Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.3 CVE-2026-9914 Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the render… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 MEDIUM 5.0 CVE-2026-9903 Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised t… Chrome 148.0.7778.216+ Fix from $1,6002026-05-28 HIGH 8.3 CVE-2026-9898 Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised t… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9885 Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the re… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-9880 Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the render… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.3 CVE-2026-10020 Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised … Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-10021 Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a … Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 MEDIUM 6.5 CVE-2026-10004 Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform UI spoofing via… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-49095 Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with F… Kibana 8.19.16 / 9.3.5+ Fix from $1,6002026-05-28 HIGH 7.3 CVE-2026-30760 An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX … Mitigation only Fix from $1,9502026-05-28 HIGH 8.2 CVE-2026-45137 Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anc… Mitigation only Fix from $1,9502026-05-27 HIGH 7.2 CVE-2026-5509 An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary… Archer Be450 Firmware 1.3.0+ Fix from $1,9502026-05-27 HIGH 7.1 CVE-2026-42553 Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permissions to create room emotes … Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-44319 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscr… Free5gc 4.2.2+ Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-44325 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser… Free5gc 4.2.2+ Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-42459 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter … Free5gc 4.2.2+ Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-48922 Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing a… Credentials Binding 725.ve52b_2328a_fde+ Fix from $1,9502026-05-27 MEDIUM 5.5 CVE-2026-24195 NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vul… Gpu Display Driver 535.309.01 / 539.72+ Fix from $1,6002026-05-26 MEDIUM 6.0 CVE-2025-33221 NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignmen… Gpu Display Driver 535.309.01 / 539.72+ Fix from $1,6002026-05-26 CRITICAL 9.0 CVE-2026-45721 Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without … Mitigation only Fix from $2,3002026-05-26 HIGH 8.1 CVE-2026-43935 e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manip… Patch available Fix from $1,9502026-05-26 HIGH 7.3 CVE-2026-9521 A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitser… Patch available Fix from $1,9502026-05-26 MEDIUM 6.3 CVE-2026-9497 A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson Aut… Mitigation only Fix from $1,6002026-05-25 HIGH 8.8 CVE-2026-40411 Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. Azure Virtual Network Gateway Mitigation only Fix from $1,9502026-05-22 HIGH 7.7 CVE-2026-26147 Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. Azure Stack Hci Mitigation only Fix from $1,9502026-05-22 HIGH 8.8 CVE-2026-3294 An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a l… Re305 Firmware 20260429 / 20260515+ Fix from $1,9502026-05-22 HIGH 7.6 CVE-2026-34207 TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, bloc… Patch available Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-44417 The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lea… Cxf 3.6.11 / 4.1.6+ Fix from $1,9502026-05-22 CRITICAL 10.0 CVE-2026-34910 KEVEPSS 87% A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command … Unifi Os Server 5.0.8 / 5.1.12+ Fix from $2,3002026-05-22 CRITICAL 9.1 CVE-2026-33000 A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices t… Unifi Os Server 5.0.8+ Fix from $2,3002026-05-22