Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2026-30460 Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module. Fuel Cms No fix yet Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2024-36057 Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $… Mitigation only Fix from $2,3002026-04-07 HIGH 7.2 CVE-2026-22666EPSS 16% Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails… Dolibarr Erp\/crm 23.0.2+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-34197 KEVEPSS 97% Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach… Activemq 5.19.4 / 6.2.3+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-35197 dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbit… Dye Mitigation only Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35178 Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0… Forceworkbench 65.0.0+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35171 Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN… Kedro 1.3.0+ Fix from $2,3002026-04-06 HIGH 7.2 CVE-2026-26026EPSS 11% GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulne… Glpi 11.0.6+ Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5631 A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/s… Mitigation only Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5594 A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.p… No fix yet Fix from $1,6002026-04-05 CRITICAL 9.8 CVE-2026-5584 A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py… Agenticseek Mitigation only Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2026-5562 A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutio… Ui after 0.7.2 Fix from $2,3002026-04-05 MEDIUM 6.3 CVE-2026-5556 A security vulnerability has been detected in badlogic pi-mono up to 0.58.4. This vulnerability affects the function discoverAndLoadExtensions of the… Mitigation only Fix from $1,6002026-04-05 MEDIUM 6.5 CVE-2026-3309 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul… Mitigation only Fix from $1,6002026-04-04 HIGH 8.8 CVE-2026-28797 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerab… Ragflow after 0.24.0 Fix from $1,9502026-04-03 MEDIUM 5.4 CVE-2026-5468 A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument … Casdoor Mitigation only Fix from $1,6002026-04-03 HIGH 8.2 CVE-2026-34725 DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-c… Patch available Fix from $1,9502026-04-02 MEDIUM 6.1 CVE-2026-5332 A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. Th… Panel Mitigation only Fix from $1,6002026-04-02 HIGH 8.8 CVE-2026-2701EPSS 57% Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. Sharefile Storage Zones Controller 5.12.4+ Fix from $1,9502026-04-02 HIGH 7.2 CVE-2026-1540 The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to … Mitigation only Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-30643 An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload. Dedecms after 5.7.118 Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2024-40489 There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary… Jeecg Boot after 3.5.3 Fix from $2,3002026-04-01 HIGH 8.8 CVE-2026-35093 A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directorie… Fedora 1.30.3 / 1.31.1+ Fix from $1,9502026-04-01 CRITICAL 9.8 CVE-2026-29014EPSS 42% MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary … Metinfo Mitigation only Fix from $2,3002026-04-01 MEDIUM 6.1 CVE-2026-5255 A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component … Simple Laundry System No fix yet Fix from $1,6002026-04-01 HIGH 7.2 CVE-2026-35056 XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel … Xenforo 2.2.18 / 2.3.9+ Fix from $1,9502026-04-01 CRITICAL 9.8 CVE-2025-71281 XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-wor… Xenforo 2.3.7+ Fix from $2,3002026-04-01 HIGH 8.2 CVE-2026-34585 SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side… Siyuan 3.6.2+ Fix from $1,9502026-03-31 CRITICAL 9.0 CVE-2026-34448 SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field … Siyuan 3.6.2+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-4800 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but di… Lodash 4.18.0+ Fix from $2,3002026-03-31