Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2026-11157 Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension t… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-10928 Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Ch… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10904 Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.2 CVE-2026-41249 CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.ym… Patch available Fix from $1,9502026-06-04 MEDIUM 5.5 CVE-2026-10688 A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_b… Mitigation only Fix from $1,6002026-06-02 HIGH 8.8 CVE-2026-49143 BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjace… Mitigation only Fix from $1,9502026-06-02 HIGH 8.8 CVE-2026-1829 The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via th… Mitigation only Fix from $1,9502026-06-02 CRITICAL 9.8 CVE-2026-47117 OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used … Patch available Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-25879 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM… Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.0 CVE-2026-9311 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 10.0 CVE-2026-45131 CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes … Patch available Fix from $2,3002026-06-01 CRITICAL 10.0 CVE-2026-45132 CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) expose… Patch available Fix from $2,3002026-06-01 CRITICAL 9.4 CVE-2026-8931 A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3. Mitigation only Fix from $2,3002026-06-01 HIGH 8.1 CVE-2026-42588 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01 HIGH 8.8 CVE-2026-45505 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10175 A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of … Mitigation only Fix from $1,6002026-05-31 CRITICAL 9.8 CVE-2026-45697 Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (wi… Patch available Fix from $2,3002026-05-29 MEDIUM 6.3 CVE-2026-44287 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks… Mitigation only Fix from $1,6002026-05-29 MEDIUM 5.3 CVE-2026-41159 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's defau… Mermaid 10.9.6 / 11.15.0+ Fix from $1,6002026-05-29 HIGH 7.8 CVE-2026-45555 Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagno… Mitigation only Fix from $1,9502026-05-29 HIGH 8.3 CVE-2026-44698 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android,… Mitigation only Fix from $1,9502026-05-29 HIGH 8.8 CVE-2026-9976 Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML p… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9938 Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via … Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 CRITICAL 9.6 CVE-2026-45311 CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalR… Mitigation only Fix from $2,3002026-05-28 HIGH 7.8 CVE-2026-45353 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0. Electerm 3.9.0+ Fix from $1,9502026-05-28 CRITICAL 9.6 CVE-2026-45374 CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure de… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.4 CVE-2026-45058 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code ex… Mitigation only Fix from $2,3002026-05-28 CRITICAL 10.0 CVE-2026-43898 SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover th… Sandboxjs 0.9.6+ Fix from $2,3002026-05-28 CRITICAL 9.3 CVE-2026-45261 GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in t… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.3 CVE-2026-44672 mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3… Mitigation only Fix from $2,3002026-05-28