Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 1607 HIGH 7.5
CVE-2026-50328

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15757

A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the…

No fix yet
Fix from $1,600 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55899

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
Jetty MEDIUM 5.3
CVE-2026-6790

In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided i…

Fix: 9.4.61 / 10.0.29+
Fix from $1,600 2026-07-14
Kuksa MEDIUM 6.5
CVE-2026-13699

In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point …

No fix yet
Fix from $1,600 2026-07-14
Unclassified CRITICAL 9.3
CVE-2026-22102

A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified MEDIUM 5.3
CVE-2026-15531

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function…

Patch available
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15535

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.d…

Patch available
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15529

A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py…

Patch available
Fix from $1,600 2026-07-13
Unclassified HIGH 7.2
CVE-2026-3576

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all version…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.9
CVE-2026-11914

vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.

No fix yet
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40454

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-15288

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and i…

Mitigation only
Fix from $1,950 2026-07-10
Pan Os MEDIUM 6.5
CVE-2026-0282

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web in…

Fix: 11.1.16 / 11.2.13+
Fix from $1,600 2026-07-09
Unclassified HIGH 7.5
CVE-2026-51606

An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP …

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-51598

An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, networ…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-51599

An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remot…

No fix yet
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2025-58146

There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised in…

No fix yet
Fix from $2,300 2026-07-09
Chrome HIGH 8.3
CVE-2026-15122

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromise…

Fix: 150.0.7871.115+
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-15105

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp …

No fix yet
Fix from $1,600 2026-07-08
Unclassified HIGH 8.8
CVE-2026-10037

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files ma…

Mitigation only
Fix from $1,950 2026-07-08
Engine.io HIGH 7.5
CVE-2026-59724

Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enable…

Fix: 6.6.7+
Fix from $1,950 2026-07-08
Unclassified CRITICAL 9.1
CVE-2026-41042

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's …

Mitigation only
Fix from $2,300 2026-07-08
Vllm HIGH 7.5
CVE-2026-54234

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative dec…

Fix: 0.24.0+
Fix from $1,950 2026-07-06
Coldfusion CRITICAL 10.0
CVE-2026-48316

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-07-06
Camel HIGH 7.3
CVE-2026-49042

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Us…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel HIGH 7.3
CVE-2026-46587

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.3
CVE-2026-46588

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel CRITICAL 9.8
CVE-2026-56140

Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-s…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06