Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.7 CVE-2026-73651 TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Pri… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-73649 Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constr… No fix yet Fix from $5,7502026-08-13 HIGH 7.8 CVE-2026-73505 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/p… No fix yet Fix from $4,9002026-08-13 HIGH 8.4 CVE-2026-67986 amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A… No fix yet Fix from $4,9002026-08-13 CRITICAL 10.0 CVE-2026-61962 Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. No fix yet Fix from $5,7502026-08-13 CRITICAL 10.0 CVE-2026-27544 Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. No fix yet Fix from $5,7502026-08-13 CRITICAL 9.0 CVE-2026-73487 Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.0 CVE-2026-73485 Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.0 CVE-2026-73486 Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.2 CVE-2026-0298 An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ … No fix yet Fix from $4,0002026-08-13 HIGH 7.8 CVE-2026-13094 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publi… I Access Client Solutions No fix yet Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-73268 A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurat… No fix yet Fix from $5,7502026-08-12 CRITICAL 10.0 CVE-2026-73299 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .… No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-65941 In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra… No fix yet Fix from $4,9002026-08-12 HIGH 7.1 CVE-2026-73291 Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/im… No fix yet Fix from $4,9002026-08-12 CRITICAL 10.0 CVE-2026-67282 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code … No fix yet Fix from $5,7502026-08-12 CRITICAL 9.8 CVE-2026-16051 The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, no… No fix yet Fix from $5,7502026-08-12 HIGH 8.5 CVE-2026-73248 calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or … No fix yet Fix from $4,9002026-08-11 CRITICAL 9.4 CVE-2026-66147 An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote… No fix yet Fix from $5,7502026-08-11 MEDIUM 6.3 CVE-2026-66148 An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic… No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-66149 Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-66150 Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi… No fix yet Fix from $4,9002026-08-11 HIGH 8.5 CVE-2026-73233 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.6 CVE-2026-73032 PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning maliciou… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.1 CVE-2026-66145 An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke… No fix yet Fix from $5,7502026-08-11 CRITICAL 10.0 CVE-2026-45618 LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa… No fix yet Fix from $5,7502026-08-11 MEDIUM 6.4 CVE-2026-18708 An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be exe… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.1 CVE-2026-73084 Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied c… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-70336 Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. Visual Studio Code 1.132.1+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70338 Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locall… Powershell 7.4.19.0 / 7.5.10.0+ Fix from $4,9002026-08-11