Fix from $1,9502026-06-12 HIGH 8.8 CVE-2026-45833 A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on th… Chromadb after 1.5.9 Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-54133 jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications wi… Jmespath 2.9.1+ Fix from $2,3002026-06-12 HIGH 7.8 CVE-2026-52858 Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the… Vim 9.2.0561+ Fix from $1,9502026-06-11 HIGH 7.8 CVE-2026-52860 Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class de… Vim 9.2.0597+ Fix from $1,9502026-06-11 HIGH 8.8 CVE-2026-47162 Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() … Vim 9.2.0495+ Fix from $1,9502026-06-11 MEDIUM 5.3 CVE-2026-47167 Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber fi… Vim 9.2.0496+ Fix from $1,6002026-06-11 HIGH 7.7 CVE-2026-44495 Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets… Advanced Cluster Management For Kubernetes 2.13.9 / 4.10.3+ Fix from $1,9502026-06-11 HIGH 8.8 CVE-2026-50223 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataR… Ofbiz 24.09.07+ Fix from $1,9502026-06-10 CRITICAL 9.9 CVE-2026-45558 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi… Mitigation only Fix from $2,3002026-06-10 HIGH 7.8 CVE-2026-46432 LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrar… Mitigation only Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-46517 LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True"… Mitigation only Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-47292 Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. Visual Studio Code 1.123.1+ Fix from $1,9502026-06-09 HIGH 8.1 CVE-2026-45583 Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. Exchange Server 15.02.2562.043+ Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2017-20251 WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitra… Mitigation only Fix from $2,3002026-06-09 HIGH 7.8 CVE-2026-8795 A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field i… Mitigation only Fix from $1,9502026-06-09 HIGH 8.8 CVE-2026-11688 Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via… Chrome 149.0.7827.103+ Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-52778 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcFie… Patch available Fix from $2,3002026-06-08 CRITICAL 9.0 CVE-2026-11393 Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote … Mitigation only Fix from $2,3002026-06-08 HIGH 8.8 CVE-2026-25856 OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary … Mitigation only Fix from $1,9502026-06-08 CRITICAL 9.9 CVE-2026-46442 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function la… Flowise 3.1.2+ Fix from $2,3002026-06-08 HIGH 8.8 CVE-2026-49493 Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runIn… Mitigation only Fix from $1,9502026-06-05 HIGH 8.1 CVE-2026-11231 Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via … Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 MEDIUM 6.8 CVE-2026-11218 Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convinced a user… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04