Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified MEDIUM 5.3
CVE-2026-6675

The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up …

No fix yet
Fix from $1,600 2026-04-21
Neko HIGH 8.8
CVE-2026-39386

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat…

Fix: 3.0.11 / 3.1.2+
Fix from $1,950 2026-04-21
Spinnaker CRITICAL 9.9
CVE-2026-32604

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor c…

Fix: 2025.3.2 / 2025.4.2+
Fix from $2,300 2026-04-20
Powerprotect Dp Series Appliance HIGH 7.2
CVE-2026-24504

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 thro…

Fix: 2.7.9 / 7.13.1.70+
Fix from $1,950 2026-04-20
Powerprotect Dp Series Appliance HIGH 7.2
CVE-2026-24505

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privileged attacker with remote ac…

Fix: 2.7.9 / 8.6.1.0+
Fix from $1,950 2026-04-20
Unclassified MEDIUM 6.3
CVE-2026-6626

A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of the component Asset Handler/…

Mitigation only
Fix from $1,600 2026-04-20
Novumos CRITICAL 9.3
CVE-2026-40317

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary …

Fix: 0.24+
Fix from $2,300 2026-04-18
Stirling Pdf MEDIUM 6.1
CVE-2026-33436

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints …

Fix: 2.0.0+
Fix from $1,600 2026-04-17
Ddk HIGH 7.3
CVE-2026-21733

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode mem…

Fix: 25.3+
Fix from $1,950 2026-04-17
Unclassified HIGH 7.1
CVE-2026-6409

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—spe…

Mitigation only
Fix from $1,950 2026-04-16
Intelligent Power Protector HIGH 7.2
CVE-2026-22615

Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and …

Fix: 2.00+
Fix from $1,950 2026-04-16
Composer HIGH 7.8
CVE-2026-40176

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce…

Fix: after 2.9.5
Fix from $1,950 2026-04-15
Composer HIGH 8.8
CVE-2026-40261

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce…

Fix: after 2.9.5
Fix from $1,950 2026-04-15
Unclassified MEDIUM 5.3
CVE-2026-1782

The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3.9.7 This is due to the payme…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified HIGH 8.3
CVE-2026-6328

Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implem…

Patch available
Fix from $1,950 2026-04-15
Unclassified CRITICAL 9.6
CVE-2026-39399

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec fi…

Patch available
Fix from $2,300 2026-04-14
Jellyfin HIGH 8.8
CVE-2026-35031

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /V…

Fix: 10.11.7+
Fix from $1,950 2026-04-14
Framemaker MEDIUM 6.3
CVE-2026-27299

Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read…

Fix: 2022.9+
Fix from $1,600 2026-04-14
Coldfusion HIGH 7.5
CVE-2026-27282

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature by…

Mitigation only
Fix from $1,950 2026-04-14
Coldfusion CRITICAL 9.3
CVE-2026-27304

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-04-14
Coldfusion HIGH 8.4
CVE-2026-27306

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $1,950 2026-04-14
Openitcockpit HIGH 8.8
CVE-2026-24893

openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contai…

Fix: 5.5.2+
Fix from $1,950 2026-04-14
Windows Server 2012 HIGH 8.0
CVE-2026-33826

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
.net HIGH 7.5
CVE-2026-33116

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a …

Fix: 8.0.26 / 9.0.15+
Fix from $1,950 2026-04-14
Sharepoint Server MEDIUM 6.5
CVE-2026-32201 KEVEPSS 23%

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20210+
Fix from $1,600 2026-04-14
.net HIGH 7.5
CVE-2026-32203

Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.

Fix: 8.0.26 / 9.0.15+
Fix from $1,950 2026-04-14
Azure Monitor Agent HIGH 7.8
CVE-2026-32168

Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.35.9+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.3
CVE-2026-32149

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows Server 2016 HIGH 8.7
CVE-2026-27928

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows Server 2012 HIGH 7.7
CVE-2026-27913

Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14