Vulnerability index

Browse CVEs

6,021 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.0 CVE-2026-59216 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and ex… Open Webui 0.10.0+ Fix from $2,3002026-07-09 CRITICAL 9.8 CVE-2026-52200 An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint … Mitigation only Fix from $2,3002026-07-08 MEDIUM 6.5 CVE-2026-35211 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exp… Opencti 7.260401.0+ Fix from $1,6002026-07-08 HIGH 7.2 CVE-2026-59821 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails produc… Litellm 1.82.0+ Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-53951 Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_setti… Mitigation only Fix from $1,9502026-07-08 HIGH 8.4 CVE-2026-55408 Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files becau… Mitigation only Fix from $1,9502026-07-07 HIGH 8.5 CVE-2026-53511 calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by cali… Patch available Fix from $1,9502026-07-07 HIGH 8.7 CVE-2026-53751 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with spe… Patch available Fix from $1,9502026-07-07 HIGH 8.9 CVE-2026-43921 FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOS… Mitigation only Fix from $1,9502026-07-06 CRITICAL 10.0 CVE-2026-57572 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra… Crawl4ai 0.9.0+ Fix from $2,3002026-07-06 CRITICAL 9.9 CVE-2026-48614 An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in … Mitigation only Fix from $2,3002026-07-06 HIGH 7.3 CVE-2026-14749 A vulnerability was identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. Impacted is the function eval of the file appli… Mitigation only Fix from $1,9502026-07-05 HIGH 7.3 CVE-2026-14722 A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impacts an unknown function of the file src/services/wiki/wikiWorker/load… Mitigation only Fix from $1,9502026-07-05 MEDIUM 6.3 CVE-2026-14691 A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_sett… Mitigation only Fix from $1,6002026-07-05 HIGH 7.8 CVE-2026-12252 In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyPar… Nltk after 3.9.3 Fix from $1,9502026-07-04 MEDIUM 5.4 CVE-2026-11778 The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in a… Mitigation only Fix from $1,6002026-07-03 CRITICAL 10.0 CVE-2026-57624 Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.1 CVE-2026-27436 Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. Mitigation only Fix from $2,3002026-07-02 HIGH 8.7 CVE-2026-55794 Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can… Patch available Fix from $1,9502026-07-02 CRITICAL 9.4 CVE-2026-14439 A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence … Mitigation only Fix from $2,3002026-07-01 HIGH 8.8 CVE-2026-14407 Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-14383 Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 150.0.7871.46+ Fix from $1,9502026-07-01 HIGH 7.8 CVE-2026-54074 Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-T… Mitigation only Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-58454 JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that allows authenticated attacker… Mitigation only Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-8857 A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Ph… Mediawiki 1.43.9 / 1.44.6+ Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-58025 Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Imp… Mediawiki 1.43.9 / 1.44.6+ Fix from $2,3002026-07-01 HIGH 7.8 CVE-2026-24248 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of … Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 HIGH 7.8 CVE-2026-24249 NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of th… Nemo Megatron Bridge 0.4.1+ Fix from $1,9502026-07-01 MEDIUM 6.1 CVE-2026-56264 Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and exe… Crawl4ai 0.8.7+ Fix from $1,6002026-06-30 CRITICAL 9.8 CVE-2026-58449 txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver… Patch available Fix from $2,3002026-06-30