Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.6 CVE-2026-42090 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Androi… Notesnook Desktop 3.3.15 / 3.3.20+ Fix from $2,3002026-05-04 CRITICAL 10.0 CVE-2026-26332 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code.… Vm2 3.11.0+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24118 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to wr… Vm2 3.11.0+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24120 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing at… Vm2 3.10.5+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24781 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function… Vm2 3.11.0+ Fix from $2,3002026-05-04 HIGH 7.8 CVE-2026-36365 An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via … Patch available Fix from $1,9502026-05-04 HIGH 8.1 CVE-2026-40563 Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that … Atlas 2.5.0+ Fix from $1,9502026-05-04 HIGH 7.2 CVE-2026-3120 Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company Sam… Mitigation only Fix from $1,9502026-05-04 HIGH 7.3 CVE-2026-7703 A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. Impacted is an unknown function of the component Websocket API. This manip… Mitigation only Fix from $1,9502026-05-03 MEDIUM 6.3 CVE-2026-7700 A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operati… Mitigation only Fix from $1,6002026-05-03 MEDIUM 5.6 CVE-2026-7669 A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transfo… Mitigation only Fix from $1,6002026-05-02 HIGH 8.8 CVE-2026-2052 The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Executi… Mitigation only Fix from $1,9502026-05-02 MEDIUM 6.3 CVE-2026-7595 A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file… Patch available Fix from $1,6002026-05-01 MEDIUM 5.3 CVE-2026-7580 A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPE… Patch available Fix from $1,6002026-05-01 CRITICAL 9.8 CVE-2026-42994 Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkma… Cli Mitigation only Fix from $2,3002026-05-01 MEDIUM 6.3 CVE-2026-7508 A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the compo… Mitigation only Fix from $1,6002026-04-30 HIGH 8.8 CVE-2026-6543 IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflo… Langflow Desktop after 1.8.4 Fix from $1,9502026-04-30 HIGH 8.1 CVE-2026-36340 An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function Mitigation only Fix from $1,9502026-04-30 HIGH 7.8 CVE-2025-14576 Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the Vect… Qtdeclarative 6.8.6 / 6.10.1+ Fix from $1,9502026-04-30 HIGH 8.8 CVE-2026-34965 Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authentica… Mitigation only Fix from $1,9502026-04-29 HIGH 8.8 CVE-2026-7466 AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-control… Patch available Fix from $1,9502026-04-29 CRITICAL 9.8 CVE-2026-38992 Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows a… Mitigation only Fix from $2,3002026-04-29 HIGH 8.1 CVE-2026-27760EPSS 35% OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to … Patch available Fix from $1,9502026-04-28 HIGH 8.6 CVE-2026-40967 In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query l… Spring Ai 1.0.6 / 1.1.5+ Fix from $1,9502026-04-28 HIGH 7.2 CVE-2026-7191 Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administr… Mitigation only Fix from $1,9502026-04-27 CRITICAL 9.8 CVE-2026-6951 Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://… Simple Git 3.36.0+ Fix from $2,3002026-04-25 HIGH 7.4 CVE-2026-41414 Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-control… Skim 4.6.1+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-40466 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-41044 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-41137 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Panda… Flowise 3.1.0+ Fix from $1,9502026-04-23