Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified MEDIUM 5.3
CVE-2026-56762

Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing inval…

No fix yet
Fix from $1,600 2026-06-23
Zephyr MEDIUM 6.5
CVE-2026-10651

bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte a…

Fix: after 4.4.1
Fix from $1,600 2026-06-23
Unclassified MEDIUM 6.4
CVE-2026-56306

Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypass subkey enforcement by subm…

Mitigation only
Fix from $1,600 2026-06-22
Ultrajson MEDIUM 6.5
CVE-2026-54911

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujso…

Fix: 5.13.0+
Fix from $1,600 2026-06-22
Messagepack HIGH 8.2
CVE-2026-48109

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used…

Fix: 2.5.301 / 3.1.7+
Fix from $1,950 2026-06-22
Astro HIGH 7.5
CVE-2026-54299

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those …

Fix: 6.4.6+
Fix from $1,950 2026-06-22
Http Proxy Middleware HIGH 8.6
CVE-2026-55602

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-tabl…

Fix: 2.0.10 / 3.0.6+
Fix from $1,950 2026-06-22
Python Multipart MEDIUM 5.3
CVE-2026-53537

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) head…

Fix: 0.0.30+
Fix from $1,600 2026-06-22
Unclassified CRITICAL 9.4
CVE-2026-7165

The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of othe…

Mitigation only
Fix from $2,300 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12787

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part o…

Mitigation only
Fix from $1,600 2026-06-21
Vllm HIGH 7.5
CVE-2026-56340

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor…

Fix: 0.13.0+
Fix from $1,950 2026-06-20
Proxysql HIGH 7.5
CVE-2026-48774

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool vio…

Fix: 4.0.9+
Fix from $1,950 2026-06-19
Unclassified MEDIUM 6.3
CVE-2026-21768

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input t…

Mitigation only
Fix from $1,600 2026-06-19
Apisix HIGH 8.8
CVE-2026-39998

Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof i…

Fix: 3.17.0+
Fix from $1,950 2026-06-19
Geoserver HIGH 8.2
CVE-2025-58175

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `E…

Fix: 2.26.4 / 2.27.3+
Fix from $1,950 2026-06-18
Flexplm CRITICAL 9.8
CVE-2026-12569 KEVEPSS 30%

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t…

Fix: 11.0m030+
Fix from $2,300 2026-06-18
Unclassified HIGH 7.5
CVE-2026-50196

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eu…

Patch available
Fix from $1,950 2026-06-17
Unclassified CRITICAL 10.0
CVE-2026-48055

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vul…

Mitigation only
Fix from $2,300 2026-06-17
Chrome HIGH 8.3
CVE-2026-12465

Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 149.0.7827.155+
Fix from $1,950 2026-06-17
Android HIGH 7.8
CVE-2025-48643

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2026-06-17
Jd Edwards Enterpriseone Tools CRITICAL 9.1
CVE-2026-46910

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions…

Fix: after 9.2.26.2
Fix from $2,300 2026-06-17
Unclassified HIGH 7.8
CVE-2026-12191

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py…

Mitigation only
Fix from $1,950 2026-06-14
Unclassified HIGH 8.1
CVE-2026-45013

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the…

Mitigation only
Fix from $1,950 2026-06-12
Jmespath CRITICAL 9.8
CVE-2026-54133

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications wi…

Fix: 2.9.1+
Fix from $2,300 2026-06-12
Unclassified HIGH 8.4
CVE-2026-47196

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not reject an empty result. Adding …

No fix yet
Fix from $1,950 2026-06-12
Cxf HIGH 8.1
CVE-2026-50632

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf HIGH 8.1
CVE-2026-50633

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Cxf CRITICAL 9.8
CVE-2026-50628

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.9
CVE-2026-47367

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agen…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.9
CVE-2026-47369

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run…

Mitigation only
Fix from $2,300 2026-06-12