Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 5.4 CVE-2025-15583 A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file utility/function.php. Executing … E Commerce No fix yet Fix from $1,6002026-02-20 CRITICAL 9.9 CVE-2025-67979 Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows … Mitigation only Fix from $2,3002026-02-20 HIGH 7.7 CVE-2025-52744 Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Inpersttion For Theme err-our-team allows Code Injection.This … No fix yet Fix from $1,9502026-02-20 CRITICAL 9.9 CVE-2026-26030 Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t… Semantic Kernel 1.39.4+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-71243EPSS 5% The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. … Saisies 5.11.1+ Fix from $2,3002026-02-19 HIGH 8.8 CVE-2026-25755 jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject ar… Jspdf 4.2.0+ Fix from $1,9502026-02-19 CRITICAL 9.1 CVE-2026-25548 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil… Invoiceplane 1.7.1+ Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-27174EPSS 7% MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in… Majordomo Patch available Fix from $2,3002026-02-18 HIGH 8.8 CVE-2025-14009 A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py… Nltk 3.9.3+ Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-61982 An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A specially crafted OpenFOAM si… Mitigation only Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-33250 NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might … Nemo 2.6.1+ Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-33251 NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might … Nemo 2.6.1+ Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-33236 NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit of this v… Nemo 2.6.1+ Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-33239 NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection. A successful exploit … Nemo Megatron Bridge 0.2.2+ Fix from $1,9502026-02-18 HIGH 7.8 CVE-2025-33240 NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection. A successful exploi… Nemo Megatron Bridge 0.2.2+ Fix from $1,9502026-02-18 HIGH 7.2 CVE-2026-2296 The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, a… Mitigation only Fix from $1,9502026-02-18 MEDIUM 5.4 CVE-2026-2622 A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blossom-backend/backend/src/main/ja… Blossom after 1.17.1 Fix from $1,6002026-02-17 CRITICAL 9.9 CVE-2025-70830 A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execu… Mitigation only Fix from $2,3002026-02-17 HIGH 7.8 CVE-2025-65715 An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when … Coderunner No fix yet Fix from $1,9502026-02-16 HIGH 8.8 CVE-2025-65716 An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md fi… Markdown Preview Enhanced No fix yet Fix from $1,9502026-02-16 MEDIUM 5.4 CVE-2026-2557 A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller/resource/MediaController.jav… Cskefu after 8.0.1 Fix from $1,6002026-02-16 MEDIUM 6.1 CVE-2026-2546 A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such … Ligerosmart after 6.1.26 Fix from $1,6002026-02-16 MEDIUM 6.1 CVE-2026-2547 A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing … Ligerosmart after 6.1.26 Fix from $1,6002026-02-16 MEDIUM 6.1 CVE-2026-2545 A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This… Ligerosmart after 6.1.26 Fix from $1,6002026-02-16 HIGH 7.3 CVE-2025-33042 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro … Avro 1.11.5+ Fix from $1,9502026-02-13 HIGH 8.8 CVE-2026-26056 Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (A… Yoke after 0.19.0 Fix from $1,9502026-02-12 HIGH 7.2 CVE-2026-25227 authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User t… Authentik 2025.8.6 / 2025.10.4+ Fix from $1,9502026-02-12 HIGH 7.8 CVE-2025-63421 An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file No fix yet Fix from $1,9502026-02-12 CRITICAL 10.0 CVE-2026-26216 Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks para… Crawl4ai 0.8.0+ Fix from $2,3002026-02-12 HIGH 8.8 CVE-2026-0969 The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX conte… Mitigation only Fix from $1,9502026-02-12