Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-34951 Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0… Workbench 65.0.0+ Fix from $1,6002026-04-06 CRITICAL 9.8 CVE-2026-22583 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPages… Marketing Cloud Engagement 2026-01-21+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2026-22585 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Cen… Marketing Cloud Engagement 2026-01-21+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2026-22586 Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Ce… Marketing Cloud Engagement 2026-01-21+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2026-22582 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeU… Marketing Cloud Engagement 2026-01-21+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2026-22584 Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code… Uni2ts 2.0.0+ Fix from $2,3002026-01-09 MEDIUM 6.5 CVE-2025-64320 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affec… Agentforce Vibes 3.2.0+ Fix from $1,6002025-11-04 MEDIUM 5.3 CVE-2025-64318 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Conf… Mulesoft Anypoint Code Builder 1.12.1+ Fix from $1,6002025-11-04 MEDIUM 5.3 CVE-2025-64319 Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Config… Mulesoft Anypoint Code Builder 1.12.1+ Fix from $1,6002025-11-04 MEDIUM 5.3 CVE-2025-64321 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configur… Agentforce Vibes 3.3.0+ Fix from $1,6002025-11-04 MEDIUM 5.3 CVE-2025-64322 Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configurat… Agentforce Vibes 3.3.0+ Fix from $1,6002025-11-04 MEDIUM 6.5 CVE-2025-10875 Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue a… Mulesoft Anypoint Code Builder 1.11.6+ Fix from $1,6002025-11-04 CRITICAL 9.8 CVE-2023-26136 Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in r… Tough Cookie 4.1.3+ Fix from $2,3002023-07-01 CRITICAL 9.8 CVE-2016-15012 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in forcedotcom SalesforceMobileSDK-Windows up to 4.x. It has been rated as critical. This i… Mobile Software Development Kit 5.0.0+ Fix from $2,3002023-01-07 HIGH 7.5 CVE-2021-1630 XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pi… Mule 4.3.0+ Fix from $1,9502021-08-05 CRITICAL 9.8 CVE-2021-1626 MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and o… Mule after 4.2.2 Fix from $2,3002021-03-26 CRITICAL 9.8 CVE-2021-1627 MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub… Mule after 4.2.2 Fix from $2,3002021-03-26 CRITICAL 9.8 CVE-2021-1628 MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub a… Mule after 4.2.2 Fix from $2,3002021-03-26 HIGH 7.5 CVE-2017-15010 A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make a… Tough Cookie after 2.3.2 Fix from $1,9502017-10-04