Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.7 CVE-2026-47869 VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and… No fix yet Fix from $1,9502026-07-18 CRITICAL 9.9 CVE-2026-8635 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute a… Langflow 1.10.1+ Fix from $2,3002026-07-17 HIGH 8.8 CVE-2026-8056 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw ex… Langflow 1.10.1+ Fix from $1,9502026-07-17 CRITICAL 9.9 CVE-2026-8481 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/va… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.1 CVE-2026-52199 An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component Mitigation only Fix from $2,3002026-07-17 CRITICAL 9.9 CVE-2026-9135 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulner… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9198 KEVEPSS 17% IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit… Langflow 1.10.1+ Fix from $2,3002026-07-17 HIGH 7.8 CVE-2026-9762 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. Db2 12.1.5+ Fix from $1,9502026-07-17 MEDIUM 6.3 CVE-2026-16008 A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the fi… No fix yet Fix from $1,6002026-07-17 CRITICAL 9.9 CVE-2026-46512 Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, de… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-46621 Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated us… Yamcs 5.12.7+ Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-44632 Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine or… Yamcs 5.12.7+ Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-46562 Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-cor… Yamcs 5.12.7+ Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-59865 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.d… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-59866 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceNa… No fix yet Fix from $2,3002026-07-16 HIGH 8.7 CVE-2026-53597 Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/t… No fix yet Fix from $1,9502026-07-16 HIGH 8.7 CVE-2026-59859 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields,… No fix yet Fix from $1,9502026-07-16 HIGH 8.7 CVE-2026-59860 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in t… Mitigation only Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-59861 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property na… No fix yet Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-59862 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descrip… No fix yet Fix from $1,9502026-07-16 HIGH 8.8 CVE-2026-55576 MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inline… Mitigation only Fix from $1,9502026-07-15 CRITICAL 9.8 CVE-2026-30618 xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker … Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.0 CVE-2026-45534 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-control… Mitigation only Fix from $2,3002026-07-15 HIGH 7.2 CVE-2026-62350 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could … Mitigation only Fix from $1,9502026-07-15 HIGH 8.4 CVE-2026-61446 PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Py… Mitigation only Fix from $1,9502026-07-15 HIGH 7.8 CVE-2026-61433 PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inje… Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-58655 The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. … Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-46640 Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute syntax can concatenate an attacker… Twig 3.26.0+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-46633 Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is p… Twig 3.26.0+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-38450 An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of… Mitigation only Fix from $2,3002026-07-14