Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ipados MEDIUM 5.5
CVE-2026-43714

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequ…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.9
CVE-2026-54272

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF thr…

No fix yet
Fix from $1,600 2026-07-27
Nimble MEDIUM 5.3
CVE-2026-46452

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resultin…

Fix: 1.10.0+
Fix from $1,600 2026-07-24
Surface Management Services HIGH 8.8
CVE-2026-54120

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.2
CVE-2026-65604

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies…

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-47668

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.0
CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 7.3
CVE-2026-16632

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/w…

No fix yet
Fix from $1,950 2026-07-23
MongoDB MEDIUM 6.5
CVE-2026-13057

An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $sea…

Fix: 8.0.28 / 8.2.12+
Fix from $1,600 2026-07-22
Powerprotect Data Manager HIGH 7.2
CVE-2026-46737

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged …

Fix: 20.2+
Fix from $1,950 2026-07-22
Powerprotect Data Manager HIGH 7.2
CVE-2026-46738

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged …

Fix: 20.2+
Fix from $1,950 2026-07-22
Powerprotect Data Manager HIGH 7.2
CVE-2026-40712

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged …

Fix: 20.2+
Fix from $1,950 2026-07-22
Powerprotect Data Manager HIGH 7.2
CVE-2026-40714

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with re…

Fix: 20.2+
Fix from $1,950 2026-07-22
Unbound HIGH 7.5
CVE-2026-55973

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the la…

Fix: 1.25.2+
Fix from $1,950 2026-07-22
Unclassified HIGH 7.5
CVE-2026-57600

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive …

No fix yet
Fix from $1,950 2026-07-22
Unclassified MEDIUM 6.9
CVE-2026-16551

Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.

No fix yet
Fix from $1,600 2026-07-22
Chrome MEDIUM 5.4
CVE-2026-16415

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of …

Fix: 150.0.7871.182+
Fix from $1,600 2026-07-21
Chrome HIGH 8.8
CVE-2026-16421

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbo…

Fix: 150.0.7871.182+
Fix from $1,950 2026-07-21
Chrome HIGH 7.5
CVE-2026-16422

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged netwo…

Fix: 150.0.7871.182+
Fix from $1,950 2026-07-21
Chrome HIGH 7.8
CVE-2026-16414

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a s…

Fix: 150.0.7871.182+
Fix from $1,950 2026-07-21
E Business Suite MEDIUM 6.3
CVE-2026-62519

Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affecte…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
Commerce Experience Manager HIGH 8.1
CVE-2026-61160

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). …

Mitigation only
Fix from $1,950 2026-07-21
Goldengate MEDIUM 5.8
CVE-2026-61079

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26…

Fix: after 23.26.2.0.0
Fix from $1,600 2026-07-21
Bi Publisher CRITICAL 9.9
CVE-2026-60719

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.…

No fix yet
Fix from $2,300 2026-07-21
Webcenter Content HIGH 8.0
CVE-2026-60648

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.0
CVE-2026-60650

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60634

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60636

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

Mitigation only
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60637

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60638

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21