Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2024-44722 SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd. Sysak after 2.0 Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-33057EPSS 5% Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai… Mesop 1.2.3+ Fix from $2,3002026-03-20 MEDIUM 6.1 CVE-2026-4474 A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php.… University Management System No fix yet Fix from $1,6002026-03-20 CRITICAL 9.8 CVE-2026-33017 KEVEPSS 96% Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id… Langflow 1.8.2+ Fix from $2,3002026-03-20 HIGH 8.8 CVE-2026-29102 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Auth… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,9502026-03-19 HIGH 7.2 CVE-2026-29103 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vuln… Suitecrm 7.15.1 / 8.9.3+ Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-30694 An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component Dedecms after 5.7.118 Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-67113 OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allo… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-30402 An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function Wgcloud after 2.3.7 Fix from $2,3002026-03-19 MEDIUM 6.5 CVE-2026-31898 jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to… Jspdf 4.2.1+ Fix from $1,6002026-03-18 HIGH 8.8 CVE-2026-21570 This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 1… Bamboo 9.6.24 / 10.2.16+ Fix from $1,9502026-03-17 CRITICAL 9.8 CVE-2025-69902 A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via… Mitigation only Fix from $2,3002026-03-16 HIGH 8.8 CVE-2025-50881 The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET re… Mitigation only Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-30875 Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authen… Chamilo Lms 1.11.36+ Fix from $1,9502026-03-16 HIGH 7.5 CVE-2026-4276 LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries. Librechat Mitigation only Fix from $1,9502026-03-16 HIGH 7.8 CVE-2026-3476 A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code … Solidworks 2026+ Fix from $1,9502026-03-16 MEDIUM 6.4 CVE-2026-32719 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, Th… Anythingllm after 1.11.1 Fix from $1,6002026-03-16 CRITICAL 9.8 CVE-2026-32640 SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modul… Simpleeval 1.0.5+ Fix from $2,3002026-03-16 HIGH 8.8 CVE-2025-14287 A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 16… Mlflow 3.7.0+ Fix from $1,9502026-03-16 HIGH 8.8 CVE-2025-15540 "Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or acc… Raytha 1.4.6+ Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-3910 KEV Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 146.0.7680.75+ Fix from $1,9502026-03-13 HIGH 7.2 CVE-2026-32414 Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion… Mitigation only Fix from $1,9502026-03-13 CRITICAL 9.1 CVE-2026-32367 Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.Th… Mitigation only Fix from $2,3002026-03-13 CRITICAL 9.8 CVE-2026-32304 Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) functi… Locutus 3.0.14+ Fix from $2,3002026-03-13 CRITICAL 10.0 CVE-2026-26954 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox… Sandboxjs 0.8.34+ Fix from $2,3002026-03-13 HIGH 8.8 CVE-2026-25817 HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improp… Mitigation only Fix from $1,9502026-03-13 CRITICAL 9.9 CVE-2026-21669 A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. Veeam Backup \& Replication 13.0.1.2067+ Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2026-21671 A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) de… Veeam Backup \& Replication after 13.0.1.1071 Fix from $2,3002026-03-12 HIGH 8.8 CVE-2026-4039 A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill E… Openclaw 2026.2.21+ Fix from $1,9502026-03-12 MEDIUM 6.3 CVE-2026-3968 A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of … Mitigation only Fix from $1,6002026-03-12