Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2025-63397 Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during bro… Oneflow Patch available Fix from $1,6002025-11-10 HIGH 8.8 CVE-2025-12907 Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code vi… Chrome 140.0.7339.80+ Fix from $1,9502025-11-08 MEDIUM 5.4 CVE-2025-12908 Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domai… Chrome 140.0.7339.80+ Fix from $1,6002025-11-08 MEDIUM 6.1 CVE-2025-63785 A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occur… Onlook No fix yet Fix from $1,6002025-11-07 HIGH 7.6 CVE-2025-63783 A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onl… Onlook No fix yet Fix from $1,9502025-11-07 MEDIUM 5.3 CVE-2025-48985 A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filet… Ai 5.0.52+ Fix from $1,6002025-11-07 MEDIUM 6.1 CVE-2025-64176 ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an attacker can upload any file… Thinkdashboard 0.6.8+ Fix from $1,6002025-11-06 HIGH 7.1 CVE-2025-61084 MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An attack… Mitigation only Fix from $1,9502025-11-05 HIGH 7.5 CVE-2025-59595 CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a spec… Secure Access 14.12+ Fix from $1,9502025-11-04 MEDIUM 6.5 CVE-2025-59596 CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a… Secure Access 14.12+ Fix from $1,6002025-11-04 HIGH 8.8 CVE-2025-62507EPSS 7% Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's… Redis 8.2.3+ Fix from $1,9502025-11-04 MEDIUM 6.5 CVE-2025-54327 An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validati… Exynos 1280 Firmware Mitigation only Fix from $1,6002025-11-04 HIGH 7.8 CVE-2025-43472 A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1… macOS 14.8.2 / 15.7.2+ Fix from $1,9502025-11-04 HIGH 7.5 CVE-2025-43401 A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1.… macOS 14.8.2 / 15.7.2+ Fix from $1,9502025-11-04 MEDIUM 5.5 CVE-2025-43348 A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may … macOS 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 CRITICAL 9.2 CVE-2025-64385 The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the manufacturer’s software. Usin… Mitigation only Fix from $2,3002025-10-31 CRITICAL 9.1 CVE-2025-61235 An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields can contai… No fix yet Fix from $2,3002025-10-28 CRITICAL 9.8 CVE-2025-12305 A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJ… Shiyi Blog after 1.2.1 Fix from $2,3002025-10-27 CRITICAL 9.8 CVE-2025-27224 TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly saniti… Trufusion Enterprise after 7.10.4.0 Fix from $2,3002025-10-27 MEDIUM 6.5 CVE-2025-12278 Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Blu Ic2 Firmware 1.20+ Fix from $1,6002025-10-26 MEDIUM 6.1 CVE-2025-12284 Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Blu Ic2 Firmware 1.20+ Fix from $1,6002025-10-26 CRITICAL 9.8 CVE-2025-12285 Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Blu Ic2 Firmware 1.20+ Fix from $2,3002025-10-26 CRITICAL 9.8 CVE-2025-12275 Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Blu Ic2 Firmware 1.20+ Fix from $2,3002025-10-26 HIGH 7.5 CVE-2025-60938 Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands… Emoncms No fix yet Fix from $1,9502025-10-24 HIGH 8.8 CVE-2025-62525 OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel m… Openwrt 24.10.4+ Fix from $1,9502025-10-22 MEDIUM 6.1 CVE-2025-12001 Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Blu Ic2 Firmware 1.20+ Fix from $1,6002025-10-20 HIGH 7.5 CVE-2025-26781 An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14… Exynos W920 Firmware Mitigation only Fix from $1,9502025-10-20 HIGH 8.1 CVE-2025-11938 A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipul… Churchcrm after 5.18.0 Fix from $1,9502025-10-19 CRITICAL 9.4 CVE-2025-8414 Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corru… Mitigation only Fix from $2,3002025-10-17 MEDIUM 6.5 CVE-2025-60537 Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute arbitrary… Mitigation only Fix from $1,6002025-10-14