Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Workbench MEDIUM 6.1
CVE-2026-34951

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0…

Fix: 65.0.0+
Fix from $1,600 2026-04-06
Marketing Cloud Engagement CRITICAL 9.8
CVE-2026-22583

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPages…

Fix: 2026-01-21+
Fix from $2,300 2026-01-24
Marketing Cloud Engagement CRITICAL 9.8
CVE-2026-22585

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Cen…

Fix: 2026-01-21+
Fix from $2,300 2026-01-24
Marketing Cloud Engagement CRITICAL 9.8
CVE-2026-22586

Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Ce…

Fix: 2026-01-21+
Fix from $2,300 2026-01-24
Marketing Cloud Engagement CRITICAL 9.8
CVE-2026-22582

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeU…

Fix: 2026-01-21+
Fix from $2,300 2026-01-24
Uni2ts CRITICAL 9.8
CVE-2026-22584

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code…

Fix: 2.0.0+
Fix from $2,300 2026-01-09
Agentforce Vibes MEDIUM 6.5
CVE-2025-64320

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affec…

Fix: 3.2.0+
Fix from $1,600 2025-11-04
Mulesoft Anypoint Code Builder MEDIUM 5.3
CVE-2025-64318

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Conf…

Fix: 1.12.1+
Fix from $1,600 2025-11-04
Mulesoft Anypoint Code Builder MEDIUM 5.3
CVE-2025-64319

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Config…

Fix: 1.12.1+
Fix from $1,600 2025-11-04
Agentforce Vibes MEDIUM 5.3
CVE-2025-64321

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configur…

Fix: 3.3.0+
Fix from $1,600 2025-11-04
Agentforce Vibes MEDIUM 5.3
CVE-2025-64322

Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configurat…

Fix: 3.3.0+
Fix from $1,600 2025-11-04
Mulesoft Anypoint Code Builder MEDIUM 6.5
CVE-2025-10875

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue a…

Fix: 1.11.6+
Fix from $1,600 2025-11-04
Tough Cookie CRITICAL 9.8
CVE-2023-26136

Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in r…

Fix: 4.1.3+
Fix from $2,300 2023-07-01
Mobile Software Development Kit CRITICAL 9.8
CVE-2016-15012

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in forcedotcom SalesforceMobileSDK-Windows up to 4.x. It has been rated as critical. This i…

Fix: 5.0.0+
Fix from $2,300 2023-01-07
Mule HIGH 7.5
CVE-2021-1630

XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pi…

Fix: 4.3.0+
Fix from $1,950 2021-08-05
Mule CRITICAL 9.8
CVE-2021-1626

MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and o…

Fix: after 4.2.2
Fix from $2,300 2021-03-26
Mule CRITICAL 9.8
CVE-2021-1627

MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub…

Fix: after 4.2.2
Fix from $2,300 2021-03-26
Mule CRITICAL 9.8
CVE-2021-1628

MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub a…

Fix: after 4.2.2
Fix from $2,300 2021-03-26
Tough Cookie HIGH 7.5
CVE-2017-15010

A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make a…

Fix: after 2.3.2
Fix from $1,950 2017-10-04