Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2026-4342 A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can … Nginx Ingress Controller 1.13.9 / 1.14.5+ Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-32622 SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulner… Sqlbot 1.6.0+ Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-27953 ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing … Ormar 0.23.1+ Fix from $2,3002026-03-19 MEDIUM 5.4 CVE-2026-20643 A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for … Ipados 26.3.1+ Fix from $1,6002026-03-17 HIGH 7.5 CVE-2026-3644 The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling… Python 3.13.13 / 3.14.4+ Fix from $1,9502026-03-16 CRITICAL 9.1 CVE-2026-23489 Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP … Fields 1.23.3+ Fix from $2,3002026-03-16 MEDIUM 5.5 CVE-2025-6969 in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. Openharmony Mitigation only Fix from $1,6002026-03-16 MEDIUM 5.3 CVE-2025-10461 Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows f… Mitigation only Fix from $1,6002026-03-16 MEDIUM 5.3 CVE-2026-22204 wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious da… Wpdiscuz 7.6.47+ Fix from $1,6002026-03-13 CRITICAL 9.8 CVE-2026-1668 The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when … Omada Sg2005p Pd Firmware 1.0.19 / 1.20.17+ Fix from $2,3002026-03-13 MEDIUM 6.3 CVE-2025-60012 Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apach… Livy 0.9.0+ Fix from $1,6002026-03-13 MEDIUM 6.3 CVE-2026-3967 A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file a… Mitigation only Fix from $1,6002026-03-12 CRITICAL 9.8 CVE-2026-31900 Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject:… Black 26.3.0+ Fix from $2,3002026-03-11 HIGH 7.8 CVE-2026-30901 Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege … Rooms 6.6.5+ Fix from $1,9502026-03-11 MEDIUM 5.3 CVE-2026-21310 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vu… Commerce 1.3.3 / 2.4.4+ Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2026-21282 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vu… Commerce 1.3.3 / 2.4.4+ Fix from $1,6002026-03-11 HIGH 7.1 CVE-2025-20068 Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalation of privilege. System softw… Mitigation only Fix from $1,9502026-03-10 MEDIUM 5.9 CVE-2025-20096 Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adversary wit… Mitigation only Fix from $1,6002026-03-10 HIGH 8.7 CVE-2025-20105 Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation of privilege. System software… Mitigation only Fix from $1,9502026-03-10 HIGH 7.1 CVE-2025-20027 Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System software adv… Mitigation only Fix from $1,9502026-03-10 HIGH 8.7 CVE-2025-20064 Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. System softwar… Mitigation only Fix from $1,9502026-03-10 HIGH 8.4 CVE-2025-36920 In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local e… Android Mitigation only Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-26310 Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::getAddressWithPort with a scope… Envoy 1.34.13 / 1.35.8+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-26121 Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. Azure Iot Explorer 0.15.14+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-26106 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20076+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-20967 Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. System Center Operations Manager Mitigation only Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-3288EPSS 6% A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject conf… Ingress Nginx 1.13.8 / 1.14.4+ Fix from $1,9502026-03-09 HIGH 7.2 CVE-2025-14558EPSS 6% The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is pass… FreeBSD No fix yet Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-61613 In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut… Android Mitigation only Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-61614 In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut… Android Mitigation only Fix from $1,9502026-03-09