Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.5 CVE-2026-47201 authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerabl… Authentik 2025.12.6 / 2026.2.4+ Fix from $1,9502026-06-02 MEDIUM 6.5 CVE-2026-35049 wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external mes… Mitigation only Fix from $1,6002026-06-02 HIGH 7.5 CVE-2026-45685 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, mal… Ebpf Instrumentation 0.9.0+ Fix from $1,9502026-06-02 MEDIUM 5.5 CVE-2026-45676 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI's replacement ELF p… Ebpf Instrumentation 0.9.0+ Fix from $1,6002026-06-02 HIGH 7.5 CVE-2026-45678 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol p… Ebpf Instrumentation 0.9.0+ Fix from $1,9502026-06-02 HIGH 8.1 CVE-2026-7195 CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.… Sitefinity 14.4.8152 / 15.0.8234+ Fix from $1,9502026-06-02 MEDIUM 5.3 CVE-2026-10566 A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/… Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.5 CVE-2026-28578 In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could le… Android Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.5 CVE-2026-0085 In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This coul… Android Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.5 CVE-2026-0070 In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation.… Android Mitigation only Fix from $1,6002026-06-01 HIGH 7.8 CVE-2026-0078 In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to … Android Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-0051 In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lea… Android Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.5 CVE-2026-0018 In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This co… Android Mitigation only Fix from $1,6002026-06-01 HIGH 7.8 CVE-2025-22424 In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of… Android Mitigation only Fix from $1,9502026-06-01 CRITICAL 9.1 CVE-2026-22872 Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantR… Capsule 0.13.0+ Fix from $2,3002026-06-01 HIGH 7.1 CVE-2026-46243 In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descript… Linux Kernel 5.10.258 / 5.15.209+ Fix from $1,9502026-06-01 HIGH 8.1 CVE-2026-42588 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01 HIGH 8.8 CVE-2026-45505 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01 CRITICAL 9.1 CVE-2026-48188 An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which … Otrs 2026.4.1+ Fix from $2,3002026-06-01 HIGH 7.5 CVE-2026-45352 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding c… Cpp Httplib 0.43.4+ Fix from $1,9502026-05-29 MEDIUM 5.3 CVE-2026-44518 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds… Liboqs after 0.15.0 Fix from $1,6002026-05-29 CRITICAL 9.6 CVE-2026-45628 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template lit… Mitigation only Fix from $2,3002026-05-29 HIGH 8.2 CVE-2026-45615 mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated … Mitigation only Fix from $1,9502026-05-29 MEDIUM 5.0 CVE-2026-9979 Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the render… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,6002026-05-28 MEDIUM 5.0 CVE-2026-9980 Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the ren… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,6002026-05-28 HIGH 8.3 CVE-2026-9982 Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the render… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 MEDIUM 5.3 CVE-2026-9985 Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromise… Chrome 148.0.7778.216+ Fix from $1,6002026-05-28 HIGH 7.8 CVE-2026-9987 Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute … Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9969 Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via … Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9977 Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromi… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28