Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 10.0 CVE-2026-22686 Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in… Enclave 2.7.0+ Fix from $2,3002026-01-14 HIGH 7.2 CVE-2022-50806 4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template … 4images No fix yet Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2026-22869 Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution fr… Eigent 0.0.78+ Fix from $2,3002026-01-13 HIGH 8.8 CVE-2025-41717 An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to cod… Mitigation only Fix from $1,9502026-01-13 HIGH 7.2 CVE-2026-0498 SAP S/4HANA (Private Cloud and On-Premise) allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC… S\/4 Hana Patch available Fix from $1,9502026-01-13 HIGH 8.8 CVE-2026-0500 Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could creat… Introscope Enterprise Manager Patch available Fix from $1,9502026-01-13 CRITICAL 9.1 CVE-2026-0491 SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw en… Mitigation only Fix from $2,3002026-01-13 HIGH 8.8 CVE-2026-22771 Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, E… Gateway 1.5.7 / 1.6.2+ Fix from $1,9502026-01-12 CRITICAL 9.8 CVE-2026-22584 Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code… Uni2ts 2.0.0+ Fix from $2,3002026-01-09 CRITICAL 9.3 CVE-2020-36875 AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The pl… Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.8 CVE-2025-66913 JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacke… Jimureport after 2.1.3 Fix from $2,3002026-01-08 CRITICAL 9.4 CVE-2025-66916 The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expres… Ruoyi Vue Plus after 5.5.1 Fix from $2,3002026-01-08 HIGH 7.2 CVE-2026-22244 OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SST… Openmetadata 1.11.4+ Fix from $1,9502026-01-08 CRITICAL 9.9 CVE-2026-21877EPSS 5% n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us… N8n 1.121.3+ Fix from $2,3002026-01-08 HIGH 7.8 CVE-2025-69262 pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .np… Pnpm 10.27.0+ Fix from $1,9502026-01-07 MEDIUM 6.1 CVE-2026-0642 A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/comp… House Rental And Property Listing Project No fix yet Fix from $1,6002026-01-07 MEDIUM 5.0 CVE-2024-14020 A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/… Patch available Fix from $1,6002026-01-07 CRITICAL 9.6 CVE-2025-55204 muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in.… Muffon 2.3.0+ Fix from $2,3002026-01-05 MEDIUM 6.1 CVE-2026-0588 A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functionality of the file rockfun.p… Rockoa after 2.7.1 Fix from $1,6002026-01-05 MEDIUM 6.1 CVE-2026-0586 A vulnerability was detected in code-projects Online Product Reservation System 1.0. The affected element is an unknown function of the file handgunn… Online Product Reservation System No fix yet Fix from $1,6002026-01-05 MEDIUM 5.4 CVE-2026-0587 A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file rock_page_gong.php of the compo… Rockoa after 2.7.1 Fix from $1,6002026-01-05 MEDIUM 6.1 CVE-2026-0580 A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Impo… Api Key Manager App Mitigation only Fix from $1,6002026-01-05 CRITICAL 9.8 CVE-2025-11837 An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulner… Malware Remover 6.6.8.20251023+ Fix from $2,3002026-01-02 MEDIUM 5.4 CVE-2025-15437 A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manip… Ligerosmart after 6.1.24 Fix from $1,6002026-01-02 MEDIUM 5.4 CVE-2025-15416 A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Var… Wangmarket after 6.4 Fix from $1,6002026-01-01 HIGH 7.2 CVE-2025-68619 Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators… Signal K Server 2.19.0+ Fix from $1,9502026-01-01 HIGH 8.8 CVE-2025-15393 A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/… Kodicms after 13.82.135 Fix from $1,9502025-12-31 HIGH 7.2 CVE-2025-15394 A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parame… Icms after 8.0.0 Fix from $1,9502025-12-31 MEDIUM 5.4 CVE-2025-15374 A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the co… Eyoucms 1.7.8+ Fix from $1,6002025-12-31 MEDIUM 6.1 CVE-2025-15223 A vulnerability was found in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. Impacted is an unknown function of the file /… Simple Php Blog after 2025-01-22 Fix from $1,6002025-12-31