Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2026-34980 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-expos… Cups after 2.4.16 Fix from $1,9502026-04-03 HIGH 8.8 CVE-2026-28797 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerab… Ragflow after 0.24.0 Fix from $1,9502026-04-03 HIGH 7.5 CVE-2020-37216 Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper hand… Mitigation only Fix from $1,9502026-04-03 HIGH 7.0 CVE-2026-5473 A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipul… Core Flight System after 7.0.0 Fix from $1,9502026-04-03 HIGH 7.1 CVE-2026-34760 vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using nump… Vllm 0.18.0+ Fix from $1,9502026-04-02 MEDIUM 6.5 CVE-2026-35038 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerabi… Signal K Server 2.24.0+ Fix from $1,6002026-04-02 MEDIUM 6.1 CVE-2026-32629 phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that… Phpmyfaq 4.1.1+ Fix from $1,6002026-04-02 CRITICAL 9.1 CVE-2026-29143 SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an a… Secure Email Gateway 15.0.3+ Fix from $2,3002026-04-02 MEDIUM 5.3 CVE-2026-29144 SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike… Secure Email Gateway 15.0.3+ Fix from $1,6002026-04-02 MEDIUM 5.3 CVE-2026-29137 SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject. Secure Email Gateway 15.0.3+ Fix from $1,6002026-04-02 MEDIUM 5.3 CVE-2026-29141 SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK]. Secure Email Gateway 15.0.3+ Fix from $1,6002026-04-02 CRITICAL 9.1 CVE-2026-29133 SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address. Secure Email Gateway 15.0.3+ Fix from $2,3002026-04-02 HIGH 7.5 CVE-2026-29135 SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization. Secure Email Gateway 15.0.3+ Fix from $1,9502026-04-02 MEDIUM 5.3 CVE-2026-34525 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohtt… Aiohttp 3.13.4+ Fix from $1,6002026-04-01 HIGH 8.6 CVE-2026-34445 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in… Onnx 1.21.0+ Fix from $1,9502026-04-01 CRITICAL 9.8 CVE-2026-20093 A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker … Mitigation only Fix from $2,3002026-04-01 MEDIUM 6.5 CVE-2026-30523 A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allow… Loan Management System No fix yet Fix from $1,6002026-04-01 MEDIUM 6.1 CVE-2026-34442 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout ve… Freescout 1.8.211+ Fix from $1,6002026-03-31 HIGH 8.3 CVE-2025-14213 Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket … Mitigation only Fix from $1,9502026-03-31 MEDIUM 6.5 CVE-2026-33029 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration a… Nginx Ui 2.3.4+ Fix from $1,6002026-03-30 HIGH 7.5 CVE-2026-30077 OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for p… Openairinterface Mitigation only Fix from $1,9502026-03-30 MEDIUM 5.3 CVE-2026-29909 MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks au… Mrcms No fix yet Fix from $1,6002026-03-30 MEDIUM 6.5 CVE-2026-21712 A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain n… Node.js after 25.8.1 Fix from $1,6002026-03-30 HIGH 7.5 CVE-2026-4987 The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up… Mitigation only Fix from $1,9502026-03-28 MEDIUM 5.3 CVE-2026-33936 The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signatur… Ecdsa 0.19.2+ Fix from $1,6002026-03-27 HIGH 7.5 CVE-2026-33894 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 sig… Forge 1.4.0+ Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2026-33882 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be ma… Statamic 5.73.16 / 6.7.2+ Fix from $1,6002026-03-27 HIGH 7.5 CVE-2026-30576 A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to va… Web Based Pharmacy Product Management System No fix yet Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-30575 A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to va… Web Based Pharmacy Product Management System No fix yet Fix from $1,9502026-03-27 MEDIUM 6.1 CVE-2026-33758 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authenticatio… Openbao 2.5.2+ Fix from $1,6002026-03-27