Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Oneflow HIGH 7.5
CVE-2025-71007

An input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a craf…

No fix yet
Fix from $1,950 2026-01-28
Oneflow HIGH 7.5
CVE-2025-71003

An input validation vulnerability in the flow.arange() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted …

No fix yet
Fix from $1,950 2026-01-28
Diskpulse HIGH 7.5
CVE-2025-59895

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration…

Mitigation only
Fix from $1,950 2026-01-28
Tapo C220 Firmware HIGH 7.5
CVE-2026-0919

The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively long URL path. An invalid‑URL er…

Fix: 1.2.3 / 1.4.2+
Fix from $1,950 2026-01-27
Tapo C220 Firmware HIGH 7.5
CVE-2026-1315

By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying a…

Fix: 1.2.3 / 1.4.2+
Fix from $1,950 2026-01-27
Cpu Z MEDIUM 5.5
CVE-2025-65264

The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface, allowing an attacker to acc…

Fix: after 2.17
Fix from $1,600 2026-01-27
Ezcast Pro Dongle Ii Firmware MEDIUM 5.3
CVE-2026-24347

Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory

Mitigation only
Fix from $1,600 2026-01-27
Ezcast Pro Dongle Ii Firmware MEDIUM 6.1
CVE-2026-24348

Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code i…

Mitigation only
Fix from $1,600 2026-01-27
Ezcast Pro Dongle Ii Firmware HIGH 8.8
CVE-2026-24345

Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to t…

Mitigation only
Fix from $1,950 2026-01-27
Root CRITICAL 9.8
CVE-2026-24811

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.

Fix: after 6.34.08
Fix from $2,300 2026-01-27
Iccdev HIGH 8.8
CVE-2026-24410

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have U…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
Iccdev HIGH 8.8
CVE-2026-24411

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have U…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
Iccdev HIGH 8.8
CVE-2026-24412

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
Iccdev HIGH 8.8
CVE-2026-24409

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have U…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
Iccdev HIGH 8.8
CVE-2026-24406

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
Iccdev HIGH 8.8
CVE-2026-24407

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have U…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
Iccdev HIGH 8.8
CVE-2026-24403

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
Iccdev HIGH 8.8
CVE-2026-24404

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CI…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
Iccdev HIGH 8.8
CVE-2026-24405

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a…

Fix: 2.3.1.2+
Fix from $1,950 2026-01-24
On Prem Enterprise Server CRITICAL 9.8
CVE-2025-27378

AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this …

Fix: 7.0.6+
Fix from $2,300 2026-01-22
Group Office MEDIUM 5.4
CVE-2026-23887

Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25.0.1 through 25.0.79, the app…

Fix: 6.8.149 / 25.0.80+
Fix from $1,600 2026-01-22
Unclassified HIGH 7.1
CVE-2026-22598

ManageIQ is an open-source management platform. A flaw was found in the ManageIQ API prior to version radjabov-2 where a malformed TimeProfile could …

Patch available
Fix from $1,950 2026-01-21
Everest HIGH 7.4
CVE-2025-68134

EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module …

Fix: 2025.10.0+
Fix from $1,950 2026-01-21
Ollama HIGH 7.5
CVE-2025-66959

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

No fix yet
Fix from $1,950 2026-01-21
Ollama HIGH 7.5
CVE-2025-66960

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string …

No fix yet
Fix from $1,950 2026-01-21
Solr HIGH 7.1
CVE-2026-22444

The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the e…

Fix: 9.10.1+
Fix from $1,950 2026-01-21
Wrangler CRITICAL 9.9
CVE-2026-0933

SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com…

Fix: 3.114.17 / 4.59.1+
Fix from $2,300 2026-01-20
Websocket Server HIGH 7.5
CVE-2025-66902

An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive information or cause unexpected server…

No fix yet
Fix from $1,950 2026-01-20
Chrome MEDIUM 5.4
CVE-2026-0903

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type …

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $1,600 2026-01-20
Unclassified HIGH 7.3
CVE-2026-23880

OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the so…

Patch available
Fix from $1,950 2026-01-19