Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-0770 KEVEPSS 63% Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote … Langflow after 1.7.3 Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0769EPSS 38% Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra… Langflow Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0768 Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in… Langflow Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0764 GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Gpt Academic Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0763 GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote a… Gpt Academic Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0761 Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers … Metagpt Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0760 Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote… Metagpt Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0759 Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0756 github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0755 gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2025-15063 Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2025-15061 Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.9 CVE-2026-24304 Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. Azure Resource Manager Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-24132 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 th… Orval 7.20.0 / 8.0.3+ Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-24306 Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. Azure Front Door No fix yet Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24305 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24124 Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below, the Job API endpoints (/api/… Dragonfly 2.4.1+ Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-21227 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile… Azure Logic Apps Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-55705 This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can res… Evmapa Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-54816 This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish con… Evmapa Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24058 Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that all… Soft Serve 0.11.3+ Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2026-20912 Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote… Gitea 1.25.4+ Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2026-20897 Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L… Gitea 1.25.4+ Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2026-20750 Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be ab… Gitea 1.25.4+ Fix from $2,3002026-01-22 CRITICAL 9.4 CVE-2026-1201 An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could a… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-56590 An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute … Html2pdf Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-22278 Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthentica… Powerscale Onefs 9.13.0.0+ Fix from $2,3002026-01-22 CRITICAL 10.0 CVE-2025-69828 File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2025-69312 Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Upload a Web Shell to a Web … Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2025-69101 Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows Authentication Abuse.This iss… Mitigation only Fix from $2,3002026-01-22