Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.9 CVE-2026-47370 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run… Mitigation only Fix from $2,3002026-06-12 MEDIUM 5.3 CVE-2026-12025 Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the rend… Chrome 149.0.7827.115+ Fix from $1,6002026-06-11 HIGH 8.3 CVE-2026-12034 Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who h… Chrome 149.0.7827.115+ Fix from $1,9502026-06-11 HIGH 8.3 CVE-2026-12016 Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process … Chrome 149.0.7827.115+ Fix from $1,9502026-06-11 HIGH 8.3 CVE-2026-12009 Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had comprom… Chrome 149.0.7827.115+ Fix from $1,9502026-06-11 HIGH 8.7 CVE-2026-47181 PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allow… Mitigation only Fix from $1,9502026-06-11 HIGH 8.2 CVE-2026-49982 tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that conta… Tmp No fix yet Fix from $1,9502026-06-11 MEDIUM 5.8 CVE-2026-53723 Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize re… Mitigation only Fix from $1,6002026-06-11 MEDIUM 5.3 CVE-2026-48998 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing … Psr 7 2.10.2+ Fix from $1,6002026-06-11 MEDIUM 5.3 CVE-2026-49214 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, … Psr 7 2.10.2+ Fix from $1,6002026-06-11 HIGH 8.7 CVE-2026-53901 Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacke… Patch available Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-49218 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing ch… Imagemagick 6.9.13-48 / 7.1.2-24+ Fix from $1,9502026-06-10 MEDIUM 5.3 CVE-2024-21944 Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with … Mitigation only Fix from $1,6002026-06-10 MEDIUM 5.3 CVE-2026-48108 Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string… No fix yet Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-48110 Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded a… No fix yet Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-46669 OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library… Openvm 1.6.0+ Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-46679 libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an… Mitigation only Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-48107 Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication pa… Mitigation only Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-45783 libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storag… Mitigation only Fix from $1,9502026-06-10 HIGH 8.1 CVE-2026-45062 FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org… Mitigation only Fix from $1,9502026-06-10 MEDIUM 5.7 CVE-2026-20255 In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.250… Splunk 9.3.13 / 9.3.2411.132+ Fix from $1,6002026-06-10 MEDIUM 5.7 CVE-2026-20256 In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.250… Splunk 9.3.13 / 9.3.2411.132+ Fix from $1,6002026-06-10 MEDIUM 5.7 CVE-2026-20257 In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.250… Splunk 9.3.13 / 9.3.2411.132+ Fix from $1,6002026-06-10 MEDIUM 5.7 CVE-2026-20254 In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.250… Splunk 9.3.13 / 9.3.2411.132+ Fix from $1,6002026-06-10 HIGH 8.1 CVE-2026-45565 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxy… Mitigation only Fix from $1,9502026-06-10 CRITICAL 9.9 CVE-2026-45556 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45558 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi… Mitigation only Fix from $2,3002026-06-10 HIGH 8.8 CVE-2026-45328 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrap… Esp Idf Patch available Fix from $1,9502026-06-10 MEDIUM 6.5 CVE-2026-45329 ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_se… Esp Idf Patch available Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-41727 Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a … Spring For Apache Kafka 2.8.12 / 2.9.14+ Fix from $1,6002026-06-10