Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 1607 HIGH 8.1
CVE-2026-61363

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 8.1
CVE-2026-59134

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
C2pa MEDIUM 6.5
CVE-2026-48436

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could l…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.8
CVE-2026-27765

Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may all…

No fix yet
Fix from $4,000 2026-08-11
Coldfusion HIGH 8.7
CVE-2026-21273

is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vul…

No fix yet
Fix from $4,900 2026-08-11
Coldfusion HIGH 8.2
CVE-2026-21279

is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabili…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.2
CVE-2026-20715

Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-48056

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable pat…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.5
CVE-2026-71217

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameter…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-73158

Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.9
CVE-2026-72867

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/serve…

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-72728

Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox…

No fix yet
Fix from $4,000 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe…

No fix yet
Fix from $5,750 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-42537

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 6.8
CVE-2026-21083

Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.1
CVE-2026-21070

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.1
CVE-2026-21071

Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.1
CVE-2026-21072

Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

No fix yet
Fix from $4,000 2026-08-10
Android HIGH 7.8
CVE-2026-21066

Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.7
CVE-2026-21060

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.

No fix yet
Fix from $4,000 2026-08-10
Android MEDIUM 6.5
CVE-2026-21061

Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction…

No fix yet
Fix from $4,000 2026-08-10
Android HIGH 7.1
CVE-2026-21058

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-19363

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 6.8
CVE-2026-9031

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by …

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47662

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.6
CVE-2026-47664

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.6
CVE-2026-50540

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P…

No fix yet
Fix from $2,300 2026-08-07
Unclassified MEDIUM 5.0
CVE-2026-62293

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command con…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.5
CVE-2026-62295

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-62296

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no…

No fix yet
Fix from $1,950 2026-08-07