Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.3 CVE-2026-56762 Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing inval… No fix yet Fix from $1,6002026-06-23 MEDIUM 6.5 CVE-2026-10651 bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte a… Zephyr after 4.4.1 Fix from $1,6002026-06-23 MEDIUM 6.4 CVE-2026-56306 Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypass subkey enforcement by subm… Mitigation only Fix from $1,6002026-06-22 MEDIUM 6.5 CVE-2026-54911 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujso… Ultrajson 5.13.0+ Fix from $1,6002026-06-22 HIGH 8.2 CVE-2026-48109 MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used… Messagepack 2.5.301 / 3.1.7+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-54299 Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those … Astro 6.4.6+ Fix from $1,9502026-06-22 HIGH 8.6 CVE-2026-55602 http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-tabl… Http Proxy Middleware 2.0.10 / 3.0.6+ Fix from $1,9502026-06-22 MEDIUM 5.3 CVE-2026-53537 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) head… Python Multipart 0.0.30+ Fix from $1,6002026-06-22 CRITICAL 9.4 CVE-2026-7165 The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of othe… Mitigation only Fix from $2,3002026-06-22 MEDIUM 6.3 CVE-2026-12787 A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part o… Mitigation only Fix from $1,6002026-06-21 HIGH 7.5 CVE-2026-56340 vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor… Vllm 0.13.0+ Fix from $1,9502026-06-20 HIGH 7.5 CVE-2026-48774 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool vio… Proxysql 4.0.9+ Fix from $1,9502026-06-19 MEDIUM 6.3 CVE-2026-21768 The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input t… Mitigation only Fix from $1,6002026-06-19 HIGH 8.8 CVE-2026-39998 Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof i… Apisix 3.17.0+ Fix from $1,9502026-06-19 HIGH 8.2 CVE-2025-58175 GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `E… Geoserver 2.26.4 / 2.27.3+ Fix from $1,9502026-06-18 CRITICAL 9.8 CVE-2026-12569 KEVEPSS 30% A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t… Flexplm 11.0m030+ Fix from $2,3002026-06-18 HIGH 7.5 CVE-2026-50196 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eu… Patch available Fix from $1,9502026-06-17 CRITICAL 10.0 CVE-2026-48055 Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vul… Mitigation only Fix from $2,3002026-06-17 HIGH 8.3 CVE-2026-12465 Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to pote… Chrome 149.0.7827.155+ Fix from $1,9502026-06-17 HIGH 7.8 CVE-2025-48643 In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with… Android Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.1 CVE-2026-46910 Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions… Jd Edwards Enterpriseone Tools after 9.2.26.2 Fix from $2,3002026-06-17 HIGH 7.8 CVE-2026-12191 A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py… Mitigation only Fix from $1,9502026-06-14 HIGH 8.1 CVE-2026-45013 ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the… Mitigation only Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-54133 jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications wi… Jmespath 2.9.1+ Fix from $2,3002026-06-12 HIGH 8.4 CVE-2026-47196 Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not reject an empty result. Adding … No fix yet Fix from $1,9502026-06-12 HIGH 8.1 CVE-2026-50632 A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 HIGH 8.1 CVE-2026-50633 A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-50628 A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other… Cxf 4.1.7 / 4.2.2+ Fix from $2,3002026-06-12 CRITICAL 9.9 CVE-2026-47367 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agen… Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.9 CVE-2026-47369 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run… Mitigation only Fix from $2,3002026-06-12