Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2026-43714 The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequ… Ipados 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 MEDIUM 6.9 CVE-2026-54272 ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF thr… No fix yet Fix from $1,6002026-07-27 MEDIUM 5.3 CVE-2026-46452 Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resultin… Nimble 1.10.0+ Fix from $1,6002026-07-24 HIGH 8.8 CVE-2026-54120 Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. Surface Management Services No fix yet Fix from $1,9502026-07-24 HIGH 8.2 CVE-2026-65604 Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies… No fix yet Fix from $1,9502026-07-23 CRITICAL 10.0 CVE-2026-47668 DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.0 CVE-2026-16723 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul… No fix yet Fix from $2,3002026-07-23 HIGH 7.3 CVE-2026-16632 A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/w… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-13057 An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $sea… MongoDB 8.0.28 / 8.2.12+ Fix from $1,6002026-07-22 HIGH 7.2 CVE-2026-46737 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged … Powerprotect Data Manager 20.2+ Fix from $1,9502026-07-22 HIGH 7.2 CVE-2026-46738 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged … Powerprotect Data Manager 20.2+ Fix from $1,9502026-07-22 HIGH 7.2 CVE-2026-40712 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged … Powerprotect Data Manager 20.2+ Fix from $1,9502026-07-22 HIGH 7.2 CVE-2026-40714 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with re… Powerprotect Data Manager 20.2+ Fix from $1,9502026-07-22 HIGH 7.5 CVE-2026-55973 In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the la… Unbound 1.25.2+ Fix from $1,9502026-07-22 HIGH 7.5 CVE-2026-57600 Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive … No fix yet Fix from $1,9502026-07-22 MEDIUM 6.9 CVE-2026-16551 Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only. No fix yet Fix from $1,6002026-07-22 MEDIUM 5.4 CVE-2026-16415 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of … Chrome 150.0.7871.182+ Fix from $1,6002026-07-21 HIGH 8.8 CVE-2026-16421 Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbo… Chrome 150.0.7871.182+ Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-16422 Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged netwo… Chrome 150.0.7871.182+ Fix from $1,9502026-07-21 HIGH 7.8 CVE-2026-16414 Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a s… Chrome 150.0.7871.182+ Fix from $1,9502026-07-21 MEDIUM 6.3 CVE-2026-62519 Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affecte… E Business Suite after 12.2.15 Fix from $1,6002026-07-21 HIGH 8.1 CVE-2026-61160 Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). … Commerce Experience Manager Mitigation only Fix from $1,9502026-07-21 MEDIUM 5.8 CVE-2026-61079 Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26… Goldengate after 23.26.2.0.0 Fix from $1,6002026-07-21 CRITICAL 9.9 CVE-2026-60719 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.… Bi Publisher No fix yet Fix from $2,3002026-07-21 HIGH 8.0 CVE-2026-60648 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a… Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.0 CVE-2026-60650 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a… Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60634 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60636 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content Mitigation only Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60637 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60638 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21