Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 7.2 CVE-2026-65693 Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary O… No fix yet Fix from $1,9502026-07-24 HIGH 8.8 CVE-2026-16801 Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an… Powershell Universal 2026.2.3.0+ Fix from $1,9502026-07-24 HIGH 8.8 CVE-2026-16800 Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an … Powershell Universal 2026.2.3.0+ Fix from $1,9502026-07-24 CRITICAL 10.0 CVE-2025-71389 Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Serv… No fix yet Fix from $2,3002026-07-23 HIGH 7.8 CVE-2026-60122 gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who cont… No fix yet Fix from $1,9502026-07-23 HIGH 8.7 CVE-2026-47722 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86… No fix yet Fix from $1,9502026-07-23 CRITICAL 10.0 CVE-2026-47668 DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut… No fix yet Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-65906 In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible Teamcity 2025.11.6 / 2026.1.2+ Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-65907 In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-64815 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files Intellij Idea 2026.2+ Fix from $2,3002026-07-23 HIGH 7.8 CVE-2026-64802 In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration Goland 2026.2+ Fix from $1,9502026-07-23 HIGH 7.8 CVE-2026-64803 In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK Goland 2026.2+ Fix from $1,9502026-07-23 CRITICAL 9.9 CVE-2026-59543 Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15011 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, an… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-16606 A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote … No fix yet Fix from $2,3002026-07-22 MEDIUM 6.5 CVE-2025-13146 The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ… No fix yet Fix from $1,6002026-07-22 CRITICAL 9.8 CVE-2026-8984 Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafte… Maxicharger Single Charger Firmware after 1.03.51 Fix from $2,3002026-07-21 HIGH 8.9 CVE-2026-43945 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to ach… Mitigation only Fix from $1,9502026-07-21 HIGH 8.0 CVE-2026-21575 This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. T… Sourcetree 3.4.13+ Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-47398 PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALL… No fix yet Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-65008 Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), w… No fix yet Fix from $2,3002026-07-21 MEDIUM 6.9 CVE-2026-51385 An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fet… No fix yet Fix from $1,6002026-07-20 CRITICAL 9.8 CVE-2026-52656 An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary … No fix yet Fix from $2,3002026-07-20 HIGH 8.9 CVE-2026-60026 Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vul… No fix yet Fix from $1,9502026-07-20 CRITICAL 10.0 CVE-2026-44359 Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow i… No fix yet Fix from $2,3002026-07-20 MEDIUM 6.3 CVE-2026-16204 A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.3 CVE-2026-16151 A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation … No fix yet Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2026-16150 A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliase… No fix yet Fix from $1,6002026-07-18 HIGH 7.8 CVE-2026-9147 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled stre… No fix yet Fix from $1,9502026-07-18 HIGH 8.7 CVE-2026-47867 VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control p… Mitigation only Fix from $1,9502026-07-18