Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2026-43724 The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS … Ipados 26.5.2+ Fix from $1,9502026-06-29 HIGH 7.1 CVE-2026-43725 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 2… Safari 26.5.2+ Fix from $1,9502026-06-29 CRITICAL 9.1 CVE-2026-39868 This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS S… Ipados 26.5.2+ Fix from $2,3002026-06-29 HIGH 7.5 CVE-2026-38639 An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a cr… Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.6 CVE-2026-52780 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (… Mitigation only Fix from $2,3002026-06-26 MEDIUM 5.9 CVE-2026-42387 A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input … Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.9 CVE-2026-42388 Incomplete validation of the SOA record present in a catalog zone might lead to a crash. Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-42389 This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers. No fix yet Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-42390 An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation. Mitigation only Fix from $1,6002026-06-25 HIGH 8.1 CVE-2026-12246 NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite t… Nsd 4.14.3+ Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-52801 Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well prot… Patch available Fix from $1,9502026-06-24 HIGH 8.3 CVE-2026-13025 Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a… Chrome 149.0.7827.197+ Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-48720 Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;F… Patch available Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-48704 Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local file… Patch available Fix from $1,9502026-06-24 HIGH 7.8 CVE-2026-12537 Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Act… Gemini Cli 0.1.22 / 0.39.1+ Fix from $1,9502026-06-24 HIGH 7.0 CVE-2026-13006 ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allow… Mitigation only Fix from $1,9502026-06-24 CRITICAL 9.6 CVE-2026-54588 Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` requ… Mitigation only Fix from $2,3002026-06-23 HIGH 8.1 CVE-2026-45135 Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/rev… Caddy 2.11.3+ Fix from $1,9502026-06-23 HIGH 8.5 CVE-2026-49444 n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify … N8n 1.123.48 / 2.21.8+ Fix from $1,9502026-06-23 MEDIUM 5.3 CVE-2026-56762 Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing inval… No fix yet Fix from $1,6002026-06-23 MEDIUM 6.5 CVE-2026-10651 bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte a… Zephyr after 4.4.1 Fix from $1,6002026-06-23 MEDIUM 6.4 CVE-2026-56306 Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypass subkey enforcement by subm… Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.5 CVE-2026-54911 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujso… Ultrajson 5.13.0+ Fix from $1,6002026-06-22 HIGH 8.2 CVE-2026-48109 MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used… Messagepack 2.5.301 / 3.1.7+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-54299 Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those … Astro 6.4.6+ Fix from $1,9502026-06-22 HIGH 8.6 CVE-2026-55602 http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-tabl… Http Proxy Middleware 2.0.10 / 3.0.6+ Fix from $1,9502026-06-22 MEDIUM 5.3 CVE-2026-53537 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) head… Python Multipart 0.0.30+ Fix from $1,6002026-06-22 CRITICAL 9.4 CVE-2026-7165 The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of othe… Mitigation only Fix from $2,3002026-06-22 MEDIUM 6.3 CVE-2026-12787 A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part o… Mitigation only Fix from $1,6002026-06-21 HIGH 7.5 CVE-2026-56340 vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor… Vllm 0.13.0+ Fix from $1,9502026-06-20