Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.1 CVE-2026-16144 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin… No fix yet Fix from $1,9502026-08-01 CRITICAL 9.8 CVE-2026-68770 sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logi… Mitigation only Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-51785 An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request No fix yet Fix from $2,3002026-07-31 HIGH 8.1 CVE-2026-53510 Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby so… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-17561 Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign… No fix yet Fix from $2,3002026-07-31 HIGH 7.2 CVE-2026-13392 The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative cap… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.9 CVE-2026-12946 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input… Langflow 1.10.1+ Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-61536 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered… No fix yet Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-18245 Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrar… Amplify Codegen Ui 2.20.6+ Fix from $1,9502026-07-30 CRITICAL 9.9 CVE-2026-13435 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. Langflow 1.10.2+ Fix from $2,3002026-07-30 CRITICAL 9.0 CVE-2026-14602 The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attack… No fix yet Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-17922 Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a crafted … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.3 CVE-2026-54661 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-ht… No fix yet Fix from $1,9502026-07-29 HIGH 8.3 CVE-2026-54662 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfi… No fix yet Fix from $1,9502026-07-29 HIGH 8.3 CVE-2026-54664 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parser… No fix yet Fix from $1,9502026-07-29 HIGH 8.3 CVE-2026-54666 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts p… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2026-14900 The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-13423 The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which … No fix yet Fix from $2,3002026-07-29 HIGH 7.5 CVE-2026-55415 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.64.0+ Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-54653 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.60.2+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-54654 datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is r… No fix yet Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-54655 datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel… No fix yet Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-54656 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.60.2+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-54621 datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_cod… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-66745 Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated at… No fix yet Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-66748 Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage p… Mitigation only Fix from $1,9502026-07-28 CRITICAL 10.0 CVE-2026-65880 Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code exec… No fix yet Fix from $2,3002026-07-28 HIGH 8.8 CVE-2026-56747 Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker … No fix yet Fix from $1,9502026-07-27 CRITICAL 9.0 CVE-2026-14289 The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection i… No fix yet Fix from $2,3002026-07-27 HIGH 7.5 CVE-2026-63720 datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve r… No fix yet Fix from $1,9502026-07-26