Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2026-30457 An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. Dwoo Mitigation only Fix from $2,3002026-03-26 MEDIUM 6.1 CVE-2026-4849 A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component … Simple Laundry System No fix yet Fix from $1,6002026-03-26 HIGH 8.8 CVE-2026-33660 n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create o… N8n 1.123.27 / 2.13.3+ Fix from $1,9502026-03-25 CRITICAL 9.1 CVE-2026-32573 Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-32525 Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-27044 Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.Thi… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.1 CVE-2026-25447 Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-25366 Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue af… Mitigation only Fix from $2,3002026-03-25 HIGH 8.5 CVE-2026-25001 Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This i… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2026-26831 textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious… Textract after 2.5.0 Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-26833 thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is c… Thumbler after 1.1.2 Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-26830 pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructCon… Pdf Image after 2.0.0 Fix from $2,3002026-03-25 CRITICAL 9.6 CVE-2026-33334 Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w… Vikunja 2.2.2+ Fix from $2,3002026-03-24 HIGH 8.8 CVE-2026-33336 Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w… Vikunja 2.2.2+ Fix from $1,9502026-03-24 HIGH 8.8 CVE-2026-33310 Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default v… Intake 2.0.9+ Fix from $1,9502026-03-24 CRITICAL 9.9 CVE-2026-33309EPSS 11% Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6… Langflow 1.9.0+ Fix from $2,3002026-03-24 CRITICAL 10.0 CVE-2026-4745 Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This vulnerability is as… Patch available Fix from $2,3002026-03-24 MEDIUM 5.4 CVE-2026-4626 A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The m… Online Lawyer Management System No fix yet Fix from $1,6002026-03-24 CRITICAL 9.3 CVE-2026-4681 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t… Mitigation only Fix from $2,3002026-03-23 HIGH 8.8 CVE-2026-32276 Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and includi… Connect Cms 1.41.1 / 2.41.1+ Fix from $1,9502026-03-23 MEDIUM 5.4 CVE-2026-4596 A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. Th… Online Lawyer Management System No fix yet Fix from $1,6002026-03-23 HIGH 8.8 CVE-2026-24516 A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshootin… Mitigation only Fix from $1,9502026-03-23 HIGH 8.8 CVE-2026-33479 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsaniti… Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 7.3 CVE-2025-10679 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to a… Mitigation only Fix from $1,9502026-03-23 MEDIUM 6.3 CVE-2026-4515 A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the file metagpt/ext/aflow/script… Metagpt after 0.8.1 Fix from $1,6002026-03-21 MEDIUM 6.5 CVE-2026-4004 The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and includin… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.6 CVE-2024-13785 The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions… Mitigation only Fix from $1,6002026-03-21 CRITICAL 9.8 CVE-2026-3584EPSS 7% The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' functio… Mitigation only Fix from $2,3002026-03-20 MEDIUM 6.3 CVE-2026-4506 A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core/mindsql_core.py. Performing … Mitigation only Fix from $1,6002026-03-20 HIGH 8.1 CVE-2026-33154 dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due … Dynaconf 3.2.13+ Fix from $1,9502026-03-20