Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.2 CVE-2025-71009 An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS… Oneflow No fix yet Fix from $1,6002026-01-29 MEDIUM 6.5 CVE-2026-23566 A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an… Digital Employee Experience 26.1+ Fix from $1,6002026-01-29 MEDIUM 6.5 CVE-2026-23570 A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prio… Digital Employee Experience 26.1+ Fix from $1,6002026-01-29 MEDIUM 6.8 CVE-2026-23571 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction.… Digital Employee Experience 26.1+ Fix from $1,6002026-01-29 HIGH 7.8 CVE-2026-24856 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Versions… Iccdev 2.3.1.2+ Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-71007 An input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a craf… Oneflow No fix yet Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-71003 An input validation vulnerability in the flow.arange() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted … Oneflow No fix yet Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-59895 Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration… Diskpulse Mitigation only Fix from $1,9502026-01-28 HIGH 7.5 CVE-2026-0919 The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively long URL path. An invalid‑URL er… Tapo C220 Firmware 1.2.3 / 1.4.2+ Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-1315 By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying a… Tapo C220 Firmware 1.2.3 / 1.4.2+ Fix from $1,9502026-01-27 MEDIUM 5.5 CVE-2025-65264 The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface, allowing an attacker to acc… Cpu Z after 2.17 Fix from $1,6002026-01-27 MEDIUM 5.3 CVE-2026-24347 Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory Ezcast Pro Dongle Ii Firmware Mitigation only Fix from $1,6002026-01-27 MEDIUM 6.1 CVE-2026-24348 Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code i… Ezcast Pro Dongle Ii Firmware Mitigation only Fix from $1,6002026-01-27 HIGH 8.8 CVE-2026-24345 Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to t… Ezcast Pro Dongle Ii Firmware Mitigation only Fix from $1,9502026-01-27 CRITICAL 9.8 CVE-2026-24811 Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root. Root after 6.34.08 Fix from $2,3002026-01-27 HIGH 8.8 CVE-2026-24410 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have U… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 HIGH 8.8 CVE-2026-24411 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have U… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 HIGH 8.8 CVE-2026-24412 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 HIGH 8.8 CVE-2026-24409 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have U… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 HIGH 8.8 CVE-2026-24406 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 HIGH 8.8 CVE-2026-24407 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have U… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 HIGH 8.8 CVE-2026-24403 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 HIGH 8.8 CVE-2026-24404 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CI… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 HIGH 8.8 CVE-2026-24405 iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a… Iccdev 2.3.1.2+ Fix from $1,9502026-01-24 CRITICAL 9.8 CVE-2025-27378 AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this … On Prem Enterprise Server 7.0.6+ Fix from $2,3002026-01-22 MEDIUM 5.4 CVE-2026-23887 Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25.0.1 through 25.0.79, the app… Group Office 6.8.149 / 25.0.80+ Fix from $1,6002026-01-22 HIGH 7.1 CVE-2026-22598 ManageIQ is an open-source management platform. A flaw was found in the ManageIQ API prior to version radjabov-2 where a malformed TimeProfile could … Patch available Fix from $1,9502026-01-21 HIGH 7.4 CVE-2025-68134 EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module … Everest 2025.10.0+ Fix from $1,9502026-01-21 HIGH 7.5 CVE-2025-66959 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder Ollama No fix yet Fix from $1,9502026-01-21 HIGH 7.5 CVE-2025-66960 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string … Ollama No fix yet Fix from $1,9502026-01-21