Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome HIGH 8.1
CVE-2026-13791

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a…

Fix: 150.0.7871.46+
Fix from $1,950 2026-06-30
Chrome HIGH 8.8
CVE-2026-13777

Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit …

Fix: 150.0.7871.46+
Fix from $1,950 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13780

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13781

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.8
CVE-2026-7803

IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component t…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 9.3
CVE-2026-48315

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48277

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48281

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-06-30
Activemq HIGH 7.5
CVE-2026-49432

Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-49434

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or m…

Fix: 5.19.8 / 6.2.7+
Fix from $1,950 2026-06-30
Ipados MEDIUM 5.5
CVE-2026-43722

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS …

Fix: 26.5.2+
Fix from $1,600 2026-06-29
Ipados HIGH 7.8
CVE-2026-43724

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS …

Fix: 26.5.2+
Fix from $1,950 2026-06-29
Safari HIGH 7.1
CVE-2026-43725

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 2…

Fix: 26.5.2+
Fix from $1,950 2026-06-29
Ipados CRITICAL 9.1
CVE-2026-39868

This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS S…

Fix: 26.5.2+
Fix from $2,300 2026-06-29
Unclassified HIGH 7.5
CVE-2026-38639

An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a cr…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.6
CVE-2026-52780

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified MEDIUM 5.9
CVE-2026-42387

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input …

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.9
CVE-2026-42388

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.3
CVE-2026-42389

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

No fix yet
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.3
CVE-2026-42390

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

Mitigation only
Fix from $1,600 2026-06-25
Nsd HIGH 8.1
CVE-2026-12246

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite t…

Fix: 4.14.3+
Fix from $1,950 2026-06-25
Unclassified HIGH 8.1
CVE-2026-52801

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well prot…

Patch available
Fix from $1,950 2026-06-24
Chrome HIGH 8.3
CVE-2026-13025

Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a…

Fix: 149.0.7827.197+
Fix from $1,950 2026-06-24
Unclassified HIGH 8.8
CVE-2026-48720

Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;F…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 8.8
CVE-2026-48704

Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local file…

Patch available
Fix from $1,950 2026-06-24
Gemini Cli HIGH 7.8
CVE-2026-12537

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Act…

Fix: 0.1.22 / 0.39.1+
Fix from $1,950 2026-06-24
Unclassified HIGH 7.0
CVE-2026-13006

ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allow…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.6
CVE-2026-54588

Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` requ…

Mitigation only
Fix from $2,300 2026-06-23
Caddy HIGH 8.1
CVE-2026-45135

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/rev…

Fix: 2.11.3+
Fix from $1,950 2026-06-23
N8n HIGH 8.5
CVE-2026-49444

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify …

Fix: 1.123.48 / 2.21.8+
Fix from $1,950 2026-06-23