Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.0 CVE-2026-32999 Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitr… Mitigation only Fix from $2,3002026-05-28 HIGH 7.8 CVE-2026-45136 claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) int… Claude Code Cache Fix 3.5.2+ Fix from $1,9502026-05-27 CRITICAL 9.8 CVE-2026-44888 Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplie… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-44887 Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitra… Mitigation only Fix from $2,3002026-05-27 MEDIUM 6.3 CVE-2026-42879 FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability e… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-45719 Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request bo… Mitigation only Fix from $1,6002026-05-27 HIGH 8.8 CVE-2026-44346 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yam… Bentoml 1.4.39+ Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-37713 An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/clas… Mitigation only Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-37711 An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/acti… Mitigation only Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-37712 An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/clas… Mitigation only Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-8832 The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution i… Mitigation only Fix from $1,9502026-05-27 HIGH 7.2 CVE-2026-6169 The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plu… Mitigation only Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob(… Patch available Fix from $1,9502026-05-27 MEDIUM 5.0 CVE-2026-9568 A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /… Patch available Fix from $1,6002026-05-26 CRITICAL 9.8 CVE-2026-8855 IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au… HTTP Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-9170 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation. HTTP Server Mitigation only Fix from $2,3002026-05-26 CRITICAL 9.8 CVE-2026-8633 IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se… Websphere Application Server after 9.0.5.27 Fix from $2,3002026-05-26 HIGH 7.8 CVE-2026-44728 Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was spe… Babel 7.29.4+ Fix from $1,9502026-05-26 HIGH 7.2 CVE-2026-42785 OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code throug… No fix yet Fix from $1,9502026-05-26 HIGH 7.2 CVE-2026-24937 Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue a… Mitigation only Fix from $1,9502026-05-25 CRITICAL 9.8 CVE-2018-25357 Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PH… Dolibarr Erp\/crm after 7.0.3 Fix from $2,3002026-05-23 MEDIUM 6.3 CVE-2026-9302 A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function … Mitigation only Fix from $1,6002026-05-23 MEDIUM 5.3 CVE-2026-41148 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.… Patch available Fix from $1,6002026-05-22 MEDIUM 5.3 CVE-2026-41149 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.… Patch available Fix from $1,6002026-05-22 CRITICAL 9.3 CVE-2026-9264 A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration thr… Mitigation only Fix from $2,3002026-05-22 MEDIUM 6.5 CVE-2026-42396 Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail Authoritative 4.9.15 / 5.0.5+ Fix from $1,6002026-05-21 MEDIUM 6.8 CVE-2026-39311 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prio… Mitigation only Fix from $1,6002026-05-20 CRITICAL 9.5 CVE-2026-8467 Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpol… Patch available Fix from $2,3002026-05-20 CRITICAL 9.0 CVE-2026-22314 Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component en… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-30117 scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpo… Mitigation only Fix from $2,3002026-05-19