Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
C2pa MEDIUM 6.2
CVE-2026-47903

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker cou…

Fix: after 0.80.1
Fix from $1,600 2026-06-09
C2pa HIGH 7.5
CVE-2026-34712

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker cou…

Fix: after 0.80.1
Fix from $1,950 2026-06-09
Coldfusion HIGH 8.4
CVE-2026-47931

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $1,950 2026-06-09
Coldfusion CRITICAL 9.6
CVE-2026-47928

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-06-09
Coldfusion HIGH 8.1
CVE-2026-47930

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature by…

Mitigation only
Fix from $1,950 2026-06-09
Dreamweaver MEDIUM 6.3
CVE-2026-47909

Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system rea…

Fix: 21.8+
Fix from $1,600 2026-06-09
Cax30 Firmware HIGH 8.8
CVE-2026-9211

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.

Fix: 1.0.5.34 / 1.0.10.72+
Fix from $1,950 2026-06-09
Lbr1020 Firmware HIGH 8.0
CVE-2026-9212

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impactin…

Fix: 1.0.4.96 / 1.0.5.50+
Fix from $1,950 2026-06-09
Mr70 Firmware HIGH 8.1
CVE-2026-9213

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and …

Fix: 1.0.2.86 / 1.0.4.48+
Fix from $1,950 2026-06-09
Freeswitch HIGH 7.5
CVE-2026-49475

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.11.0+
Fix from $1,950 2026-06-09
Freeswitch CRITICAL 9.1
CVE-2026-49840

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.11.1+
Fix from $2,300 2026-06-09
Visual Studio Code MEDIUM 5.5
CVE-2026-48569

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Fix: 1.123.2+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47641

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45636

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 11 26h1 HIGH 7.8
CVE-2026-44811

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.28000.2269+
Fix from $1,950 2026-06-09
Visual Studio Code HIGH 8.1
CVE-2026-40376

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.123.2+
Fix from $1,950 2026-06-09
Jr6150 Firmware HIGH 8.0
CVE-2026-0419

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local W…

Mitigation only
Fix from $1,950 2026-06-09
Chrome CRITICAL 9.6
CVE-2026-11697

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox …

Fix: 149.0.7827.103+
Fix from $2,300 2026-06-09
Chrome MEDIUM 5.4
CVE-2026-11701

Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HT…

Fix: 149.0.7827.103+
Fix from $1,600 2026-06-09
Chrome HIGH 8.1
CVE-2026-11689

Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer proc…

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Chrome HIGH 8.3
CVE-2026-11682

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer pr…

Fix: 149.0.7827.102+
Fix from $1,950 2026-06-09
Chrome HIGH 8.3
CVE-2026-11676

Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had c…

Fix: 149.0.7827.102+
Fix from $1,950 2026-06-09
Chrome HIGH 8.3
CVE-2026-11660

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the…

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Chrome MEDIUM 5.4
CVE-2026-11666

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a c…

Fix: 149.0.7827.103+
Fix from $1,600 2026-06-09
Chrome MEDIUM 6.5
CVE-2026-11653

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer proces…

Fix: 149.0.7827.103+
Fix from $1,600 2026-06-09
Chrome MEDIUM 6.5
CVE-2026-11658

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the r…

Fix: 149.0.7827.103+
Fix from $1,600 2026-06-09
Chrome CRITICAL 9.6
CVE-2026-11659

Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a craf…

Fix: 149.0.7827.103+
Fix from $2,300 2026-06-09
Routinator HIGH 7.5
CVE-2026-49234

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only a…

Fix: 0.15.2+
Fix from $1,950 2026-06-08
Cordova Inappbrowser HIGH 7.5
CVE-2026-47430

## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPlugi…

Fix: 6.0.1+
Fix from $1,950 2026-06-08
Unclassified HIGH 7.3
CVE-2026-11460

A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of…

Mitigation only
Fix from $1,950 2026-06-07