Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.6 CVE-2026-30304 In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description f… Ai Code after 3.12.4 Fix from $2,3002026-03-27 HIGH 7.2 CVE-2025-69986 A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application fails to validate the length … Mitigation only Fix from $1,9502026-03-27 HIGH 7.3 CVE-2026-4982 A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or channels in other worlds on … Mitigation only Fix from $1,9502026-03-27 HIGH 7.5 CVE-2025-59028 When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invali… Dovecot 2.4.3 / 3.1.2+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2025-59032 ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, makin… Dovecot 2.4.3 / 3.1.3+ Fix from $1,9502026-03-27 CRITICAL 9.8 CVE-2026-33729 OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to… Openfga 1.13.1+ Fix from $2,3002026-03-27 MEDIUM 6.5 CVE-2026-29905 Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image up… Kirby after 5.1.4 Fix from $1,6002026-03-26 CRITICAL 9.8 CVE-2025-55270 HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS… Aftermarket Cloud Mitigation only Fix from $2,3002026-03-26 HIGH 7.3 CVE-2026-4860 A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file sr… Mitigation only Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-33285 LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mecha… Liquidjs 10.25.1+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-33287 LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS … Liquidjs 10.25.1+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-33218 NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which … Nats Server 2.11.15 / 2.12.6+ Fix from $1,9502026-03-25 HIGH 7.5 CVE-2026-28894 A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS … Ipados 14.8.5 / 15.7.5+ Fix from $1,9502026-03-25 MEDIUM 5.5 CVE-2026-28852 A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS S… Ipados 15.7.5 / 18.7.7+ Fix from $1,6002026-03-25 HIGH 8.4 CVE-2026-28821 A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue … macOS 14.8.5 / 15.7.5+ Fix from $1,9502026-03-25 MEDIUM 5.3 CVE-2026-20686 This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user… Ipados 26.3+ Fix from $1,6002026-03-25 HIGH 8.7 CVE-2026-3912 Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows inf… Mitigation only Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33332 NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-c… Nicegui 3.9.0+ Fix from $1,9502026-03-24 HIGH 8.8 CVE-2026-22559 An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engin… Mitigation only Fix from $1,9502026-03-24 MEDIUM 5.3 CVE-2026-33769 Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs … Astro 5.18.1+ Fix from $1,6002026-03-24 CRITICAL 9.8 CVE-2026-4755 CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. Android Imagemagick7 7.1.2-11+ Fix from $2,3002026-03-24 HIGH 7.5 CVE-2026-33250 Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specia… Patch available Fix from $1,9502026-03-24 HIGH 7.5 CVE-2025-15606 A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitization, allows crafted request… Td W8961nd Firmware 250925+ Fix from $1,9502026-03-23 HIGH 7.8 CVE-2026-4538 A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation … Pytorch Patch available Fix from $1,9502026-03-22 MEDIUM 5.3 CVE-2026-3641 The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. This is due to the plugin reg… Mitigation only Fix from $1,6002026-03-21 MEDIUM 5.3 CVE-2026-3460 The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This … Mitigation only Fix from $1,6002026-03-21 HIGH 7.5 CVE-2026-33151 Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially c… Socket.io Parser 3.3.5 / 3.4.4+ Fix from $1,9502026-03-20 MEDIUM 5.4 CVE-2026-4438 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 t… Glibc after 2.43 Fix from $1,6002026-03-20 HIGH 8.2 CVE-2026-31805 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plu… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,9502026-03-20 HIGH 8.8 CVE-2026-4451 Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the r… Chrome 146.0.7680.153+ Fix from $1,9502026-03-20