Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.5
CVE-2025-61615

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,950 2026-03-09
Android HIGH 7.5
CVE-2025-61616

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,950 2026-03-09
Android HIGH 7.5
CVE-2025-69278

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,950 2026-03-09
Android HIGH 7.5
CVE-2025-69279

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,950 2026-03-09
Iotdb CRITICAL 9.8
CVE-2026-24713

Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a…

Fix: 1.3.7 / 2.0.7+
Fix from $2,300 2026-03-09
Yocto HIGH 7.5
CVE-2025-61611

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed..

No fix yet
Fix from $1,950 2026-03-09
Android HIGH 7.5
CVE-2025-61612

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut…

Mitigation only
Fix from $1,950 2026-03-09
Agentgateway MEDIUM 6.5
CVE-2026-29791

Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environment. Prior to version 0.12.0, w…

Fix: 0.12.0+
Fix from $1,600 2026-03-06
Tinyweb HIGH 8.2
CVE-2026-29046

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them i…

Fix: 2.04+
Fix from $1,950 2026-03-06
Nltk CRITICAL 10.0
CVE-2026-0848

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamic…

Fix: after 3.9.2
Fix from $2,300 2026-03-05
Omada Eap610 Firmware MEDIUM 6.5
CVE-2025-7375

A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cau…

Fix: 1.6.0+
Fix from $1,600 2026-03-05
Jetty MEDIUM 6.5
CVE-2025-11143

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in system…

Fix: 12.0.31 / 12.1.5+
Fix from $1,600 2026-03-05
Chrome CRITICAL 9.6
CVE-2026-3545

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape…

Fix: 145.0.7632.159 / 145.0.7632.160+
Fix from $2,300 2026-03-04
Adaptive Security Appliance Software MEDIUM 5.7
CVE-2026-20020

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent att…

Mitigation only
Fix from $1,600 2026-03-04
Seppmail HIGH 7.5
CVE-2026-27443

SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME entities, allowing an attacker …

Fix: 15.0.1+
Fix from $1,950 2026-03-04
Remote Desktop Manager CRITICAL 9.8
CVE-2026-2590

Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.…

Fix: after 2025.3.30.0
Fix from $2,300 2026-03-03
Devolutions Server CRITICAL 9.8
CVE-2026-3204

Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error…

Fix: after 2025.3.16.0
Fix from $2,300 2026-03-03
Easyweb CRITICAL 9.8
CVE-2024-55020

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to…

Mitigation only
Fix from $2,300 2026-03-03
Exynos 1280 Firmware MEDIUM 5.5
CVE-2025-62816

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP input lead…

Mitigation only
Fix from $1,600 2026-03-03
Android HIGH 8.4
CVE-2026-0034

In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could …

Mitigation only
Fix from $1,950 2026-03-02
Android MEDIUM 6.2
CVE-2026-0015

In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to lo…

Mitigation only
Fix from $1,600 2026-03-02
Android MEDIUM 6.2
CVE-2026-0014

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to…

Mitigation only
Fix from $1,600 2026-03-02
Android MEDIUM 5.5
CVE-2025-48644

In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service …

No fix yet
Fix from $1,600 2026-03-02
Android MEDIUM 6.2
CVE-2025-48585

In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to…

Mitigation only
Fix from $1,600 2026-03-02
Android MEDIUM 6.2
CVE-2025-48587

In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to…

Mitigation only
Fix from $1,600 2026-03-02
Vim HIGH 7.8
CVE-2026-28421

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim'…

Fix: 9.2.0077+
Fix from $1,950 2026-02-27
Http\ MEDIUM 6.5
CVE-2018-25160

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depe…

Fix: after 1.09
Fix from $1,600 2026-02-27
Fastify\/middie CRITICAL 9.1
CVE-2026-2880

A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example,…

Fix: 9.2.0+
Fix from $2,300 2026-02-27
Web CRITICAL 9.8
CVE-2026-2750

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affec…

Fix: 24.04.24 / 24.10.20+
Fix from $2,300 2026-02-27
Kibana HIGH 7.5
CVE-2026-26935

Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulatio…

Fix: 8.19.12 / 9.2.6+
Fix from $1,950 2026-02-26