Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2020-37186 Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration ins… Mitigation only Fix from $2,3002026-02-11 HIGH 7.5 CVE-2020-37178 KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vu… No fix yet Fix from $1,9502026-02-11 CRITICAL 9.8 CVE-2025-69872 DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can … Mitigation only Fix from $2,3002026-02-11 HIGH 7.0 CVE-2026-1226 CWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintended code within the application… Mitigation only Fix from $1,9502026-02-11 HIGH 8.8 CVE-2026-1560EPSS 9% The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via mu… Mitigation only Fix from $1,9502026-02-11 HIGH 7.2 CVE-2025-14541 The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.22 via the conditional… Mitigation only Fix from $1,9502026-02-11 HIGH 8.8 CVE-2026-21537 Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adj… Defender For Endpoint Mitigation only Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-21256 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack… Visual Studio 2022 17.14.26+ Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-25807 ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing featu… Zai Shell 9.0.3+ Fix from $1,9502026-02-09 MEDIUM 5.4 CVE-2026-2224 A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users… Online Reviewer System No fix yet Fix from $1,6002026-02-09 CRITICAL 9.8 CVE-2026-1615 Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions… Patch available Fix from $2,3002026-02-09 MEDIUM 5.4 CVE-2026-2201 A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLea… Studentmanager No fix yet Fix from $1,6002026-02-09 MEDIUM 6.1 CVE-2026-2160 A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of… Simple Responsive Tourism Website No fix yet Fix from $1,6002026-02-08 MEDIUM 6.1 CVE-2026-2159 A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.ph… Simple Responsive Tourism Website No fix yet Fix from $1,6002026-02-08 MEDIUM 6.1 CVE-2026-2154 A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impacted is an unknown function of … Patients Waiting Area Queue Management System No fix yet Fix from $1,6002026-02-08 MEDIUM 6.1 CVE-2026-2150 A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown funct… Patients Waiting Area Queue Management System No fix yet Fix from $1,6002026-02-08 MEDIUM 6.1 CVE-2026-2149 A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an … Patients Waiting Area Queue Management System No fix yet Fix from $1,6002026-02-08 MEDIUM 5.4 CVE-2026-2145 A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of th… Nginxwebui after 4.3.7 Fix from $1,6002026-02-08 HIGH 7.8 CVE-2026-25636 calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corru… Calibre 9.2.0+ Fix from $1,9502026-02-06 MEDIUM 5.4 CVE-2026-2064 A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/me… I Educar after 2.10.0 Fix from $1,6002026-02-06 CRITICAL 10.0 CVE-2026-25587 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By over… Sandboxjs 0.8.29+ Fix from $2,3002026-02-06 HIGH 8.8 CVE-2026-2008 A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability affects the function eqn_char… Fermat after 2025-10-08 Fix from $1,9502026-02-06 MEDIUM 6.3 CVE-2026-1977 A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vul… Mitigation only Fix from $1,6002026-02-06 HIGH 7.2 CVE-2025-70073 An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function Chestnutcms after 1.5.8 Fix from $1,9502026-02-05 CRITICAL 9.8 CVE-2020-37137 PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code … Phpfusion Mitigation only Fix from $2,3002026-02-05 HIGH 8.6 CVE-2025-61732 A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. Go 1.24.13 / 1.25.7+ Fix from $1,9502026-02-05 CRITICAL 9.6 CVE-2026-25481 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-4… Langroid 0.59.32+ Fix from $2,3002026-02-04 HIGH 8.8 CVE-2026-25510 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.28.5.0+ Fix from $1,9502026-02-03 HIGH 8.8 CVE-2026-24887 Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirm… Claude Code 2.0.72+ Fix from $1,9502026-02-03 HIGH 7.8 CVE-2026-24149 NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection iss… Mitigation only Fix from $1,9502026-02-03