Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2025-61260EPSS 7% A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) conf… Mitigation only Fix from $2,3002026-04-14 MEDIUM 6.5 CVE-2026-2582 The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions… Mitigation only Fix from $1,6002026-04-14 CRITICAL 9.8 CVE-2026-40288 PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to … Praisonaiagents 1.5.140 / 4.5.139+ Fix from $2,3002026-04-14 HIGH 8.4 CVE-2026-40287 PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import … Praisonaiagents 1.5.140 / 4.5.139+ Fix from $1,9502026-04-14 HIGH 7.4 CVE-2026-39421 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in the ToolExecutor component. B… Maxkb 2.8.0+ Fix from $1,9502026-04-14 MEDIUM 6.1 CVE-2026-27674 Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted in… Netweaver Application Server Java Mitigation only Fix from $1,6002026-04-14 HIGH 8.8 CVE-2025-51414 In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality … Mitigation only Fix from $1,9502026-04-13 CRITICAL 9.8 CVE-2026-31048 An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message. Mitigation only Fix from $2,3002026-04-13 HIGH 8.8 CVE-2026-29955 The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.… Kubeplus after 4.2.0 Fix from $1,9502026-04-13 MEDIUM 6.3 CVE-2026-6125 A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save… Mitigation only Fix from $1,6002026-04-12 CRITICAL 9.8 CVE-2026-6110 A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.… Metagpt Patch available Fix from $2,3002026-04-12 HIGH 7.8 CVE-2026-40156 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the current working directory to … Praisonai 4.5.128+ Fix from $1,9502026-04-10 HIGH 7.8 CVE-2026-40158 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampolin… Praisonai 4.5.128+ Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-40217EPSS 6% LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. Litellm after 2026-04-08 Fix from $1,9502026-04-10 CRITICAL 9.8 CVE-2026-5970 A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MB… Metagpt after 0.8.1 Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5971 A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/action… Metagpt after 0.8.1 Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-30479 A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted execut… Mitigation only Fix from $2,3002026-04-09 HIGH 8.8 CVE-2025-70364 An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Su… Mitigation only Fix from $1,9502026-04-09 HIGH 7.2 CVE-2024-1490 An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If … Mitigation only Fix from $1,9502026-04-09 MEDIUM 5.7 CVE-2026-1516 GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Co… GitLab 18.8.9 / 18.9.5+ Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-39891 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that proces… Praisonai after 4.5.114 Fix from $1,9502026-04-08 HIGH 7.8 CVE-2026-39881 Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious … Vim 9.2.0316+ Fix from $1,9502026-04-08 HIGH 7.2 CVE-2026-34724 Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RC… Zammad Mitigation only Fix from $1,9502026-04-08 CRITICAL 9.8 CVE-2026-31040 A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command… Stata Mcp 1.13.0+ Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-25776 Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script. Movable Type 8.0.10 / 8.8.3+ Fix from $2,3002026-04-08 CRITICAL 9.0 CVE-2026-39846 SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the Si… Siyuan 3.6.4+ Fix from $2,3002026-04-07 HIGH 7.3 CVE-2026-5739 A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi… Mitigation only Fix from $1,9502026-04-07 CRITICAL 9.1 CVE-2025-71058 Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configure… No fix yet Fix from $2,3002026-04-07 CRITICAL 10.0 CVE-2026-39337 ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's … Churchcrm 7.1.0+ Fix from $2,3002026-04-07 MEDIUM 6.1 CVE-2025-70844 yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the ac… Yaffa Mitigation only Fix from $1,6002026-04-07