Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Nginx Ingress Controller HIGH 8.8
CVE-2026-4342

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can …

Fix: 1.13.9 / 1.14.5+
Fix from $1,950 2026-03-19
Sqlbot HIGH 8.8
CVE-2026-32622

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulner…

Fix: 1.6.0+
Fix from $1,950 2026-03-19
Ormar CRITICAL 9.8
CVE-2026-27953

ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing …

Fix: 0.23.1+
Fix from $2,300 2026-03-19
Ipados MEDIUM 5.4
CVE-2026-20643

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for …

Fix: 26.3.1+
Fix from $1,600 2026-03-17
Python HIGH 7.5
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling…

Fix: 3.13.13 / 3.14.4+
Fix from $1,950 2026-03-16
Fields CRITICAL 9.1
CVE-2026-23489

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP …

Fix: 1.23.3+
Fix from $2,300 2026-03-16
Openharmony MEDIUM 5.5
CVE-2025-6969

in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.

Mitigation only
Fix from $1,600 2026-03-16
Unclassified MEDIUM 5.3
CVE-2025-10461

Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows f…

Mitigation only
Fix from $1,600 2026-03-16
Wpdiscuz MEDIUM 5.3
CVE-2026-22204

wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious da…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Omada Sg2005p Pd Firmware CRITICAL 9.8
CVE-2026-1668

The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when …

Fix: 1.0.19 / 1.20.17+
Fix from $2,300 2026-03-13
Livy MEDIUM 6.3
CVE-2025-60012

Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apach…

Fix: 0.9.0+
Fix from $1,600 2026-03-13
Unclassified MEDIUM 6.3
CVE-2026-3967

A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file a…

Mitigation only
Fix from $1,600 2026-03-12
Black CRITICAL 9.8
CVE-2026-31900

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject:…

Fix: 26.3.0+
Fix from $2,300 2026-03-11
Rooms HIGH 7.8
CVE-2026-30901

Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege …

Fix: 6.6.5+
Fix from $1,950 2026-03-11
Commerce MEDIUM 5.3
CVE-2026-21310

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vu…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Commerce MEDIUM 5.3
CVE-2026-21282

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vu…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2026-03-11
Unclassified HIGH 7.1
CVE-2025-20068

Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalation of privilege. System softw…

Mitigation only
Fix from $1,950 2026-03-10
Unclassified MEDIUM 5.9
CVE-2025-20096

Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adversary wit…

Mitigation only
Fix from $1,600 2026-03-10
Unclassified HIGH 8.7
CVE-2025-20105

Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation of privilege. System software…

Mitigation only
Fix from $1,950 2026-03-10
Unclassified HIGH 7.1
CVE-2025-20027

Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System software adv…

Mitigation only
Fix from $1,950 2026-03-10
Unclassified HIGH 8.7
CVE-2025-20064

Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. System softwar…

Mitigation only
Fix from $1,950 2026-03-10
Android HIGH 8.4
CVE-2025-36920

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local e…

Mitigation only
Fix from $1,950 2026-03-10
Envoy HIGH 7.5
CVE-2026-26310

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::getAddressWithPort with a scope…

Fix: 1.34.13 / 1.35.8+
Fix from $1,950 2026-03-10
Azure Iot Explorer HIGH 7.5
CVE-2026-26121

Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.

Fix: 0.15.14+
Fix from $1,950 2026-03-10
Sharepoint Server HIGH 8.8
CVE-2026-26106

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20076+
Fix from $1,950 2026-03-10
System Center Operations Manager HIGH 8.8
CVE-2026-20967

Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-03-10
Ingress Nginx HIGH 8.8
CVE-2026-3288EPSS 6%

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject conf…

Fix: 1.13.8 / 1.14.4+
Fix from $1,950 2026-03-09
FreeBSD HIGH 7.2
CVE-2025-14558EPSS 6%

The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is pass…

No fix yet
Fix from $1,950 2026-03-09
Android HIGH 7.5
CVE-2025-61613

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,950 2026-03-09
Android HIGH 7.5
CVE-2025-61614

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,950 2026-03-09