Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unclassified HIGH 7.7
CVE-2026-69192

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21553

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21554

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21555

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21548

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21549

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21550

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21551

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21552

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-59650

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS b…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified HIGH 8.6
CVE-2025-71399

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments,…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.0
CVE-2026-67326

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary sect…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.9
CVE-2026-67330

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authoriza…

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67296

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length b…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-54909

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS att…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.9
CVE-2026-53551

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate …

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-53503

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>…

No fix yet
Fix from $1,950 2026-07-31
Build Of Keycloak MEDIUM 5.4
CVE-2026-18211

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.8
CVE-2026-65834

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex a…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.9
CVE-2026-59881

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames…

No fix yet
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-18014

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restric…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-18002

Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the r…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17987

Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17988

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17990

Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rend…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17991

Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer p…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17940

Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17929

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restric…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome HIGH 7.5
CVE-2026-17930

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17921

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30