Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2021-47939 Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitr… No fix yet Fix from $1,9502026-05-10 HIGH 8.8 CVE-2021-47935 Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious… Sentry No fix yet Fix from $1,9502026-05-10 HIGH 7.8 CVE-2026-42301 pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the su… Mitigation only Fix from $1,9502026-05-09 CRITICAL 9.8 CVE-2026-42298 Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflo… Postiz 2.21.7+ Fix from $2,3002026-05-08 HIGH 8.8 CVE-2026-41486 Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ra… Ray Patch available Fix from $1,9502026-05-08 HIGH 8.8 CVE-2026-29202 Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already aut… Mitigation only Fix from $1,9502026-05-08 HIGH 8.4 CVE-2026-44334 PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISO… Praisonai 4.6.32+ Fix from $1,9502026-05-08 CRITICAL 9.6 CVE-2026-44336 PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou… Praisonai 4.6.34+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41507 math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim i… Math Codegen 0.4.3+ Fix from $2,3002026-05-08 CRITICAL 9.9 CVE-2026-41512 ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerab… 0din Scanner 1.4.1+ Fix from $2,3002026-05-08 HIGH 8.8 CVE-2026-25077 Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hyp… Cloudstack 4.20.3.0 / 4.22.0.1+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2025-67887 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and exec… Mitigation only Fix from $2,3002026-05-08 HIGH 7.3 CVE-2024-46507 A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to … Yeti 2.1.12+ Fix from $1,9502026-05-08 CRITICAL 9.6 CVE-2026-43944 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerabl… Electerm 3.8.15+ Fix from $2,3002026-05-08 HIGH 8.8 CVE-2026-42203 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts… Litellm 1.83.7+ Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2026-41645 Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expressio… Nuclei 3.8.0+ Fix from $1,6002026-05-08 CRITICAL 10.0 CVE-2026-41900 OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was… Openlearnx Patch available Fix from $2,3002026-05-08 HIGH 7.8 CVE-2026-44244 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's … Gitpython 3.1.49+ Fix from $1,9502026-05-07 HIGH 7.8 CVE-2026-42214 Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpol… Notepad Next 0.14+ Fix from $1,9502026-05-07 CRITICAL 9.8 CVE-2026-36458 ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injec… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2025-63706 NPM package next-npm-version1.0.1 is vulnerable to Command injection. Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-8094 Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2. Firefox 140.10.2+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2025-1978 Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G3… Virtual Storage One Block Mitigation only Fix from $2,3002026-05-07 HIGH 8.8 CVE-2026-41139 Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed v… Mathjs 15.2.0+ Fix from $1,9502026-05-07 MEDIUM 6.6 CVE-2026-35255 Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is af… Cloud Native Environment Command Line Interface Mitigation only Fix from $1,6002026-05-06 HIGH 8.8 CVE-2026-7841 A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissi… Mitigation only Fix from $1,9502026-05-06 CRITICAL 9.8 CVE-2026-38431 ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates ca… Erpnext after 15.103.1 Fix from $2,3002026-05-05 HIGH 8.8 CVE-2023-54345 Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role … Erpnext No fix yet Fix from $1,9502026-05-05 CRITICAL 9.8 CVE-2026-42238 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) tha… Nginx Ui 2.3.8+ Fix from $2,3002026-05-04 HIGH 8.8 CVE-2026-42234 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create o… N8n 1.123.32 / 2.17.4+ Fix from $1,9502026-05-04