Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.2 CVE-2026-25887 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1… Chartbrew 4.8.1+ Fix from $1,9502026-03-06 HIGH 8.8 CVE-2026-25888 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1… Chartbrew 4.8.1+ Fix from $1,9502026-03-06 HIGH 8.8 CVE-2025-70995 An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation… Mitigation only Fix from $1,9502026-03-05 HIGH 8.5 CVE-2026-28134 Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue af… Mitigation only Fix from $1,9502026-03-05 CRITICAL 9.0 CVE-2026-27984 Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This is… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2026-22390 Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allo… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-28783 Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerou… Craft Cms 4.17.0 / 5.9.0+ Fix from $2,3002026-03-04 HIGH 8.1 CVE-2026-23808 A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled… Arubaos after 10.7.2.2 Fix from $1,9502026-03-04 HIGH 7.8 CVE-2025-70341 Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files. App Auto Patch after 3.4.2 Fix from $1,9502026-03-04 HIGH 8.8 CVE-2024-55022 Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name paramet… Easyweb Mitigation only Fix from $1,9502026-03-03 HIGH 8.8 CVE-2023-31044 An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functio… Impact Mobile after 23 Fix from $1,9502026-03-03 CRITICAL 9.8 CVE-2025-59059 Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to… Ranger 2.8.0+ Fix from $2,3002026-03-03 HIGH 8.8 CVE-2026-21853 AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerabi… Affine 0.25.4+ Fix from $1,9502026-03-02 HIGH 8.8 CVE-2026-3132 The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via t… Mitigation only Fix from $1,9502026-03-02 CRITICAL 9.8 CVE-2026-24105 An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a … Ac15 Firmware Mitigation only Fix from $2,3002026-03-02 HIGH 7.2 CVE-2026-26699 sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php. Personnel Property Equipment System No fix yet Fix from $1,9502026-03-02 CRITICAL 9.8 CVE-2026-26720 An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module. Twenty after 1.15.0 Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-24107 An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`… W20e Firmware Mitigation only Fix from $2,3002026-03-02 MEDIUM 6.1 CVE-2026-3412 A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file /att_single_view.php. The man… University Management System No fix yet Fix from $1,6002026-03-02 HIGH 7.3 CVE-2026-3409 A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the fi… Mitigation only Fix from $1,9502026-03-02 CRITICAL 9.8 CVE-2026-3395 A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe… Maxsite Cms 109.2+ Fix from $2,3002026-03-01 HIGH 8.0 CVE-2026-28425 Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with… Statamic 5.73.11 / 6.4.0+ Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-21656 Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21657 Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21658 Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls … Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 MEDIUM 6.1 CVE-2026-3302 A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown functionality of the file /reg… Doctor Appointment System No fix yet Fix from $1,6002026-02-27 HIGH 7.8 CVE-2026-26682 An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java component Fastcms 0.1.6+ Fix from $1,9502026-02-26 CRITICAL 9.8 CVE-2026-27966EPSS 34% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allo… Langflow 1.8.0+ Fix from $2,3002026-02-26 CRITICAL 9.9 CVE-2026-27952 Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom cod… Agenta 0.48.1+ Fix from $2,3002026-02-26 HIGH 8.0 CVE-2026-27830 c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instanc… Patch available Fix from $1,9502026-02-26