Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.5 CVE-2025-69319 Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Code Inje… Mitigation only Fix from $1,9502026-01-22 MEDIUM 5.3 CVE-2025-69001 Improper Control of Generation of Code ('Code Injection') vulnerability in Shahjahan Jewel FluentForm fluentform allows Code Injection.This issue aff… No fix yet Fix from $1,6002026-01-22 CRITICAL 9.0 CVE-2025-68015 Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scan… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2025-67944 Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi… Mitigation only Fix from $2,3002026-01-22 MEDIUM 6.8 CVE-2026-23946 Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions 15.3.11 and below include a … Tendenci 15.3.12+ Fix from $1,6002026-01-22 CRITICAL 9.8 CVE-2026-22807 vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging … Vllm 0.14.0+ Fix from $2,3002026-01-21 CRITICAL 9.6 CVE-2026-22793 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsi… 5ire 0.15.3+ Fix from $2,3002026-01-21 HIGH 8.8 CVE-2021-47770 OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code throug… No fix yet Fix from $1,9502026-01-21 HIGH 7.2 CVE-2021-47778 GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code … Getsimplecms No fix yet Fix from $1,9502026-01-21 CRITICAL 9.8 CVE-2026-20045 KEV A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME… Unified Communications Manager 14su5+ Fix from $2,3002026-01-21 MEDIUM 6.5 CVE-2026-1245 A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values a… Binary Parser 2.3.0+ Fix from $1,6002026-01-20 CRITICAL 9.8 CVE-2025-55423 A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port… N104s R1 Firmware after 12.07.6 Fix from $2,3002026-01-20 HIGH 7.8 CVE-2025-33233 NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. A successful exploit of this … Mitigation only Fix from $1,9502026-01-20 CRITICAL 9.8 CVE-2026-23947 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul… Orval 7.19.0 / 8.0.2+ Fix from $2,3002026-01-20 CRITICAL 9.6 CVE-2026-23852 SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attac… Siyuan 3.5.4+ Fix from $2,3002026-01-19 MEDIUM 5.4 CVE-2026-1151 A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This ma… Mpay after 1.2.4 Fix from $1,6002026-01-19 MEDIUM 5.4 CVE-2026-1147 A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file… Patients Waiting Area Queue Management System Mitigation only Fix from $1,6002026-01-19 MEDIUM 5.4 CVE-2026-1146 A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unkn… Patients Waiting Area Queue Management System Mitigation only Fix from $1,6002026-01-19 MEDIUM 6.1 CVE-2026-1135 A security flaw has been discovered in itsourcecode Society Management System 1.0. This impacts an unknown function of the file /admin/activity.php. … Society Management System No fix yet Fix from $1,6002026-01-19 MEDIUM 6.1 CVE-2026-1134 A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown function of the file /admin/expenses.php. The m… Society Management System No fix yet Fix from $1,6002026-01-19 MEDIUM 6.4 CVE-2026-23733 LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Merma… Mitigation only Fix from $1,6002026-01-18 CRITICAL 9.9 CVE-2026-0863EPSS 9% Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted… N8n after 2.4.2 Fix from $2,3002026-01-18 MEDIUM 5.4 CVE-2026-1049 A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such … Ligerosmart after 6.1.26 Fix from $1,6002026-01-17 MEDIUM 5.4 CVE-2026-1048 A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This m… Ligerosmart after 6.1.26 Fix from $1,6002026-01-17 HIGH 8.8 CVE-2026-23742 Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. Th… Skipper 0.23.0+ Fix from $1,9502026-01-16 HIGH 8.8 CVE-2026-23523EPSS 6% Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can instal… Dive 0.13.0+ Fix from $1,9502026-01-16 HIGH 8.8 CVE-2025-64691 The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges… Process Optimization 2025+ Fix from $1,9502026-01-16 CRITICAL 10.0 CVE-2025-61937 The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” s… Process Optimization 2025+ Fix from $2,3002026-01-16 HIGH 7.2 CVE-2026-23498 Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure … Shopware 6.7.6.1+ Fix from $1,9502026-01-14 CRITICAL 9.8 CVE-2026-22708 Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce… Cursor 2.3+ Fix from $2,3002026-01-14