Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.4 CVE-2026-9157 Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issu… Mitigation only Fix from $1,9502026-05-21 MEDIUM 5.3 CVE-2026-9124 Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the ren… Chrome 148.0.7778.178+ Fix from $1,6002026-05-20 HIGH 7.4 CVE-2026-39850 Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that lea… Patch available Fix from $1,9502026-05-20 MEDIUM 6.5 CVE-2026-20240 In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.… Splunk 9.3.12 / 9.3.2411.129+ Fix from $1,6002026-05-20 HIGH 7.5 CVE-2026-5946 Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `… Bind 9.18.49 / 9.20.23+ Fix from $1,9502026-05-20 CRITICAL 9.6 CVE-2026-8959 Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, … Firefox 140.11 / 140.11.0+ Fix from $2,3002026-05-19 MEDIUM 6.5 CVE-2026-31378 Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to vers… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 HIGH 7.2 CVE-2026-27891 FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() fu… Patch available Fix from $1,9502026-05-18 CRITICAL 9.8 CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Edge Chromium 148.0.3967.70+ Fix from $2,3002026-05-18 MEDIUM 5.4 CVE-2026-45492 Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 148.0.3967.70+ Fix from $1,6002026-05-18 MEDIUM 6.5 CVE-2026-20685 An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation.… Private Cloud Compute 5e290.3+ Fix from $1,6002026-05-18 HIGH 7.3 CVE-2026-8759 A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-cla… Mitigation only Fix from $1,9502026-05-17 CRITICAL 9.8 CVE-2026-8751 A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Mod… H2o after 7402 Fix from $2,3002026-05-17 MEDIUM 6.3 CVE-2026-8735 A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the … Mitigation only Fix from $1,6002026-05-17 HIGH 8.4 CVE-2025-29936 Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impa… Mitigation only Fix from $1,9502026-05-15 HIGH 8.7 CVE-2026-42327 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP respond… Mitigation only Fix from $1,9502026-05-14 MEDIUM 5.3 CVE-2026-8538 Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 HIGH 8.8 CVE-2026-8527 Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code … Chrome 148.0.7778.168+ Fix from $1,9502026-05-14 MEDIUM 5.3 CVE-2026-8516 Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 MEDIUM 6.5 CVE-2026-26062 Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `Publi… Fleet 4.81.0+ Fix from $1,6002026-05-14 HIGH 8.6 CVE-2026-44522 Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload ass… No fix yet Fix from $1,9502026-05-14 HIGH 8.6 CVE-2026-20224 A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbi… Catalyst Sd Wan Manager 20.9.9.1 / 20.12.5.4+ Fix from $1,9502026-05-14 CRITICAL 9.6 CVE-2026-44482 soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an… Mitigation only Fix from $2,3002026-05-14 MEDIUM 5.4 CVE-2026-44425 ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each fi… Shellhub 0.24.2+ Fix from $1,6002026-05-13 HIGH 8.1 CVE-2026-45055 CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at boots… Mitigation only Fix from $1,9502026-05-13 MEDIUM 5.3 CVE-2026-44379 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uu… Misp 2.5.37+ Fix from $1,6002026-05-13 CRITICAL 9.1 CVE-2026-42579 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC… Netty 4.1.133 / 4.2.13+ Fix from $2,3002026-05-13 MEDIUM 6.3 CVE-2026-2695 A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Im… Mitigation only Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2026-44294 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors… Protobufjs 7.5.6 / 8.0.2+ Fix from $1,6002026-05-13 MEDIUM 6.0 CVE-2026-8369 Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all platforms allows an attacker on t… Patch available Fix from $1,6002026-05-13