Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2026-42544 Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a We… Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.2 CVE-2026-34679 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 MEDIUM 6.2 CVE-2026-34688 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 MEDIUM 6.2 CVE-2026-34666 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 MEDIUM 6.2 CVE-2026-34668 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 MEDIUM 6.2 CVE-2026-34669 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 MEDIUM 6.2 CVE-2026-34670 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could resul… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-23825 Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnera… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-44343 WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allo… Wgdashboard 4.3.2+ Fix from $2,3002026-05-12 MEDIUM 6.5 CVE-2026-44204 Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /ass… Patch available Fix from $1,6002026-05-12 HIGH 7.3 CVE-2026-35433 Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. .net Framework 8.0.27 / 9.0.16+ Fix from $1,9502026-05-12 HIGH 7.3 CVE-2026-32177 Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. Visual Studio 2022 8.0.27 / 9.0.16+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-20767 Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escala… Quickassist Technology 1.13.0-0021+ Fix from $1,9502026-05-12 HIGH 8.5 CVE-2026-43989 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the age… Patch available Fix from $1,9502026-05-12 MEDIUM 6.6 CVE-2026-20905 Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial o… Quickassist Technology 2.6.0-0018+ Fix from $1,6002026-05-12 MEDIUM 6.6 CVE-2026-20717 Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial … Quickassist Technology 1.13.0-0021+ Fix from $1,6002026-05-12 HIGH 8.8 CVE-2025-35990 Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allo… Endpoint Management Assistant 1.14.5.0+ Fix from $1,9502026-05-12 CRITICAL 9.8 CVE-2026-41293 Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1… Tomcat 9.0.118 / 10.1.55+ Fix from $2,3002026-05-12 MEDIUM 5.3 CVE-2026-8391 Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb… Firefox 150.0.3+ Fix from $1,6002026-05-12 HIGH 7.8 CVE-2026-45391 A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary command… Mitigation only Fix from $1,9502026-05-12 HIGH 8.7 CVE-2026-45392 DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an auth… Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-45393 A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorr… Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.6 CVE-2026-43899 DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitig… Mitigation only Fix from $2,3002026-05-11 HIGH 7.5 CVE-2026-28936 The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, ma… Ipados 14.8.7 / 18.7.9+ Fix from $1,9502026-05-11 HIGH 8.1 CVE-2026-28907 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, m… Ipados 18.7.9 / 26.5+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28860 The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia … Ipados 14.8.5 / 15.7.5+ Fix from $1,9502026-05-11 HIGH 7.3 CVE-2026-31251 CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC … Mitigation only Fix from $1,9502026-05-11 CRITICAL 9.4 CVE-2026-42613 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and acc… Patch available Fix from $2,3002026-05-11 HIGH 7.8 CVE-2026-42301 pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the su… Mitigation only Fix from $1,9502026-05-09 CRITICAL 9.6 CVE-2026-44336 PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou… Praisonai 4.6.34+ Fix from $2,3002026-05-08