Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Edge Chromium 148.0.3967.70+ Fix from $2,3002026-05-18 CRITICAL 10.0 CVE-2026-45829EPSS 12% A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run… Mitigation only Fix from $2,3002026-05-18 HIGH 7.7 CVE-2026-6902 A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potenti… Mitigation only Fix from $1,9502026-05-18 CRITICAL 9.8 CVE-2018-25320 ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands … Mitigation only Fix from $2,3002026-05-17 CRITICAL 9.8 CVE-2021-47952 python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing ma… Mitigation only Fix from $2,3002026-05-16 MEDIUM 6.3 CVE-2025-67031 ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant pro… Mitigation only Fix from $1,6002026-05-15 HIGH 8.8 CVE-2021-47964 Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading mali… No fix yet Fix from $1,9502026-05-15 CRITICAL 9.8 CVE-2026-44717 MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mat… Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.1 CVE-2026-41258 OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateC… Mitigation only Fix from $2,3002026-05-15 HIGH 8.1 CVE-2026-35194 Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission pr… Flink 1.20.4 / 2.0.2+ Fix from $1,9502026-05-15 MEDIUM 6.5 CVE-2026-39052 Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String,… Mitigation only Fix from $1,6002026-05-15 CRITICAL 9.1 CVE-2026-8634 Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repo… Patch available Fix from $2,3002026-05-14 MEDIUM 5.4 CVE-2026-8539 Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (U… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 CRITICAL 9.4 CVE-2026-44670 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTM… Mitigation only Fix from $2,3002026-05-14 HIGH 8.3 CVE-2026-44586 SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metada… Mitigation only Fix from $1,9502026-05-14 HIGH 8.8 CVE-2025-15024 Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems … Mitigation only Fix from $1,9502026-05-14 HIGH 8.8 CVE-2026-44827 Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_… Diffusers 0.38.0+ Fix from $1,9502026-05-14 HIGH 8.8 CVE-2026-44513 Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows … Diffusers 0.38.0+ Fix from $1,9502026-05-14 CRITICAL 9.1 CVE-2026-42555 Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case … Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.6 CVE-2026-44482 soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an… Mitigation only Fix from $2,3002026-05-14 MEDIUM 6.3 CVE-2025-69443 Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the us… Mitigation only Fix from $1,6002026-05-14 MEDIUM 5.4 CVE-2025-12669 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that c… GitLab 18.9.7 / 18.10.6+ Fix from $1,6002026-05-14 CRITICAL 9.1 CVE-2026-45714 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple m… Mitigation only Fix from $2,3002026-05-13 HIGH 7.2 CVE-2026-45708 CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. … Mitigation only Fix from $1,9502026-05-13 CRITICAL 9.1 CVE-2026-44377 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple m… Patch available Fix from $2,3002026-05-13 HIGH 7.8 CVE-2026-0236 A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing… Prisma Browser 146.10.7.154+ Fix from $1,9502026-05-13 CRITICAL 10.0 CVE-2026-44005 vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 10.0 CVE-2026-44006 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 10.0 CVE-2026-43997 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Objec… Vm2 3.11.0+ Fix from $2,3002026-05-13 HIGH 8.8 CVE-2026-44293 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conve… Protobufjs 7.5.6 / 8.0.2+ Fix from $1,9502026-05-13