Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.7 CVE-2026-44295 protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identif… Protobufjs Cli 1.2.1 / 2.0.2+ Fix from $1,9502026-05-13 HIGH 8.1 CVE-2026-44291 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited proto… Protobufjs 7.5.6 / 8.0.2+ Fix from $1,9502026-05-13 CRITICAL 10.0 CVE-2026-42288 ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code ex… Mitigation only Fix from $2,3002026-05-12 HIGH 7.2 CVE-2026-43680 A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS … Filemaker Cloud 2.22.0.5+ Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2025-15463 The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.… Mitigation only Fix from $1,6002026-05-12 CRITICAL 9.4 CVE-2026-44262EPSS 6% Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and val… Mitigation only Fix from $2,3002026-05-12 HIGH 7.2 CVE-2026-44403 Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authent… Wing Ftp Server 8.1.3+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-8429 SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in t… Mitigation only Fix from $1,9502026-05-12 HIGH 8.1 CVE-2026-8430 SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allo… Mitigation only Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-43892 AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal fo… Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.9 CVE-2026-42898 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over … Dynamics 365 9.1.45.11+ Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-41094 Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. Data Formulator 0.7+ Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-31230 The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_e… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31231 Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to e… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31233 Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packag… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31236 The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2025-65719 An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted H… Mitigation only Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-31225 The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() func… Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-31228 The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluat… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31217 The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07… Optimate Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31220 PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of use… Mitigation only Fix from $2,3002026-05-12 HIGH 7.2 CVE-2026-43874 WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the YPTSocket autoEvalCodeOnHTML e… Patch available Fix from $1,9502026-05-11 HIGH 7.3 CVE-2026-37630 An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function Mitigation only Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-42603 OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/… Mitigation only Fix from $1,9502026-05-11 HIGH 7.3 CVE-2026-31251 CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC … Mitigation only Fix from $1,9502026-05-11 MEDIUM 5.7 CVE-2026-31252 CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model… Mitigation only Fix from $1,6002026-05-11 HIGH 7.3 CVE-2026-31253 The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnera… Mitigation only Fix from $1,9502026-05-11 CRITICAL 9.1 CVE-2026-42607 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE… Patch available Fix from $2,3002026-05-11 HIGH 8.8 CVE-2022-50944 Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious f… No fix yet Fix from $1,9502026-05-10 HIGH 8.8 CVE-2021-47938 ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to exec… No fix yet Fix from $1,9502026-05-10