Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2025-61615 In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut… Android Mitigation only Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-61616 In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut… Android Mitigation only Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-69278 In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut… Android Mitigation only Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-69279 In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut… Android Mitigation only Fix from $1,9502026-03-09 CRITICAL 9.8 CVE-2026-24713 Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a… Iotdb 1.3.7 / 2.0.7+ Fix from $2,3002026-03-09 HIGH 7.5 CVE-2025-61611 In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.. Yocto No fix yet Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-61612 In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execut… Android Mitigation only Fix from $1,9502026-03-09 MEDIUM 6.5 CVE-2026-29791 Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environment. Prior to version 0.12.0, w… Agentgateway 0.12.0+ Fix from $1,6002026-03-06 HIGH 8.2 CVE-2026-29046 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them i… Tinyweb 2.04+ Fix from $1,9502026-03-06 CRITICAL 10.0 CVE-2026-0848 NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamic… Nltk after 3.9.2 Fix from $2,3002026-03-05 MEDIUM 6.5 CVE-2025-7375 A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cau… Omada Eap610 Firmware 1.6.0+ Fix from $1,6002026-03-05 MEDIUM 6.5 CVE-2025-11143 The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in system… Jetty 12.0.31 / 12.1.5+ Fix from $1,6002026-03-05 CRITICAL 9.6 CVE-2026-3545 Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape… Chrome 145.0.7632.159 / 145.0.7632.160+ Fix from $2,3002026-03-04 MEDIUM 5.7 CVE-2026-20020 A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent att… Adaptive Security Appliance Software Mitigation only Fix from $1,6002026-03-04 HIGH 7.5 CVE-2026-27443 SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME entities, allowing an attacker … Seppmail 15.0.1+ Fix from $1,9502026-03-04 CRITICAL 9.8 CVE-2026-2590 Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.… Remote Desktop Manager after 2025.3.30.0 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3204 Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error… Devolutions Server after 2025.3.16.0 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2024-55020 A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to… Easyweb Mitigation only Fix from $2,3002026-03-03 MEDIUM 5.5 CVE-2025-62816 An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP input lead… Exynos 1280 Firmware Mitigation only Fix from $1,6002026-03-03 HIGH 8.4 CVE-2026-0034 In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could … Android Mitigation only Fix from $1,9502026-03-02 MEDIUM 6.2 CVE-2026-0015 In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to lo… Android Mitigation only Fix from $1,6002026-03-02 MEDIUM 6.2 CVE-2026-0014 In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to… Android Mitigation only Fix from $1,6002026-03-02 MEDIUM 5.5 CVE-2025-48644 In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service … Android No fix yet Fix from $1,6002026-03-02 MEDIUM 6.2 CVE-2025-48585 In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to… Android Mitigation only Fix from $1,6002026-03-02 MEDIUM 6.2 CVE-2025-48587 In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to… Android Mitigation only Fix from $1,6002026-03-02 HIGH 7.8 CVE-2026-28421 Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim'… Vim 9.2.0077+ Fix from $1,9502026-02-27 MEDIUM 6.5 CVE-2018-25160 HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depe… Http\ after 1.09 Fix from $1,6002026-02-27 CRITICAL 9.1 CVE-2026-2880 A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example,… Fastify\/middie 9.2.0+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-2750 Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affec… Web 24.04.24 / 24.10.20+ Fix from $2,3002026-02-27 HIGH 7.5 CVE-2026-26935 Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulatio… Kibana 8.19.12 / 9.2.6+ Fix from $1,9502026-02-26