Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.3 CVE-2026-54217 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious… No fix yet Fix from $1,6002026-08-07 HIGH 7.7 CVE-2026-54204 Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.3 CVE-2026-54205 Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set … No fix yet Fix from $1,6002026-08-07 MEDIUM 6.3 CVE-2026-54206 Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network loc… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.3 CVE-2026-54207 Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network loca… No fix yet Fix from $1,6002026-08-07 HIGH 8.5 CVE-2026-54208 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write … No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-54199 Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing function… No fix yet Fix from $1,6002026-08-07 HIGH 8.3 CVE-2026-19177 Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer … Chrome 151.0.7922.109+ Fix from $1,9502026-08-06 HIGH 8.8 CVE-2026-19169 Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privileg… Chrome 151.0.7922.109+ Fix from $1,9502026-08-06 CRITICAL 9.6 CVE-2026-19164 Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sand… Chrome 151.0.7922.109+ Fix from $2,3002026-08-06 HIGH 8.1 CVE-2026-19153 Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rend… Chrome 151.0.7922.109+ Fix from $1,9502026-08-06 HIGH 8.6 CVE-2026-19143 Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially per… Chrome 151.0.7922.109+ Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-15149 The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.8 CVE-2024-6541 The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows aut… No fix yet Fix from $1,6002026-08-06 HIGH 8.1 CVE-2026-57817 The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache C… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 MEDIUM 5.8 CVE-2024-10302 The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data… Api Control Plane No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-70607 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 CRITICAL 9.9 CVE-2026-20303 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen… No fix yet Fix from $2,3002026-08-05 HIGH 8.6 CVE-2026-20273 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen… Ios Xe No fix yet Fix from $1,9502026-08-05 MEDIUM 6.0 CVE-2026-70603 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 HIGH 8.7 CVE-2026-46334 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerabilit… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-16793 An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) … No fix yet Fix from $1,9502026-08-04 CRITICAL 9.3 CVE-2026-18801 OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who ca… No fix yet Fix from $2,3002026-08-04 MEDIUM 6.5 CVE-2026-18772 Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion. No fix yet Fix from $1,6002026-08-04 MEDIUM 5.6 CVE-2026-11835 Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mo… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-67978 An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame. No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67969 An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.App… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67974 A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to caus… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.9 CVE-2026-69198 ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classificatio… No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-69185 Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO pac… No fix yet Fix from $1,9502026-08-03