Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified HIGH 8.8
CVE-2026-52876

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler i…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.3
CVE-2026-52877

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in sr…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-15316

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-18504

fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a req…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-47629

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-63335

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 8.2
CVE-2026-66783

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster ad…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-66793

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions t…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.2
CVE-2026-16139

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation i…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.3
CVE-2026-22072

Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-12128

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to,…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-73845

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19826

A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/Hes…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.2
CVE-2026-73658

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-59109

SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a rece…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49827

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73418

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper i…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-69106

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

No fix yet
Fix from $4,900 2026-08-12
365 Apps MEDIUM 5.5
CVE-2026-70323

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70325

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70316

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70318

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70319

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70320

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70322

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70312

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps HIGH 7.8
CVE-2026-70313

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,900 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70314

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
Power Bi Report Server HIGH 8.8
CVE-2026-65811

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

No fix yet
Fix from $4,900 2026-08-11
Sharepoint Server HIGH 8.1
CVE-2026-63520

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20522+
Fix from $4,900 2026-08-11