Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Polaris CRITICAL 9.9
CVE-2026-42810

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42811

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Frrouting MEDIUM 6.5
CVE-2026-37458

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denia…

Fix: after 10.6.0
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7712

A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipul…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7597

A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Per…

Patch available
Fix from $1,600 2026-05-01
Unclassified HIGH 7.8
CVE-2025-52347

An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 …

Mitigation only
Fix from $1,950 2026-05-01
Db2 MEDIUM 6.5
CVE-2026-1577

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user …

Fix: after 12.1.4
Fix from $1,600 2026-04-30
Unclassified HIGH 7.5
CVE-2025-46115

An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

Mitigation only
Fix from $1,950 2026-04-30
Moveit Automation HIGH 8.8
CVE-2026-5174

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: fr…

Fix: 2024.1.8 / 2025.1.5+
Fix from $1,950 2026-04-30
Qtdeclarative HIGH 7.8
CVE-2025-14576

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the Vect…

Fix: 6.8.6 / 6.10.1+
Fix from $1,950 2026-04-30
Tvicport HIGH 7.8
CVE-2026-30769

An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending cr…

Mitigation only
Fix from $1,950 2026-04-29
Chrome HIGH 8.3
CVE-2026-7345

Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the ren…

Fix: 147.0.7727.138+
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.0
CVE-2026-7317

A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system…

Patch available
Fix from $1,600 2026-04-28
Nvflare MEDIUM 6.5
CVE-2026-24204

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this v…

Fix: 2.7.2+
Fix from $1,600 2026-04-28
Knb 2000 Firmware MEDIUM 6.5
CVE-2024-54011

Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, ca…

Fix: 2.23.01+
Fix from $1,600 2026-04-28
Pdf Editor HIGH 7.1
CVE-2026-5941

Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to inv…

Fix: 14.0.4 / 2026.1.1+
Fix from $1,950 2026-04-27
Activemq HIGH 8.8
CVE-2026-40466

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.6 / 6.2.5+
Fix from $1,950 2026-04-24
Activemq HIGH 8.8
CVE-2026-41044

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache…

Fix: 5.19.6 / 6.2.5+
Fix from $1,950 2026-04-24
Flowise CRITICAL 9.8
CVE-2026-41268EPSS 14%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Nimiq Proof Of Stake MEDIUM 5.3
CVE-2026-34066

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStore::put_historic_txns` uses an…

Fix: 1.3.0+
Fix from $1,600 2026-04-22
Nimiq Proof Of Stake CRITICAL 9.6
CVE-2026-33471

nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len…

Fix: 1.3.0+
Fix from $2,300 2026-04-22
Coreutils MEDIUM 5.5
CVE-2026-35380

A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte string '' (two single quotes) a…

Fix: 0.8.0+
Fix from $1,600 2026-04-22
Coreutils MEDIUM 5.5
CVE-2026-35369

An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send the default signal (SIGTERM) to…

Fix: 0.6.0+
Fix from $1,600 2026-04-22
Raindrop MEDIUM 6.5
CVE-2026-31192

Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user da…

Mitigation only
Fix from $1,600 2026-04-22
Spring Security MEDIUM 6.5
CVE-2026-22748

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must conf…

Fix: 6.3.15 / 6.4.15+
Fix from $1,600 2026-04-22
Unclassified HIGH 7.2
CVE-2026-40871EPSS 10%

mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerabili…

Mitigation only
Fix from $1,950 2026-04-21
Firefox MEDIUM 5.3
CVE-2026-6777

Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox MEDIUM 5.3
CVE-2026-6779

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Unclassified HIGH 8.2
CVE-2025-13826

Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vulnerability is caused by inad…

Mitigation only
Fix from $1,950 2026-04-21