Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified HIGH 7.5
CVE-2026-42544

Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a We…

Mitigation only
Fix from $1,950 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34679

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34688

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34666

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34668

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34669

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34670

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
Arubaos HIGH 7.5
CVE-2026-23825

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnera…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Wgdashboard CRITICAL 9.8
CVE-2026-44343

WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allo…

Fix: 4.3.2+
Fix from $2,300 2026-05-12
Unclassified MEDIUM 6.5
CVE-2026-44204

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /ass…

Patch available
Fix from $1,600 2026-05-12
.net Framework HIGH 7.3
CVE-2026-35433

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

Fix: 8.0.27 / 9.0.16+
Fix from $1,950 2026-05-12
Visual Studio 2022 HIGH 7.3
CVE-2026-32177

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

Fix: 8.0.27 / 9.0.16+
Fix from $1,950 2026-05-12
Quickassist Technology HIGH 7.8
CVE-2026-20767

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escala…

Fix: 1.13.0-0021+
Fix from $1,950 2026-05-12
Unclassified HIGH 8.5
CVE-2026-43989

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the age…

Patch available
Fix from $1,950 2026-05-12
Quickassist Technology MEDIUM 6.6
CVE-2026-20905

Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial o…

Fix: 2.6.0-0018+
Fix from $1,600 2026-05-12
Quickassist Technology MEDIUM 6.6
CVE-2026-20717

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial …

Fix: 1.13.0-0021+
Fix from $1,600 2026-05-12
Endpoint Management Assistant HIGH 8.8
CVE-2025-35990

Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allo…

Fix: 1.14.5.0+
Fix from $1,950 2026-05-12
Tomcat CRITICAL 9.8
CVE-2026-41293

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Firefox MEDIUM 5.3
CVE-2026-8391

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb…

Fix: 150.0.3+
Fix from $1,600 2026-05-12
Unclassified HIGH 7.8
CVE-2026-45391

A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary command…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.7
CVE-2026-45392

DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an auth…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.8
CVE-2026-45393

A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorr…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified CRITICAL 9.6
CVE-2026-43899

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitig…

Mitigation only
Fix from $2,300 2026-05-11
Ipados HIGH 7.5
CVE-2026-28936

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, ma…

Fix: 14.8.7 / 18.7.9+
Fix from $1,950 2026-05-11
Ipados HIGH 8.1
CVE-2026-28907

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, m…

Fix: 18.7.9 / 26.5+
Fix from $1,950 2026-05-11
Ipados HIGH 7.5
CVE-2026-28860

The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia …

Fix: 14.8.5 / 15.7.5+
Fix from $1,950 2026-05-11
Unclassified HIGH 7.3
CVE-2026-31251

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC …

Mitigation only
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.4
CVE-2026-42613

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and acc…

Patch available
Fix from $2,300 2026-05-11
Unclassified HIGH 7.8
CVE-2026-42301

pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the su…

Mitigation only
Fix from $1,950 2026-05-09
Praisonai CRITICAL 9.6
CVE-2026-44336

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou…

Fix: 4.6.34+
Fix from $2,300 2026-05-08