Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.5 CVE-2026-65660 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a net… Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 HIGH 8.4 CVE-2026-73076 Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-19546 A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mit… No fix yet Fix from $4,9002026-08-11 HIGH 8.7 CVE-2026-72765 n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create … No fix yet Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-58231 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain function… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.1 CVE-2026-44758 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected fu… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.3 CVE-2026-72904 Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in … No fix yet Fix from $5,7502026-08-10 MEDIUM 5.5 CVE-2026-18942 A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by … No fix yet Fix from $4,0002026-08-10 HIGH 8.8 CVE-2026-66738 SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-type… No fix yet Fix from $4,9002026-08-10 HIGH 7.0 CVE-2026-72718 goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather t… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.8 CVE-2026-42537 Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-44416 Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-55799 Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 10.0 CVE-2026-66915 Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the aja… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.6 CVE-2026-46409 OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des… No fix yet Fix from $2,3002026-08-07 HIGH 8.7 CVE-2026-17603 Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A us… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-50159 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulne… No fix yet Fix from $1,6002026-08-06 HIGH 8.8 CVE-2026-48054 OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to … No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-19060 A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. … No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-19058 A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.1 CVE-2026-66709 Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 10.0 CVE-2026-65553 Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.9 CVE-2026-65548 Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.3 CVE-2026-67531 FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host … No fix yet Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-71319 Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channe… No fix yet Fix from $2,3002026-08-05 HIGH 8.1 CVE-2026-71320 Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nux… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-55522 PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-9196 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to imp… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-8478 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-8182 IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via … Langflow 1.11.0+ Fix from $1,9502026-08-05