Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ai Code CRITICAL 9.6
CVE-2026-30304

In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description f…

Fix: after 3.12.4
Fix from $2,300 2026-03-27
Unclassified HIGH 7.2
CVE-2025-69986

A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application fails to validate the length …

Mitigation only
Fix from $1,950 2026-03-27
Unclassified HIGH 7.3
CVE-2026-4982

A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or channels in other worlds on …

Mitigation only
Fix from $1,950 2026-03-27
Dovecot HIGH 7.5
CVE-2025-59028

When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invali…

Fix: 2.4.3 / 3.1.2+
Fix from $1,950 2026-03-27
Dovecot HIGH 7.5
CVE-2025-59032

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, makin…

Fix: 2.4.3 / 3.1.3+
Fix from $1,950 2026-03-27
Openfga CRITICAL 9.8
CVE-2026-33729

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to…

Fix: 1.13.1+
Fix from $2,300 2026-03-27
Kirby MEDIUM 6.5
CVE-2026-29905

Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image up…

Fix: after 5.1.4
Fix from $1,600 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55270

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS…

Mitigation only
Fix from $2,300 2026-03-26
Unclassified HIGH 7.3
CVE-2026-4860

A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file sr…

Mitigation only
Fix from $1,950 2026-03-26
Liquidjs HIGH 7.5
CVE-2026-33285

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mecha…

Fix: 10.25.1+
Fix from $1,950 2026-03-26
Liquidjs HIGH 7.5
CVE-2026-33287

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS …

Fix: 10.25.1+
Fix from $1,950 2026-03-26
Nats Server HIGH 7.5
CVE-2026-33218

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which …

Fix: 2.11.15 / 2.12.6+
Fix from $1,950 2026-03-25
Ipados HIGH 7.5
CVE-2026-28894

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS …

Fix: 14.8.5 / 15.7.5+
Fix from $1,950 2026-03-25
Ipados MEDIUM 5.5
CVE-2026-28852

A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS S…

Fix: 15.7.5 / 18.7.7+
Fix from $1,600 2026-03-25
macOS HIGH 8.4
CVE-2026-28821

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue …

Fix: 14.8.5 / 15.7.5+
Fix from $1,950 2026-03-25
Ipados MEDIUM 5.3
CVE-2026-20686

This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user…

Fix: 26.3+
Fix from $1,600 2026-03-25
Unclassified HIGH 8.7
CVE-2026-3912

Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows inf…

Mitigation only
Fix from $1,950 2026-03-24
Nicegui HIGH 7.5
CVE-2026-33332

NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-c…

Fix: 3.9.0+
Fix from $1,950 2026-03-24
Unclassified HIGH 8.8
CVE-2026-22559

An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engin…

Mitigation only
Fix from $1,950 2026-03-24
Astro MEDIUM 5.3
CVE-2026-33769

Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs …

Fix: 5.18.1+
Fix from $1,600 2026-03-24
Android Imagemagick7 CRITICAL 9.8
CVE-2026-4755

CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

Fix: 7.1.2-11+
Fix from $2,300 2026-03-24
Unclassified HIGH 7.5
CVE-2026-33250

Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specia…

Patch available
Fix from $1,950 2026-03-24
Td W8961nd Firmware HIGH 7.5
CVE-2025-15606

A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted request…

Fix: 250925+
Fix from $1,950 2026-03-23
Pytorch HIGH 7.8
CVE-2026-4538

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation …

Patch available
Fix from $1,950 2026-03-22
Unclassified MEDIUM 5.3
CVE-2026-3641

The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. This is due to the plugin reg…

Mitigation only
Fix from $1,600 2026-03-21
Unclassified MEDIUM 5.3
CVE-2026-3460

The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This …

Mitigation only
Fix from $1,600 2026-03-21
Socket.io Parser HIGH 7.5
CVE-2026-33151

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially c…

Fix: 3.3.5 / 3.4.4+
Fix from $1,950 2026-03-20
Glibc MEDIUM 5.4
CVE-2026-4438

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 t…

Fix: after 2.43
Fix from $1,600 2026-03-20
Discourse HIGH 8.2
CVE-2026-31805

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plu…

Fix: 2026.1.2 / 2026.2.1+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4451

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the r…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20