Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.1 CVE-2026-22444 The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the e… Solr 9.10.1+ Fix from $1,9502026-01-21 CRITICAL 9.9 CVE-2026-0933 SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com… Wrangler 3.114.17 / 4.59.1+ Fix from $2,3002026-01-20 HIGH 7.5 CVE-2025-66902 An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive information or cause unexpected server… Websocket Server No fix yet Fix from $1,9502026-01-20 MEDIUM 5.4 CVE-2026-0903 Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type … Chrome 144.0.7559.59 / 144.0.7559.60+ Fix from $1,6002026-01-20 HIGH 7.3 CVE-2026-23880 OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the so… Patch available Fix from $1,9502026-01-19 MEDIUM 5.3 CVE-2026-23886 Swift W3C TraceContext is a Swift implementation of the W3C Trace Context standard, and Swift OTel is an OpenTelemetry Protocol (OTLP) backend for Sw… Patch available Fix from $1,6002026-01-19 MEDIUM 6.1 CVE-2026-23839 Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-si… Movary 0.70.0+ Fix from $1,6002026-01-19 MEDIUM 6.1 CVE-2026-23840 Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-si… Movary 0.70.0+ Fix from $1,6002026-01-19 MEDIUM 6.1 CVE-2026-23841 Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-si… Movary 0.70.0+ Fix from $1,6002026-01-19 HIGH 8.8 CVE-2026-23836 HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP form… Hotcrp 3.2+ Fix from $1,9502026-01-19 HIGH 7.5 CVE-2025-61684 Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. … Quicly 2026-01-18+ Fix from $1,9502026-01-19 HIGH 7.5 CVE-2025-29847 A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if… Linkis 1.8.0+ Fix from $1,9502026-01-19 MEDIUM 5.8 CVE-2025-12718 The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6. This is due to the 'qcf_val… Mitigation only Fix from $1,6002026-01-17 HIGH 7.8 CVE-2025-48647 In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This coul… Android Mitigation only Fix from $1,9502026-01-16 HIGH 7.5 CVE-2025-9014 A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input vali… Tl Wr841n Firmware 250908+ Fix from $1,9502026-01-15 MEDIUM 6.8 CVE-2025-65397 An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacke… Dome Flare Firmware after 24.1114.151.929 Fix from $1,6002026-01-14 MEDIUM 5.5 CVE-2025-68970 Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service co… Emui Mitigation only Fix from $1,6002026-01-14 MEDIUM 5.5 CVE-2025-68964 Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002026-01-14 HIGH 7.5 CVE-2026-22862 go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a spe… Go Ethereum 1.16.8+ Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-22868 go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a spe… Go Ethereum 1.16.8+ Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2026-0543 Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially… Kibana 8.19.0 / 9.1.10+ Fix from $1,6002026-01-13 HIGH 7.2 CVE-2025-37173 An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating… Arubaos 8.10.0.21 / 8.13.1.1+ Fix from $1,9502026-01-13 HIGH 8.6 CVE-2026-21268 Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code executio… Dreamweaver 21.7+ Fix from $1,9502026-01-13 HIGH 8.6 CVE-2026-21271 Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code executio… Dreamweaver 21.7+ Fix from $1,9502026-01-13 HIGH 8.6 CVE-2026-21272 Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system wri… Dreamweaver 21.7+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20951 Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. Sharepoint Server 16.0.19127.20442+ Fix from $1,9502026-01-13 HIGH 8.1 CVE-2026-20856 Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2026-20812 Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 HIGH 8.0 CVE-2026-0403 An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injecti… Rbe971 Firmware 7.2.8.5 / 9.10.0.2+ Fix from $1,9502026-01-13 HIGH 8.0 CVE-2026-0404 An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over W… Rbr750 Firmware 7.2.8.5+ Fix from $1,9502026-01-13