Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2026-50328 Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 6.3 CVE-2026-15757 A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the… No fix yet Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-55899 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20175+ Fix from $1,9502026-07-14 MEDIUM 5.3 CVE-2026-6790 In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided i… Jetty 9.4.61 / 10.0.29+ Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-13699 In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point … Kuksa No fix yet Fix from $1,6002026-07-14 CRITICAL 9.3 CVE-2026-22102 A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in… Mitigation only Fix from $2,3002026-07-13 MEDIUM 5.3 CVE-2026-15531 A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function… Patch available Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15535 A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.d… Patch available Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15529 A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py… Patch available Fix from $1,6002026-07-13 HIGH 7.2 CVE-2026-3576 The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all version… Mitigation only Fix from $1,9502026-07-11 MEDIUM 5.9 CVE-2026-11914 vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. No fix yet Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-40454 Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer … Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-15288 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and i… Mitigation only Fix from $1,9502026-07-10 MEDIUM 6.5 CVE-2026-0282 A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web in… Pan Os 11.1.16 / 11.2.13+ Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-51606 An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP … Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.5 CVE-2026-51598 An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, networ… Mitigation only Fix from $1,6002026-07-09 CRITICAL 9.8 CVE-2026-51599 An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remot… No fix yet Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-58146 There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised in… No fix yet Fix from $2,3002026-07-09 HIGH 8.3 CVE-2026-15122 Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromise… Chrome 150.0.7871.115+ Fix from $1,9502026-07-08 MEDIUM 6.3 CVE-2026-15105 A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp … No fix yet Fix from $1,6002026-07-08 HIGH 8.8 CVE-2026-10037 A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files ma… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59724 Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enable… Engine.io 6.6.7+ Fix from $1,9502026-07-08 CRITICAL 9.1 CVE-2026-41042 Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's … Mitigation only Fix from $2,3002026-07-08 HIGH 7.5 CVE-2026-54234 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative dec… Vllm 0.24.0+ Fix from $1,9502026-07-06 CRITICAL 10.0 CVE-2026-48316 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-07-06 HIGH 7.3 CVE-2026-49042 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Us… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-46587 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-46588 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-55994 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 CRITICAL 9.8 CVE-2026-56140 Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-s… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06