Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Koa HIGH 7.5
CVE-2026-27959

Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of th…

Fix: 2.16.4 / 3.1.2+
Fix from $1,950 2026-02-26
Terriajs Server HIGH 7.5
CVE-2026-27818

TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions pri…

Fix: 4.0.3+
Fix from $1,950 2026-02-26
Freerdp HIGH 8.1
CVE-2026-25941

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 …

Fix: 2.11.8 / 3.23.0+
Fix from $1,950 2026-02-25
Budibase CRITICAL 9.0
CVE-2026-27702

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i…

Fix: 3.30.4+
Fix from $2,300 2026-02-25
Rustfs CRITICAL 9.1
CVE-2026-27607

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi…

Mitigation only
Fix from $2,300 2026-02-25
Endpoint Security HIGH 7.8
CVE-2025-14963

A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system p…

Fix: after 34.0.0
Fix from $1,950 2026-02-24
Caddy CRITICAL 9.8
CVE-2026-27590

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind…

Fix: 2.11.1+
Fix from $2,300 2026-02-24
Caddy MEDIUM 6.5
CVE-2026-27585

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanit…

Fix: 2.11.1+
Fix from $1,600 2026-02-24
Udm HIGH 7.5
CVE-2026-27642

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t…

Fix: after 1.4.1
Fix from $1,950 2026-02-24
Valkey Bloom HIGH 7.5
CVE-2026-21864

Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to co…

Fix: 1.0.1+
Fix from $1,950 2026-02-24
Udm HIGH 7.5
CVE-2025-69250

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t…

Fix: after 1.4.1
Fix from $1,950 2026-02-24
Udm MEDIUM 5.3
CVE-2025-69251

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t…

Fix: after 1.4.1
Fix from $1,600 2026-02-24
Go Upf HIGH 7.5
CVE-2025-69232

free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to f…

Fix: after 1.4.0
Fix from $1,950 2026-02-23
Valkey HIGH 7.5
CVE-2026-27623

Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can…

Fix: 9.0.3+
Fix from $1,950 2026-02-23
Datapizza Ai HIGH 7.5
CVE-2026-2970

A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-…

No fix yet
Fix from $1,950 2026-02-23
Funadmin MEDIUM 6.5
CVE-2026-2898

A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.p…

Fix: 7.1.0+
Fix from $1,600 2026-02-22
Opensift HIGH 7.1
CVE-2026-27170

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest…

Fix: 1.1.3+
Fix from $1,950 2026-02-21
Web Interface MEDIUM 5.4
CVE-2026-26952

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below…

Fix: 6.4.1+
Fix from $1,600 2026-02-19
Web Interface MEDIUM 5.4
CVE-2026-26953

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and abov…

Fix: 6.4.1+
Fix from $1,600 2026-02-19
Go Ethereum HIGH 7.5
CVE-2026-26314

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to s…

Fix: 1.16.9+
Fix from $1,950 2026-02-19
Unclassified HIGH 8.8
CVE-2026-26063

CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validatio…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified MEDIUM 6.5
CVE-2025-13587

The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including…

Mitigation only
Fix from $1,600 2026-02-19
Tomcat HIGH 7.5
CVE-2026-24734

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o…

Fix: 1.3.5 / 2.0.12+
Fix from $1,950 2026-02-17
Tomcat CRITICAL 9.1
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…

Fix: 9.0.113 / 10.1.50+
Fix from $2,300 2026-02-17
Jeecg Boot HIGH 7.5
CVE-2026-2555

A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/…

No fix yet
Fix from $1,950 2026-02-16
Free5gc HIGH 7.5
CVE-2025-70123

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF in…

No fix yet
Fix from $1,950 2026-02-13
Qs HIGH 7.5
CVE-2026-2391

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cau…

Fix: 6.14.2+
Fix from $1,950 2026-02-12
Ipados MEDIUM 5.5
CVE-2026-20627

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPa…

Fix: 14.8.4 / 26.3+
Fix from $1,600 2026-02-11
365 Apps MEDIUM 5.5
CVE-2026-21258

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Fix: 16.0.10417.20097+
Fix from $1,600 2026-02-10
Windows 10 1607 HIGH 7.3
CVE-2026-21247

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10