Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.2 CVE-2026-47903 CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker cou… C2pa after 0.80.1 Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-34712 CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker cou… C2pa after 0.80.1 Fix from $1,9502026-06-09 HIGH 8.4 CVE-2026-47931 ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $1,9502026-06-09 CRITICAL 9.6 CVE-2026-47928 ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-06-09 HIGH 8.1 CVE-2026-47930 ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature by… Coldfusion Mitigation only Fix from $1,9502026-06-09 MEDIUM 6.3 CVE-2026-47909 Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system rea… Dreamweaver 21.8+ Fix from $1,6002026-06-09 HIGH 8.8 CVE-2026-9211 An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. Cax30 Firmware 1.0.5.34 / 1.0.10.72+ Fix from $1,9502026-06-09 HIGH 8.0 CVE-2026-9212 Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impactin… Lbr1020 Firmware 1.0.4.96 / 1.0.5.50+ Fix from $1,9502026-06-09 HIGH 8.1 CVE-2026-9213 A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and … Mr70 Firmware 1.0.2.86 / 1.0.4.48+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-49475 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.11.0+ Fix from $1,9502026-06-09 CRITICAL 9.1 CVE-2026-49840 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.11.1+ Fix from $2,3002026-06-09 MEDIUM 5.5 CVE-2026-48569 Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Visual Studio Code 1.123.2+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-47641 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 7.8 CVE-2026-45636 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-44811 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 11 26h1 10.0.28000.2269+ Fix from $1,9502026-06-09 HIGH 8.1 CVE-2026-40376 Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Visual Studio Code 1.123.2+ Fix from $1,9502026-06-09 HIGH 8.0 CVE-2026-0419 Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local W… Jr6150 Firmware Mitigation only Fix from $1,9502026-06-09 CRITICAL 9.6 CVE-2026-11697 Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox … Chrome 149.0.7827.103+ Fix from $2,3002026-06-09 MEDIUM 5.4 CVE-2026-11701 Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HT… Chrome 149.0.7827.103+ Fix from $1,6002026-06-09 HIGH 8.1 CVE-2026-11689 Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer proc… Chrome 149.0.7827.103+ Fix from $1,9502026-06-09 HIGH 8.3 CVE-2026-11682 Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer pr… Chrome 149.0.7827.102+ Fix from $1,9502026-06-09 HIGH 8.3 CVE-2026-11676 Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had c… Chrome 149.0.7827.102+ Fix from $1,9502026-06-09 HIGH 8.3 CVE-2026-11660 Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the… Chrome 149.0.7827.103+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-11666 Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a c… Chrome 149.0.7827.103+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-11653 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer proces… Chrome 149.0.7827.103+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-11658 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the r… Chrome 149.0.7827.103+ Fix from $1,6002026-06-09 CRITICAL 9.6 CVE-2026-11659 Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a craf… Chrome 149.0.7827.103+ Fix from $2,3002026-06-09 HIGH 7.5 CVE-2026-49234 When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only a… Routinator 0.15.2+ Fix from $1,9502026-06-08 HIGH 7.5 CVE-2026-47430 ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPlugi… Cordova Inappbrowser 6.0.1+ Fix from $1,9502026-06-08 HIGH 7.3 CVE-2026-11460 A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of… Mitigation only Fix from $1,9502026-06-07