Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2026-21229 Improper input validation in Power BI allows an authorized attacker to execute code over a network. Power Bi Report Server 15.0.1120.113+ Fix from $1,9502026-02-10 HIGH 8.2 CVE-2025-25210 Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an esc… Mitigation only Fix from $1,9502026-02-10 HIGH 7.5 CVE-2025-22453 Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an esc… Mitigation only Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-25892 Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version … Adminer 5.4.2+ Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-2113 A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/web… Tpadmin after 1.3.12 Fix from $2,3002026-02-07 MEDIUM 6.5 CVE-2026-25631 n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validatio… N8n 1.121.0+ Fix from $1,6002026-02-06 CRITICAL 9.1 CVE-2026-25722 Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write op… Claude Code 2.0.57+ Fix from $2,3002026-02-06 MEDIUM 6.5 CVE-2026-25723 Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations with the … Claude Code 2.0.55+ Fix from $1,6002026-02-06 HIGH 8.8 CVE-2025-15566 A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inj… Mitigation only Fix from $1,9502026-02-06 MEDIUM 6.5 CVE-2025-12131 A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service. Simplicity Software Development Kit after 2025.6.2 Fix from $1,6002026-02-05 HIGH 8.8 CVE-2026-25514 FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL … Facturascripts 2025.81+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2026-25513 FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL … Facturascripts 2025.81+ Fix from $1,9502026-02-04 HIGH 7.2 CVE-2026-21893 n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s… N8n 1.120.3+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2026-1580 A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configu… Mitigation only Fix from $1,9502026-02-03 HIGH 8.8 CVE-2026-24512 A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This… Mitigation only Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2026-24936 When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr… Data Master 5.1.2.re51+ Fix from $2,3002026-02-03 MEDIUM 6.5 CVE-2025-67480 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryRevisionsBase.Php. This is… Mediawiki 1.39.16 / 1.43.6+ Fix from $1,6002026-02-03 CRITICAL 9.8 CVE-2025-67484 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php. This issue affec… Mediawiki 1.39.16 / 1.43.6+ Fix from $2,3002026-02-03 HIGH 8.8 CVE-2026-1691 A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/… Bolo Solo after 2.6.4 Fix from $1,9502026-01-30 HIGH 7.5 CVE-2026-25128 fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In v… Fast Xml Parser 5.3.4+ Fix from $1,9502026-01-30 HIGH 7.5 CVE-2024-4027 A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the cl… Mitigation only Fix from $1,9502026-01-30 HIGH 8.3 CVE-2026-25117 pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit e33da14449a5abcff507e554f66e2141d6683b0a, missing sandboxing on… Patch available Fix from $1,9502026-01-29 HIGH 7.1 CVE-2026-25126 PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`POST /api/v1/forum/vote`) trusts the JS… Polarlearn Patch available Fix from $1,9502026-01-29 MEDIUM 6.8 CVE-2025-15545 The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, … Archer Re605x Firmware 1.2.10+ Fix from $1,6002026-01-29 MEDIUM 6.2 CVE-2025-71011 An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of OneFlow v0.9.0 allows attacker… Oneflow No fix yet Fix from $1,6002026-01-29 MEDIUM 6.2 CVE-2025-71009 An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS… Oneflow No fix yet Fix from $1,6002026-01-29 MEDIUM 6.5 CVE-2026-23566 A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an… Digital Employee Experience 26.1+ Fix from $1,6002026-01-29 MEDIUM 6.5 CVE-2026-23570 A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prio… Digital Employee Experience 26.1+ Fix from $1,6002026-01-29 MEDIUM 6.8 CVE-2026-23571 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction.… Digital Employee Experience 26.1+ Fix from $1,6002026-01-29 HIGH 7.8 CVE-2026-24856 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Versions… Iccdev 2.3.1.2+ Fix from $1,9502026-01-28