Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.3 CVE-2026-7905 Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised … Chrome 148.0.7778.96+ Fix from $1,9502026-05-06 HIGH 8.8 CVE-2026-40068 In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its co… Claude Code 2.1.84+ Fix from $1,9502026-05-05 MEDIUM 6.5 CVE-2026-32603 Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exi… Sandboxie 1.17.3+ Fix from $1,6002026-05-05 HIGH 8.1 CVE-2026-6180 A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions invo… Papercut Mf 24.1.9 / 25.0.10+ Fix from $1,9502026-05-05 CRITICAL 9.9 CVE-2026-42809 Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42810 Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42811 In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 MEDIUM 6.5 CVE-2026-37458 Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denia… Frrouting after 10.6.0 Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7712 A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipul… Mitigation only Fix from $1,6002026-05-04 MEDIUM 6.3 CVE-2026-7597 A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Per… Patch available Fix from $1,6002026-05-01 HIGH 7.8 CVE-2025-52347 An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 … Mitigation only Fix from $1,9502026-05-01 MEDIUM 6.5 CVE-2026-1577 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user … Db2 after 12.1.4 Fix from $1,6002026-04-30 HIGH 7.5 CVE-2025-46115 An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request Mitigation only Fix from $1,9502026-04-30 HIGH 8.8 CVE-2026-5174 Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: fr… Moveit Automation 2024.1.8 / 2025.1.5+ Fix from $1,9502026-04-30 HIGH 7.8 CVE-2025-14576 Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the Vect… Qtdeclarative 6.8.6 / 6.10.1+ Fix from $1,9502026-04-30 HIGH 7.8 CVE-2026-30769 An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending cr… Tvicport Mitigation only Fix from $1,9502026-04-29 HIGH 8.3 CVE-2026-7345 Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the ren… Chrome 147.0.7727.138+ Fix from $1,9502026-04-28 MEDIUM 5.0 CVE-2026-7317 A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system… Patch available Fix from $1,6002026-04-28 MEDIUM 6.5 CVE-2026-24204 NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this v… Nvflare 2.7.2+ Fix from $1,6002026-04-28 MEDIUM 6.5 CVE-2024-54011 Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, ca… Knb 2000 Firmware 2.23.01+ Fix from $1,6002026-04-28 HIGH 7.1 CVE-2026-5941 Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to inv… Pdf Editor 14.0.4 / 2026.1.1+ Fix from $1,9502026-04-27 HIGH 8.8 CVE-2026-40466 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-41044 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache… Activemq 5.19.6 / 6.2.5+ Fix from $1,9502026-04-24 CRITICAL 9.8 CVE-2026-41268EPSS 14% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen… Flowise 3.1.0+ Fix from $2,3002026-04-23 MEDIUM 5.3 CVE-2026-34066 nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStore::put_historic_txns` uses an… Nimiq Proof Of Stake 1.3.0+ Fix from $1,6002026-04-22 CRITICAL 9.6 CVE-2026-33471 nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len… Nimiq Proof Of Stake 1.3.0+ Fix from $2,3002026-04-22 MEDIUM 5.5 CVE-2026-35380 A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte string '' (two single quotes) a… Coreutils 0.8.0+ Fix from $1,6002026-04-22 MEDIUM 5.5 CVE-2026-35369 An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send the default signal (SIGTERM) to… Coreutils 0.6.0+ Fix from $1,6002026-04-22 MEDIUM 6.5 CVE-2026-31192 Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user da… Raindrop Mitigation only Fix from $1,6002026-04-22