Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified CRITICAL 9.9
CVE-2026-47370

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run…

Mitigation only
Fix from $2,300 2026-06-12
Chrome MEDIUM 5.3
CVE-2026-12025

Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the rend…

Fix: 149.0.7827.115+
Fix from $1,600 2026-06-11
Chrome HIGH 8.3
CVE-2026-12034

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who h…

Fix: 149.0.7827.115+
Fix from $1,950 2026-06-11
Chrome HIGH 8.3
CVE-2026-12016

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process …

Fix: 149.0.7827.115+
Fix from $1,950 2026-06-11
Chrome HIGH 8.3
CVE-2026-12009

Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had comprom…

Fix: 149.0.7827.115+
Fix from $1,950 2026-06-11
Unclassified HIGH 8.7
CVE-2026-47181

PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allow…

Mitigation only
Fix from $1,950 2026-06-11
Tmp HIGH 8.2
CVE-2026-49982

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that conta…

No fix yet
Fix from $1,950 2026-06-11
Unclassified MEDIUM 5.8
CVE-2026-53723

Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize re…

Mitigation only
Fix from $1,600 2026-06-11
Psr 7 MEDIUM 5.3
CVE-2026-48998

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing …

Fix: 2.10.2+
Fix from $1,600 2026-06-11
Psr 7 MEDIUM 5.3
CVE-2026-49214

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, …

Fix: 2.10.2+
Fix from $1,600 2026-06-11
Unclassified HIGH 8.7
CVE-2026-53901

Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacke…

Patch available
Fix from $1,950 2026-06-11
Imagemagick HIGH 7.5
CVE-2026-49218

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing ch…

Fix: 6.9.13-48 / 7.1.2-24+
Fix from $1,950 2026-06-10
Unclassified MEDIUM 5.3
CVE-2024-21944

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with …

Mitigation only
Fix from $1,600 2026-06-10
Unclassified MEDIUM 5.3
CVE-2026-48108

Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string…

No fix yet
Fix from $1,600 2026-06-10
Unclassified HIGH 7.5
CVE-2026-48110

Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded a…

No fix yet
Fix from $1,950 2026-06-10
Openvm HIGH 7.5
CVE-2026-46669

OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library…

Fix: 1.6.0+
Fix from $1,950 2026-06-10
Unclassified HIGH 7.5
CVE-2026-46679

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified MEDIUM 6.5
CVE-2026-48107

Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication pa…

Mitigation only
Fix from $1,600 2026-06-10
Unclassified HIGH 7.5
CVE-2026-45783

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storag…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 8.1
CVE-2026-45062

FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org…

Mitigation only
Fix from $1,950 2026-06-10
Splunk MEDIUM 5.7
CVE-2026-20255

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.250…

Fix: 9.3.13 / 9.3.2411.132+
Fix from $1,600 2026-06-10
Splunk MEDIUM 5.7
CVE-2026-20256

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.250…

Fix: 9.3.13 / 9.3.2411.132+
Fix from $1,600 2026-06-10
Splunk MEDIUM 5.7
CVE-2026-20257

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.250…

Fix: 9.3.13 / 9.3.2411.132+
Fix from $1,600 2026-06-10
Splunk MEDIUM 5.7
CVE-2026-20254

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.250…

Fix: 9.3.13 / 9.3.2411.132+
Fix from $1,600 2026-06-10
Unclassified HIGH 8.1
CVE-2026-45565

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxy…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified CRITICAL 9.9
CVE-2026-45556

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>…

Mitigation only
Fix from $2,300 2026-06-10
Unclassified CRITICAL 9.9
CVE-2026-45558

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi…

Mitigation only
Fix from $2,300 2026-06-10
Esp Idf HIGH 8.8
CVE-2026-45328

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrap…

Patch available
Fix from $1,950 2026-06-10
Esp Idf MEDIUM 6.5
CVE-2026-45329

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_se…

Patch available
Fix from $1,600 2026-06-10
Spring For Apache Kafka MEDIUM 6.5
CVE-2026-41727

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a …

Fix: 2.8.12 / 2.9.14+
Fix from $1,600 2026-06-10