Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified HIGH 8.4
CVE-2026-9157

Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issu…

Mitigation only
Fix from $1,950 2026-05-21
Chrome MEDIUM 5.3
CVE-2026-9124

Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the ren…

Fix: 148.0.7778.178+
Fix from $1,600 2026-05-20
Unclassified HIGH 7.4
CVE-2026-39850

Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that lea…

Patch available
Fix from $1,950 2026-05-20
Splunk MEDIUM 6.5
CVE-2026-20240

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.…

Fix: 9.3.12 / 9.3.2411.129+
Fix from $1,600 2026-05-20
Bind HIGH 7.5
CVE-2026-5946

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `…

Fix: 9.18.49 / 9.20.23+
Fix from $1,950 2026-05-20
Firefox CRITICAL 9.6
CVE-2026-8959

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, …

Fix: 140.11 / 140.11.0+
Fix from $2,300 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-31378

Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to vers…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Unclassified HIGH 7.2
CVE-2026-27891

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() fu…

Patch available
Fix from $1,950 2026-05-18
Edge Chromium CRITICAL 9.8
CVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 148.0.3967.70+
Fix from $2,300 2026-05-18
Edge Chromium MEDIUM 5.4
CVE-2026-45492

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Fix: 148.0.3967.70+
Fix from $1,600 2026-05-18
Private Cloud Compute MEDIUM 6.5
CVE-2026-20685

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation.…

Fix: 5e290.3+
Fix from $1,600 2026-05-18
Unclassified HIGH 7.3
CVE-2026-8759

A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-cla…

Mitigation only
Fix from $1,950 2026-05-17
H2o CRITICAL 9.8
CVE-2026-8751

A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Mod…

Fix: after 7402
Fix from $2,300 2026-05-17
Unclassified MEDIUM 6.3
CVE-2026-8735

A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the …

Mitigation only
Fix from $1,600 2026-05-17
Unclassified HIGH 8.4
CVE-2025-29936

Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impa…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified HIGH 8.7
CVE-2026-42327

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP respond…

Mitigation only
Fix from $1,950 2026-05-14
Chrome MEDIUM 5.3
CVE-2026-8538

Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Chrome HIGH 8.8
CVE-2026-8527

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code …

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
Chrome MEDIUM 5.3
CVE-2026-8516

Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Fleet MEDIUM 6.5
CVE-2026-26062

Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `Publi…

Fix: 4.81.0+
Fix from $1,600 2026-05-14
Unclassified HIGH 8.6
CVE-2026-44522

Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload ass…

No fix yet
Fix from $1,950 2026-05-14
Catalyst Sd Wan Manager HIGH 8.6
CVE-2026-20224

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbi…

Fix: 20.9.9.1 / 20.12.5.4+
Fix from $1,950 2026-05-14
Unclassified CRITICAL 9.6
CVE-2026-44482

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an…

Mitigation only
Fix from $2,300 2026-05-14
Shellhub MEDIUM 5.4
CVE-2026-44425

ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each fi…

Fix: 0.24.2+
Fix from $1,600 2026-05-13
Unclassified HIGH 8.1
CVE-2026-45055

CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at boots…

Mitigation only
Fix from $1,950 2026-05-13
Misp MEDIUM 5.3
CVE-2026-44379

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uu…

Fix: 2.5.37+
Fix from $1,600 2026-05-13
Netty CRITICAL 9.1
CVE-2026-42579

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC…

Fix: 4.1.133 / 4.2.13+
Fix from $2,300 2026-05-13
Unclassified MEDIUM 6.3
CVE-2026-2695

A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Im…

Mitigation only
Fix from $1,600 2026-05-13
Protobufjs MEDIUM 5.3
CVE-2026-44294

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors…

Fix: 7.5.6 / 8.0.2+
Fix from $1,600 2026-05-13
Unclassified MEDIUM 6.0
CVE-2026-8369

Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all platforms allows an attacker on t…

Patch available
Fix from $1,600 2026-05-13