Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Authentik HIGH 8.5
CVE-2026-47201

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerabl…

Fix: 2025.12.6 / 2026.2.4+
Fix from $1,950 2026-06-02
Unclassified MEDIUM 6.5
CVE-2026-35049

wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external mes…

Mitigation only
Fix from $1,600 2026-06-02
Ebpf Instrumentation HIGH 7.5
CVE-2026-45685

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, mal…

Fix: 0.9.0+
Fix from $1,950 2026-06-02
Ebpf Instrumentation MEDIUM 5.5
CVE-2026-45676

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI's replacement ELF p…

Fix: 0.9.0+
Fix from $1,600 2026-06-02
Ebpf Instrumentation HIGH 7.5
CVE-2026-45678

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol p…

Fix: 0.9.0+
Fix from $1,950 2026-06-02
Sitefinity HIGH 8.1
CVE-2026-7195

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.…

Fix: 14.4.8152 / 15.0.8234+
Fix from $1,950 2026-06-02
Unclassified MEDIUM 5.3
CVE-2026-10566

A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/…

Mitigation only
Fix from $1,600 2026-06-02
Android MEDIUM 5.5
CVE-2026-28578

In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could le…

Mitigation only
Fix from $1,600 2026-06-01
Android MEDIUM 5.5
CVE-2026-0085

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This coul…

Mitigation only
Fix from $1,600 2026-06-01
Android MEDIUM 5.5
CVE-2026-0070

In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation.…

Mitigation only
Fix from $1,600 2026-06-01
Android HIGH 7.8
CVE-2026-0078

In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to …

Mitigation only
Fix from $1,950 2026-06-01
Android MEDIUM 6.5
CVE-2026-0051

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lea…

Mitigation only
Fix from $1,600 2026-06-01
Android MEDIUM 5.5
CVE-2026-0018

In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This co…

Mitigation only
Fix from $1,600 2026-06-01
Android HIGH 7.8
CVE-2025-22424

In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2026-06-01
Capsule CRITICAL 9.1
CVE-2026-22872

Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantR…

Fix: 0.13.0+
Fix from $2,300 2026-06-01
Linux Kernel HIGH 7.1
CVE-2026-46243

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descript…

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-06-01
Activemq HIGH 8.1
CVE-2026-42588

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Activemq HIGH 8.8
CVE-2026-45505

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01
Otrs CRITICAL 9.1
CVE-2026-48188

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which …

Fix: 2026.4.1+
Fix from $2,300 2026-06-01
Cpp Httplib HIGH 7.5
CVE-2026-45352

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding c…

Fix: 0.43.4+
Fix from $1,950 2026-05-29
Liboqs MEDIUM 5.3
CVE-2026-44518

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds…

Fix: after 0.15.0
Fix from $1,600 2026-05-29
Unclassified CRITICAL 9.6
CVE-2026-45628

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template lit…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 8.2
CVE-2026-45615

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated …

Mitigation only
Fix from $1,950 2026-05-29
Chrome MEDIUM 5.0
CVE-2026-9979

Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the render…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,600 2026-05-28
Chrome MEDIUM 5.0
CVE-2026-9980

Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the ren…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,600 2026-05-28
Chrome HIGH 8.3
CVE-2026-9982

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the render…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome MEDIUM 5.3
CVE-2026-9985

Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromise…

Fix: 148.0.7778.216+
Fix from $1,600 2026-05-28
Chrome HIGH 7.8
CVE-2026-9987

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute …

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.8
CVE-2026-9969

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via …

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 8.3
CVE-2026-9977

Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromi…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28