Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2025-69983 FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-suppl… Fuxa Mitigation only Fix from $2,3002026-02-03 CRITICAL 10.0 CVE-2026-25142 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain proto… Sandboxjs 0.8.27+ Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2020-37052 AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system … Mitigation only Fix from $2,3002026-01-30 HIGH 8.8 CVE-2026-25153 Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDo… Backstage 1.13.11 / 1.14.1+ Fix from $1,9502026-01-30 CRITICAL 9.8 CVE-2026-25141 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7… Orval 7.21.0 / 8.2.0+ Fix from $2,3002026-01-30 HIGH 8.1 CVE-2025-24293 # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transfo… Mitigation only Fix from $1,9502026-01-30 HIGH 7.8 CVE-2025-62348 Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead t… Mitigation only Fix from $1,9502026-01-30 MEDIUM 5.4 CVE-2026-1700 A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.p… House Rental And Property Listing Project No fix yet Fix from $1,6002026-01-30 CRITICAL 9.8 CVE-2026-1281 KEVEPSS 82% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.5.0.0 Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1340 KEVEPSS 86% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.7.0.0 Fix from $2,3002026-01-29 HIGH 8.8 CVE-2026-24780 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.44+ Fix from $1,9502026-01-29 MEDIUM 5.4 CVE-2026-1598 A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknown function of the file /dashb… Bhojon after 2026-01-16 Fix from $1,6002026-01-29 HIGH 8.8 CVE-2026-24897 Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files… Erugo after 0.2.14 Fix from $1,9502026-01-28 HIGH 8.8 CVE-2025-69517 An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject arbitrary HTML content during t… Mitigation only Fix from $1,9502026-01-28 HIGH 7.8 CVE-2025-57283 The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly san… Browserstack Local Mitigation only Fix from $1,9502026-01-28 CRITICAL 10.0 CVE-2026-23830 SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated … Sandboxjs 0.8.26+ Fix from $2,3002026-01-28 HIGH 8.8 CVE-2026-24747 PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows a… Pytorch 2.10.0+ Fix from $1,9502026-01-27 CRITICAL 9.8 CVE-2025-69564 code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password,… Mobile Shop Management System Mitigation only Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24871 Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Mana… Patch available Fix from $2,3002026-01-27 MEDIUM 5.3 CVE-2026-24806 Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org… Patch available Fix from $1,6002026-01-27 CRITICAL 10.0 CVE-2026-22709 vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitizatio… Vm2 3.10.2+ Fix from $2,3002026-01-26 MEDIUM 5.4 CVE-2026-1421 A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the component Add Pages. Such manip… Online Examination System No fix yet Fix from $1,6002026-01-26 MEDIUM 5.3 CVE-2026-24474 Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a, `use_an… Patch available Fix from $1,6002026-01-24 HIGH 7.3 CVE-2024-11976 The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to t… Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2025-67847 A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to in… Moodle 4.1.22 / 4.4.12+ Fix from $1,9502026-01-23 HIGH 7.1 CVE-2026-0771 Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a… Langflow Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0766EPSS 27% Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… Open Webui Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.8 CVE-2026-0768 Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… Langflow Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0761 Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers … Metagpt Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-24132 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 th… Orval 7.20.0 / 8.0.3+ Fix from $2,3002026-01-23