Browse vulnerabilities
378,245 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-46442 | High | 36.3% | 9.9 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-34156 | High | 35.0% | 9.9 | NocoBase is an AI-powered no-code/low-code platform for building business applications and… | |
| CVE-2025-56005 | High | 19.1% | 9.8 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote… | |
| CVE-2026-34938 | High | 13.2% | 10.0 | PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praiso… | |
| CVE-2026-35216 | High | 10.7% | 9.0 | Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated … | |
| CVE-2026-33439 | High | 10.0% | 9.8 | Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIde… | |
| CVE-2019-18184 | High | 8.1% | 9.8 | Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharact… | |
| CVE-2026-8985 | High | 6.6% | 9.8 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection … | |
| CVE-2026-62241 | High | 6.5% | 9.1 | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('… | |
| CVE-2026-7854 | High | 5.9% | 9.8 | A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this … | |
| CVE-2026-19586 | High | 5.7% | 9.8 | A pre-authentication OS command injection vulnerability has been identified in Omada gatew… | |
| CVE-2026-0545 | High | 4.4% | 9.8 | In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected… | |
| CVE-2026-45700 | High | 4.4% | 9.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP'… | |
| CVE-2026-61498 | High | 4.1% | 9.8 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in th… | |
| CVE-2018-18861 | High | 4.1% | 9.8 | Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE co… | |
| CVE-2026-39932 | High | 3.7% | 9.1 | OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document categ… | |
| CVE-2015-10138 | High | 3.6% | 9.8 | The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads… | |
| CVE-2026-32625 | High | 2.9% | 9.6 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up… | |
| CVE-2026-25244 | High | 2.8% | 9.8 | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDr… | |
| CVE-2025-15379 | High | 2.4% | 10.0 | A command injection vulnerability exists in MLflow's model serving container initializatio… | |
| CVE-2026-60121 | High | 2.3% | 9.8 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in th… | |
| CVE-2026-57827 | High | 2.3% | 9.8 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.… | |
| CVE-2026-8986 | High | 2.3% | 9.8 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection … | |
| CVE-2026-34243 | High | 2.2% | 9.8 | wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or… | |
| CVE-2026-86426 | High | 2.1% | 9.8 | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API tha… | |
| CVE-2026-33937 | High | 1.7% | 9.8 | Handlebars provides the power necessary to let users build semantic templates. In versions… | |
| CVE-2018-25357 | High | 1.7% | 9.8 | Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthen… | |
| CVE-2024-28056 | High | 1.7% | 9.8 | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM … | |
| CVE-2024-31823 | High | 1.7% | 9.8 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479… | |
| CVE-2026-48687 | High | 1.6% | 9.8 | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability … | |
| CVE-2026-7853 | High | 1.5% | 9.8 | A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function spri… | |
| CVE-2026-27606 | High | 1.5% | 9.8 | Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of… | |
| CVE-2019-25687 | High | 1.4% | 9.8 | Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plu… | |
| CVE-2026-47103 | High | 1.4% | 9.8 | Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerabi… | |
| CVE-2023-27168 | High | 1.3% | 9.8 | An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attack… | |
| CVE-2021-27080 | High | 1.3% | 9.3 | Azure Sphere Unsigned Code Execution Vulnerability | |
| CVE-2026-79657 | High | 1.2% | 9.8 | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted p… | |
| CVE-2026-63294 | High | 1.2% | 9.9 | A link following vulnerability in LXD allows an attacker to achieve root command execution… | |
| CVE-2025-62718 | High | 1.2% | 9.9 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31… | |
| CVE-2026-19931 | High | 1.2% | 9.8 | A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname usi… | |
| CVE-2026-69264 | High | 1.2% | 9.8 | Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFil… | |
| CVE-2025-71338 | High | 1.2% | 10.0 | Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoin… | |
| CVE-2022-31340 | High | 1.1% | 9.8 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax… | |
| CVE-2026-29063 | High | 1.0% | 9.8 | Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, … | |
| CVE-2026-43997 | High | 1.0% | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain th… | |
| CVE-2026-43999 | High | 1.0% | 9.9 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist … | |
| CVE-2026-44007 | High | 1.0% | 9.1 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created wi… | |
| CVE-2026-73487 | High | 1.0% | 9.8 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtab… | |
| CVE-2021-47103 | High | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: inet: fully convert s… | |
| CVE-2016-20052 | High | 1.0% | 9.8 | Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticat… |