Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2026-26170 Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-26161 Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-26156 Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.5 CVE-2026-26154 Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. Windows Server 2012 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-26143 Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. Powershell 7.4.14 / 7.5.5+ Fix from $1,9502026-04-14 MEDIUM 5.5 CVE-2026-39417 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execu… Maxkb 2.8.0+ Fix from $1,6002026-04-14 MEDIUM 5.3 CVE-2026-33948 jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows v… Jq 2026-04-12+ Fix from $1,6002026-04-14 CRITICAL 9.8 CVE-2026-22563 A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. A… Mitigation only Fix from $2,3002026-04-13 HIGH 7.5 CVE-2026-22565 An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause the device to stop responding… Mitigation only Fix from $1,9502026-04-13 HIGH 7.5 CVE-2026-6231 The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for … C Driver 1.30.5 / 2.0.2+ Fix from $1,9502026-04-13 MEDIUM 5.7 CVE-2026-34855 Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidenti… Harmonyos No fix yet Fix from $1,6002026-04-13 HIGH 7.1 CVE-2026-40162 Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bun… Bugsink Mitigation only Fix from $1,9502026-04-10 MEDIUM 5.9 CVE-2026-5500 wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check.… Wolfssl after 5.9.0 Fix from $1,6002026-04-10 HIGH 7.4 CVE-2026-33797 An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a … Junos Mitigation only Fix from $1,9502026-04-09 MEDIUM 5.3 CVE-2026-32990 Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 … Tomcat 9.0.116 / 10.1.53+ Fix from $1,6002026-04-09 MEDIUM 6.5 CVE-2026-5329 Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Veloc… Velociraptor 0.76.3+ Fix from $1,6002026-04-09 CRITICAL 9.1 CVE-2026-34178 In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates … Lxd after 6.7 Fix from $2,3002026-04-09 HIGH 8.1 CVE-2026-5915 Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds mem… Chrome 147.0.7727.55+ Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-5919 Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the re… Chrome 147.0.7727.55+ Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-5884 Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the rendere… Chrome 147.0.7727.55+ Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-5885 Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentiall… Chrome 147.0.7727.55+ Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-5879 Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary cod… Chrome 147.0.7727.55+ Fix from $1,9502026-04-08 HIGH 8.8 CVE-2026-34197 KEVEPSS 97% Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach… Activemq 5.19.4 / 6.2.3+ Fix from $1,9502026-04-07 HIGH 7.5 CVE-2025-57834 An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem (Exynos 980, 850, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2… Exynos 980 Firmware Mitigation only Fix from $1,9502026-04-06 MEDIUM 5.5 CVE-2025-48651 In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This c… Android Mitigation only Fix from $1,6002026-04-06 HIGH 7.5 CVE-2025-57835 An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1… Exynos 990 Firmware Mitigation only Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5659 A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/d… Mitigation only Fix from $1,6002026-04-06 HIGH 7.5 CVE-2026-30078 OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message sp… Oai Cn5g Amf No fix yet Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5536 A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC s… Fedml after 0.8.9 Fix from $1,9502026-04-05 HIGH 7.5 CVE-2026-34773 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and… Electron 38.8.6 / 39.8.1+ Fix from $1,9502026-04-04