Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
HIGH 8.4 CVE-2026-42049 jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest into the generated app/build.gra… Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.9 CVE-2026-48322 ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in… Coldfusion Mitigation only Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-50650 Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. .net Framework 8.0.29 / 9.0.18+ Fix from $1,9502026-07-14 HIGH 7.2 CVE-2026-15410 KEVEPSS 76% Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C… Sma6210 Firmware Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-56185 Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. Windows Admin Center 2511+ Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15702 A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Su… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15697 A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm P… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15698 A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Execu… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15699 A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the … Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15598 A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipula… Mitigation only Fix from $1,6002026-07-13 HIGH 8.8 CVE-2026-55771 CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9… Mitigation only Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-55773 CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.5 CVE-2026-6875EPSS 27% ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an … Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.3 CVE-2026-12257 Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/… Mitigation only Fix from $2,3002026-07-13 CRITICAL 10.0 CVE-2026-57811 Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allo… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.2 CVE-2026-13014 A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrari… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.6 CVE-2026-14453 This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution… Mitigation only Fix from $2,3002026-07-13 MEDIUM 6.3 CVE-2026-15538 A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component AP… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15512 A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the file \pig-master\pig-visual\p… Mitigation only Fix from $1,6002026-07-13 HIGH 7.3 CVE-2026-15497 A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/mai… Mitigation only Fix from $1,9502026-07-12 CRITICAL 10.0 CVE-2026-61447 PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without… Mitigation only Fix from $2,3002026-07-11 HIGH 8.8 CVE-2026-13353 The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all vers… No fix yet Fix from $1,9502026-07-11 CRITICAL 9.1 CVE-2026-61444 PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated int… Mitigation only Fix from $2,3002026-07-10 MEDIUM 6.5 CVE-2026-61450 Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrat… Mitigation only Fix from $1,6002026-07-10 CRITICAL 10.0 CVE-2026-54769 Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape … Mitigation only Fix from $2,3002026-07-10 HIGH 7.8 CVE-2026-59856 Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a… Vim 9.2.0736+ Fix from $1,9502026-07-09 HIGH 7.8 CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the t… Vim 9.2.0735+ Fix from $1,9502026-07-09 HIGH 8.6 CVE-2026-59833 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engin… Patch available Fix from $1,9502026-07-09 CRITICAL 9.1 CVE-2026-59826 Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase di… Metabase 1.58.15.1 / 1.59.12+ Fix from $2,3002026-07-09 MEDIUM 6.3 CVE-2026-15195 A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/… Patch available Fix from $1,6002026-07-09