Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2026-27959 Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of th… Koa 2.16.4 / 3.1.2+ Fix from $1,9502026-02-26 HIGH 7.5 CVE-2026-27818 TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions pri… Terriajs Server 4.0.3+ Fix from $1,9502026-02-26 HIGH 8.1 CVE-2026-25941 FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 … Freerdp 2.11.8 / 3.23.0+ Fix from $1,9502026-02-25 CRITICAL 9.0 CVE-2026-27702 Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i… Budibase 3.30.4+ Fix from $2,3002026-02-25 CRITICAL 9.1 CVE-2026-27607 RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi… Rustfs Mitigation only Fix from $2,3002026-02-25 HIGH 7.8 CVE-2025-14963 A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system p… Endpoint Security after 34.0.0 Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2026-27590 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind… Caddy 2.11.1+ Fix from $2,3002026-02-24 MEDIUM 6.5 CVE-2026-27585 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanit… Caddy 2.11.1+ Fix from $1,6002026-02-24 HIGH 7.5 CVE-2026-27642 free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t… Udm after 1.4.1 Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-21864 Valkey-Bloom is a Rust based Valkey module which brings a Bloom Filter (Module) data type into the Valkey distributed key-value database. Prior to co… Valkey Bloom 1.0.1+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2025-69250 free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t… Udm after 1.4.1 Fix from $1,9502026-02-24 MEDIUM 5.3 CVE-2025-69251 free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up t… Udm after 1.4.1 Fix from $1,6002026-02-24 HIGH 7.5 CVE-2025-69232 free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to f… Go Upf after 1.4.0 Fix from $1,9502026-02-23 HIGH 7.5 CVE-2026-27623 Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can… Valkey 9.0.3+ Fix from $1,9502026-02-23 HIGH 7.5 CVE-2026-2970 A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-… Datapizza Ai No fix yet Fix from $1,9502026-02-23 MEDIUM 6.5 CVE-2026-2898 A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.p… Funadmin 7.1.0+ Fix from $1,6002026-02-22 HIGH 7.1 CVE-2026-27170 OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest… Opensift 1.1.3+ Fix from $1,9502026-02-21 MEDIUM 5.4 CVE-2026-26952 Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below… Web Interface 6.4.1+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-26953 Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and abov… Web Interface 6.4.1+ Fix from $1,6002026-02-19 HIGH 7.5 CVE-2026-26314 go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to s… Go Ethereum 1.16.9+ Fix from $1,9502026-02-19 HIGH 8.8 CVE-2026-26063 CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validatio… Mitigation only Fix from $1,9502026-02-19 MEDIUM 6.5 CVE-2025-13587 The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including… Mitigation only Fix from $1,6002026-02-19 HIGH 7.5 CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o… Tomcat 1.3.5 / 2.0.12+ Fix from $1,9502026-02-17 CRITICAL 9.1 CVE-2025-66614 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.… Tomcat 9.0.113 / 10.1.50+ Fix from $2,3002026-02-17 HIGH 7.5 CVE-2026-2555 A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/… Jeecg Boot No fix yet Fix from $1,9502026-02-16 HIGH 7.5 CVE-2025-70123 An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF in… Free5gc No fix yet Fix from $1,9502026-02-13 HIGH 7.5 CVE-2026-2391 ### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cau… Qs 6.14.2+ Fix from $1,9502026-02-12 MEDIUM 5.5 CVE-2026-20627 An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPa… Ipados 14.8.4 / 26.3+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2026-21258 Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps 16.0.10417.20097+ Fix from $1,6002026-02-10 HIGH 7.3 CVE-2026-21247 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10