Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Solr HIGH 7.1
CVE-2026-22444

The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the e…

Fix: 9.10.1+
Fix from $1,950 2026-01-21
Wrangler CRITICAL 9.9
CVE-2026-0933

SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com…

Fix: 3.114.17 / 4.59.1+
Fix from $2,300 2026-01-20
Websocket Server HIGH 7.5
CVE-2025-66902

An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive information or cause unexpected server…

No fix yet
Fix from $1,950 2026-01-20
Chrome MEDIUM 5.4
CVE-2026-0903

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type …

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $1,600 2026-01-20
Unclassified HIGH 7.3
CVE-2026-23880

OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the so…

Patch available
Fix from $1,950 2026-01-19
Unclassified MEDIUM 5.3
CVE-2026-23886

Swift W3C TraceContext is a Swift implementation of the W3C Trace Context standard, and Swift OTel is an OpenTelemetry Protocol (OTLP) backend for Sw…

Patch available
Fix from $1,600 2026-01-19
Movary MEDIUM 6.1
CVE-2026-23839

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-si…

Fix: 0.70.0+
Fix from $1,600 2026-01-19
Movary MEDIUM 6.1
CVE-2026-23840

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-si…

Fix: 0.70.0+
Fix from $1,600 2026-01-19
Movary MEDIUM 6.1
CVE-2026-23841

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-si…

Fix: 0.70.0+
Fix from $1,600 2026-01-19
Hotcrp HIGH 8.8
CVE-2026-23836

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP form…

Fix: 3.2+
Fix from $1,950 2026-01-19
Quicly HIGH 7.5
CVE-2025-61684

Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. …

Fix: 2026-01-18+
Fix from $1,950 2026-01-19
Linkis HIGH 7.5
CVE-2025-29847

A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if…

Fix: 1.8.0+
Fix from $1,950 2026-01-19
Unclassified MEDIUM 5.8
CVE-2025-12718

The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6. This is due to the 'qcf_val…

Mitigation only
Fix from $1,600 2026-01-17
Android HIGH 7.8
CVE-2025-48647

In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This coul…

Mitigation only
Fix from $1,950 2026-01-16
Tl Wr841n Firmware HIGH 7.5
CVE-2025-9014

A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input vali…

Fix: 250908+
Fix from $1,950 2026-01-15
Dome Flare Firmware MEDIUM 6.8
CVE-2025-65397

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacke…

Fix: after 24.1114.151.929
Fix from $1,600 2026-01-14
Emui MEDIUM 5.5
CVE-2025-68970

Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service co…

Mitigation only
Fix from $1,600 2026-01-14
Harmonyos MEDIUM 5.5
CVE-2025-68964

Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-01-14
Go Ethereum HIGH 7.5
CVE-2026-22862

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a spe…

Fix: 1.16.8+
Fix from $1,950 2026-01-13
Go Ethereum HIGH 7.5
CVE-2026-22868

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a spe…

Fix: 1.16.8+
Fix from $1,950 2026-01-13
Kibana MEDIUM 6.5
CVE-2026-0543

Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially…

Fix: 8.19.0 / 9.1.10+
Fix from $1,600 2026-01-13
Arubaos HIGH 7.2
CVE-2025-37173

An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating…

Fix: 8.10.0.21 / 8.13.1.1+
Fix from $1,950 2026-01-13
Dreamweaver HIGH 8.6
CVE-2026-21268

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code executio…

Fix: 21.7+
Fix from $1,950 2026-01-13
Dreamweaver HIGH 8.6
CVE-2026-21271

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code executio…

Fix: 21.7+
Fix from $1,950 2026-01-13
Dreamweaver HIGH 8.6
CVE-2026-21272

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system wri…

Fix: 21.7+
Fix from $1,950 2026-01-13
Sharepoint Server HIGH 7.8
CVE-2026-20951

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Fix: 16.0.19127.20442+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 8.1
CVE-2026-20856

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 6.5
CVE-2026-20812

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Rbe971 Firmware HIGH 8.0
CVE-2026-0403

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injecti…

Fix: 7.2.8.5 / 9.10.0.2+
Fix from $1,950 2026-01-13
Rbr750 Firmware HIGH 8.0
CVE-2026-0404

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over W…

Fix: 7.2.8.5+
Fix from $1,950 2026-01-13