Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 1607 HIGH 7.8
CVE-2026-26170

Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1809 HIGH 7.8
CVE-2026-26161

Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-26156

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows Server 2012 HIGH 7.5
CVE-2026-26154

Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Powershell HIGH 7.8
CVE-2026-26143

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

Fix: 7.4.14 / 7.5.5+
Fix from $1,950 2026-04-14
Maxkb MEDIUM 5.5
CVE-2026-39417

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execu…

Fix: 2.8.0+
Fix from $1,600 2026-04-14
Jq MEDIUM 5.3
CVE-2026-33948

jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows v…

Fix: 2026-04-12+
Fix from $1,600 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-22563

A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. A…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified HIGH 7.5
CVE-2026-22565

An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding…

Mitigation only
Fix from $1,950 2026-04-13
C Driver HIGH 7.5
CVE-2026-6231

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for …

Fix: 1.30.5 / 2.0.2+
Fix from $1,950 2026-04-13
Harmonyos MEDIUM 5.7
CVE-2026-34855

Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidenti…

No fix yet
Fix from $1,600 2026-04-13
Bugsink HIGH 7.1
CVE-2026-40162

Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bun…

Mitigation only
Fix from $1,950 2026-04-10
Wolfssl MEDIUM 5.9
CVE-2026-5500

wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check.…

Fix: after 5.9.0
Fix from $1,600 2026-04-10
Junos HIGH 7.4
CVE-2026-33797

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a …

Mitigation only
Fix from $1,950 2026-04-09
Tomcat MEDIUM 5.3
CVE-2026-32990

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 …

Fix: 9.0.116 / 10.1.53+
Fix from $1,600 2026-04-09
Velociraptor MEDIUM 6.5
CVE-2026-5329

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Veloc…

Fix: 0.76.3+
Fix from $1,600 2026-04-09
Lxd CRITICAL 9.1
CVE-2026-34178

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates …

Fix: after 6.7
Fix from $2,300 2026-04-09
Chrome HIGH 8.1
CVE-2026-5915

Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds mem…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome MEDIUM 6.5
CVE-2026-5919

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the re…

Fix: 147.0.7727.55+
Fix from $1,600 2026-04-08
Chrome HIGH 8.8
CVE-2026-5884

Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the rendere…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome MEDIUM 6.5
CVE-2026-5885

Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentiall…

Fix: 147.0.7727.55+
Fix from $1,600 2026-04-08
Chrome HIGH 8.8
CVE-2026-5879

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary cod…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Exynos 980 Firmware HIGH 7.5
CVE-2025-57834

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem (Exynos 980, 850, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2…

Mitigation only
Fix from $1,950 2026-04-06
Android MEDIUM 5.5
CVE-2025-48651

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This c…

Mitigation only
Fix from $1,600 2026-04-06
Exynos 990 Firmware HIGH 7.5
CVE-2025-57835

An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5659

A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/d…

Mitigation only
Fix from $1,600 2026-04-06
Oai Cn5g Amf HIGH 7.5
CVE-2026-30078

OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message sp…

No fix yet
Fix from $1,950 2026-04-06
Fedml HIGH 7.3
CVE-2026-5536

A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC s…

Fix: after 0.8.9
Fix from $1,950 2026-04-05
Electron HIGH 7.5
CVE-2026-34773

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and…

Fix: 38.8.6 / 39.8.1+
Fix from $1,950 2026-04-04