Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.5 CVE-2026-34202 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction p… Zebra 4.3.0 / 6.0.1+ Fix from $1,9502026-03-31 CRITICAL 9.8 CVE-2026-34060 Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rub… Ruby Lsp 0.10.2 / 0.26.9+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-3300EPSS 41% The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12… Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-4257EPSS 41% The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in a… Mitigation only Fix from $2,3002026-03-30 CRITICAL 9.8 CVE-2026-30308 In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands. … Hai Build after 3.13.3 Fix from $2,3002026-03-30 CRITICAL 9.8 CVE-2026-30313 DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple… Cline after 1.1.2 Fix from $2,3002026-03-30 CRITICAL 9.8 CVE-2026-30306 In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The description f… Sakadev 4.0.6+ Fix from $2,3002026-03-30 CRITICAL 9.8 CVE-2026-30305 Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely … Syntx after 2.5.0 Fix from $2,3002026-03-30 CRITICAL 9.8 CVE-2026-30307 Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism complete… Roo Code after 3.46.1 Fix from $2,3002026-03-30 CRITICAL 10.0 CVE-2026-28505 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handl… Tautulli 2.17.0+ Fix from $2,3002026-03-30 CRITICAL 9.8 CVE-2026-2287 CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation. Crewai Mitigation only Fix from $2,3002026-03-30 MEDIUM 6.3 CVE-2026-5011 A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the file /webhook of the component J… Mitigation only Fix from $1,6002026-03-28 HIGH 7.3 CVE-2026-4998 A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai… Mitigation only Fix from $1,9502026-03-28 HIGH 8.6 CVE-2026-33955 Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison vi… Notesnook Desktop 3.3.11+ Fix from $1,9502026-03-27 CRITICAL 9.6 CVE-2026-33976 Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can … Notesnook Desktop 3.3.11 / 3.3.17+ Fix from $2,3002026-03-27 HIGH 8.1 CVE-2026-33940 Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the templa… Handlebars 4.7.9+ Fix from $1,9502026-03-27 HIGH 8.2 CVE-2026-33941 Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/… Handlebars 4.7.9+ Fix from $1,9502026-03-27 CRITICAL 9.8 CVE-2026-33943 Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection … Happy Dom 20.8.8+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33937 Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-… Handlebars 4.7.9+ Fix from $2,3002026-03-27 HIGH 8.1 CVE-2026-33938 Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable… Handlebars 4.7.9+ Fix from $1,9502026-03-27 HIGH 7.2 CVE-2026-33881 Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are … Windmill 1.664.0+ Fix from $1,9502026-03-27 CRITICAL 9.9 CVE-2026-33873 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow exec… Langflow 1.9.0+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33654 nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module … Nanobot 0.1.4+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-4965 A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the… Letta Mitigation only Fix from $2,3002026-03-27 CRITICAL 10.0 CVE-2026-4963 A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the… Smolagents Mitigation only Fix from $2,3002026-03-27 HIGH 7.2 CVE-2025-15616 Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow… Wazuh 4.8.0+ Fix from $1,9502026-03-27 CRITICAL 9.1 CVE-2026-27876 A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a… Grafana 11.6.0 / 12.0.0+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-32669 Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the pr… Wcr 1166dhpl Firmware 1.01 / 2.53+ Fix from $2,3002026-03-27 HIGH 7.8 CVE-2026-33744 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.37, the `docker.system_packag… Bentoml 1.4.37+ Fix from $1,9502026-03-27 HIGH 8.8 CVE-2026-33622 PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary Ja… Pinchtab after 0.8.5 Fix from $1,9502026-03-26