Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.1 CVE-2026-61363 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-59134 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-48436 CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could l… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.8 CVE-2026-27765 Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may all… No fix yet Fix from $4,0002026-08-11 HIGH 8.7 CVE-2026-21273 is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vul… Coldfusion No fix yet Fix from $4,9002026-08-11 HIGH 8.2 CVE-2026-21279 is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabili… Coldfusion No fix yet Fix from $4,9002026-08-11 HIGH 8.2 CVE-2026-20715 Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may… No fix yet Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-48056 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable pat… No fix yet Fix from $5,7502026-08-11 HIGH 7.5 CVE-2026-71217 A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameter… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.1 CVE-2026-73158 Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.9 CVE-2026-72867 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/serve… No fix yet Fix from $5,7502026-08-10 MEDIUM 6.3 CVE-2026-72728 Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-42537 Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $5,7502026-08-10 MEDIUM 6.8 CVE-2026-21083 Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. No fix yet Fix from $4,0002026-08-10 MEDIUM 5.1 CVE-2026-21070 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. No fix yet Fix from $4,0002026-08-10 MEDIUM 5.1 CVE-2026-21071 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. No fix yet Fix from $4,0002026-08-10 MEDIUM 5.1 CVE-2026-21072 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. No fix yet Fix from $4,0002026-08-10 HIGH 7.8 CVE-2026-21066 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. Android No fix yet Fix from $4,9002026-08-10 MEDIUM 6.7 CVE-2026-21060 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-21061 Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction… Android No fix yet Fix from $4,0002026-08-10 HIGH 7.1 CVE-2026-21058 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. Android No fix yet Fix from $4,9002026-08-10 MEDIUM 5.3 CVE-2026-19363 A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda… No fix yet Fix from $4,0002026-08-09 MEDIUM 6.8 CVE-2026-9031 An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by … No fix yet Fix from $1,6002026-08-07 HIGH 8.7 CVE-2026-47662 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 HIGH 8.6 CVE-2026-47664 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling … No fix yet Fix from $1,9502026-08-07 CRITICAL 9.6 CVE-2026-50540 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P… No fix yet Fix from $2,3002026-08-07 MEDIUM 5.0 CVE-2026-62293 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command con… No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-62295 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in … No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-62296 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no… No fix yet Fix from $1,9502026-08-07