Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.8 CVE-2026-17633 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-17632 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-17624 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, … Langflow 1.11.0+ Fix from $1,9502026-08-05 MEDIUM 5.7 CVE-2026-70609 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-70431 Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowin… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-71278 rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. Th… No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-46581 In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing a… Mojarra after 4.1.13 Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-71235 Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. T… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-71232 MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex… No fix yet Fix from $1,9502026-08-05 HIGH 7.7 CVE-2026-51401 An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/sr… No fix yet Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-70553 MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application co… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.5 CVE-2026-70477 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using … No fix yet Fix from $2,3002026-08-04 HIGH 8.4 CVE-2026-47781 PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plu… No fix yet Fix from $1,9502026-08-04 CRITICAL 9.4 CVE-2026-69264 Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.4 CVE-2026-69259 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/c… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.2 CVE-2026-69255 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/ag… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.4 CVE-2026-69256 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide P… No fix yet Fix from $2,3002026-08-04 CRITICAL 10.0 CVE-2026-64633 A vulnerability allowing remote unauthenticated code execution on the agent host. No fix yet Fix from $2,3002026-08-04 HIGH 8.6 CVE-2026-58074 A vulnerability allowing a high-privileged user to execute arbitrary code on the server. No fix yet Fix from $1,9502026-08-04 CRITICAL 9.4 CVE-2026-69254 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-prov… No fix yet Fix from $2,3002026-08-04 HIGH 8.8 CVE-2026-69100 LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes u… No fix yet Fix from $1,9502026-08-04 CRITICAL 9.0 CVE-2026-69251 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory node… No fix yet Fix from $2,3002026-08-04 HIGH 7.3 CVE-2026-18770 A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /c… No fix yet Fix from $1,9502026-08-04 HIGH 8.0 CVE-2026-16623 The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, al… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.1 CVE-2026-65804 Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over… Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 CRITICAL 9.6 CVE-2026-18667 A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sens… No fix yet Fix from $2,3002026-08-03 HIGH 8.4 CVE-2026-66065 Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions … No fix yet Fix from $1,9502026-08-03 HIGH 7.2 CVE-2026-61523 WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arb… No fix yet Fix from $1,9502026-08-03 HIGH 8.1 CVE-2026-69088 Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives bec… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-67340 ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor … Mitigation only Fix from $2,3002026-08-01