Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Power Bi Report Server HIGH 8.8
CVE-2026-21229

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

Fix: 15.0.1120.113+
Fix from $1,950 2026-02-10
Unclassified HIGH 8.2
CVE-2025-25210

Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an esc…

Mitigation only
Fix from $1,950 2026-02-10
Unclassified HIGH 7.5
CVE-2025-22453

Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an esc…

Mitigation only
Fix from $1,950 2026-02-10
Adminer HIGH 7.5
CVE-2026-25892

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version …

Fix: 5.4.2+
Fix from $1,950 2026-02-09
Tpadmin CRITICAL 9.8
CVE-2026-2113

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/web…

Fix: after 1.3.12
Fix from $2,300 2026-02-07
N8n MEDIUM 6.5
CVE-2026-25631

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validatio…

Fix: 1.121.0+
Fix from $1,600 2026-02-06
Claude Code CRITICAL 9.1
CVE-2026-25722

Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write op…

Fix: 2.0.57+
Fix from $2,300 2026-02-06
Claude Code MEDIUM 6.5
CVE-2026-25723

Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the …

Fix: 2.0.55+
Fix from $1,600 2026-02-06
Unclassified HIGH 8.8
CVE-2025-15566

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inj…

Mitigation only
Fix from $1,950 2026-02-06
Simplicity Software Development Kit MEDIUM 6.5
CVE-2025-12131

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

Fix: after 2025.6.2
Fix from $1,600 2026-02-05
Facturascripts HIGH 8.8
CVE-2026-25514

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL …

Fix: 2025.81+
Fix from $1,950 2026-02-04
Facturascripts HIGH 8.8
CVE-2026-25513

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL …

Fix: 2025.81+
Fix from $1,950 2026-02-04
N8n HIGH 7.2
CVE-2026-21893

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s…

Fix: 1.120.3+
Fix from $1,950 2026-02-04
Unclassified HIGH 8.8
CVE-2026-1580

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configu…

Mitigation only
Fix from $1,950 2026-02-03
Unclassified HIGH 8.8
CVE-2026-24512

A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This…

Mitigation only
Fix from $1,950 2026-02-03
Data Master CRITICAL 9.8
CVE-2026-24936

When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…

Fix: 5.1.2.re51+
Fix from $2,300 2026-02-03
Mediawiki MEDIUM 6.5
CVE-2025-67480

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryRevisionsBase.Php. This is…

Fix: 1.39.16 / 1.43.6+
Fix from $1,600 2026-02-03
Mediawiki CRITICAL 9.8
CVE-2025-67484

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php. This issue affec…

Fix: 1.39.16 / 1.43.6+
Fix from $2,300 2026-02-03
Bolo Solo HIGH 8.8
CVE-2026-1691

A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/…

Fix: after 2.6.4
Fix from $1,950 2026-01-30
Fast Xml Parser HIGH 7.5
CVE-2026-25128

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In v…

Fix: 5.3.4+
Fix from $1,950 2026-01-30
Unclassified HIGH 7.5
CVE-2024-4027

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the cl…

Mitigation only
Fix from $1,950 2026-01-30
Unclassified HIGH 8.3
CVE-2026-25117

pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit e33da14449a5abcff507e554f66e2141d6683b0a, missing sandboxing on…

Patch available
Fix from $1,950 2026-01-29
Polarlearn HIGH 7.1
CVE-2026-25126

PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`POST /api/v1/forum/vote`) trusts the JS…

Patch available
Fix from $1,950 2026-01-29
Archer Re605x Firmware MEDIUM 6.8
CVE-2025-15545

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, …

Fix: 1.2.10+
Fix from $1,600 2026-01-29
Oneflow MEDIUM 6.2
CVE-2025-71011

An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of OneFlow v0.9.0 allows attacker…

No fix yet
Fix from $1,600 2026-01-29
Oneflow MEDIUM 6.2
CVE-2025-71009

An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS…

No fix yet
Fix from $1,600 2026-01-29
Digital Employee Experience MEDIUM 6.5
CVE-2026-23566

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an…

Fix: 26.1+
Fix from $1,600 2026-01-29
Digital Employee Experience MEDIUM 6.5
CVE-2026-23570

A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prio…

Fix: 26.1+
Fix from $1,600 2026-01-29
Digital Employee Experience MEDIUM 6.8
CVE-2026-23571

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction.…

Fix: 26.1+
Fix from $1,600 2026-01-29
Iccdev HIGH 7.8
CVE-2026-24856

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Versions…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-28