Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified MEDIUM 5.3
CVE-2026-54217

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.7
CVE-2026-54204

Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-54205

Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set …

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-54206

Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network loc…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-54207

Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network loca…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.5
CVE-2026-54208

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-54199

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing function…

No fix yet
Fix from $1,600 2026-08-07
Chrome HIGH 8.3
CVE-2026-19177

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer …

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.8
CVE-2026-19169

Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privileg…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19164

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sand…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome HIGH 8.1
CVE-2026-19153

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rend…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Chrome HIGH 8.6
CVE-2026-19143

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially per…

Fix: 151.0.7922.109+
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-15149

The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.8
CVE-2024-6541

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows aut…

No fix yet
Fix from $1,600 2026-08-06
Cxf HIGH 8.1
CVE-2026-57817

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache C…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Api Control Plane MEDIUM 5.8
CVE-2024-10302

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-70607

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-20303

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Ios Xe HIGH 8.6
CVE-2026-20273

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.0
CVE-2026-70603

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.7
CVE-2026-46334

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerabilit…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-16793

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) …

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.3
CVE-2026-18801

OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who ca…

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-18772

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.6
CVE-2026-11835

Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mo…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67978

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67969

An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.App…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67974

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to caus…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-69198

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classificatio…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.5
CVE-2026-69185

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO pac…

No fix yet
Fix from $1,950 2026-08-03