Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2026-60639 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 8.3 CVE-2026-60640 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content Mitigation only Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-60633 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected … Webcenter Content No fix yet Fix from $1,9502026-07-21 MEDIUM 6.4 CVE-2026-60620 Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supported versio… Jd Edwards Enterpriseone Configurator No fix yet Fix from $1,6002026-07-21 MEDIUM 6.6 CVE-2026-60613 Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version th… Peoplesoft Enterprise Campus Software Campus Community No fix yet Fix from $1,6002026-07-21 HIGH 8.8 CVE-2026-60603 Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features). The supported version … Peoplesoft Enterprise Campus Software Campus Community Mitigation only Fix from $1,9502026-07-21 MEDIUM 6.7 CVE-2026-60526 Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. Difficult… Jdk No fix yet Fix from $1,6002026-07-21 HIGH 8.4 CVE-2026-64877 An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database. Security Center Mitigation only Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-15792 A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. Buildkit 0.31.2+ Fix from $1,9502026-07-21 HIGH 8.7 CVE-2026-15724 In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal … No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 HIGH 7.2 CVE-2026-1771 The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all version… No fix yet Fix from $1,9502026-07-21 HIGH 8.2 CVE-2026-47255 AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0… No fix yet Fix from $1,9502026-07-20 MEDIUM 5.4 CVE-2026-58624 Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.… Mina Sshd 2.19.0+ Fix from $1,6002026-07-20 HIGH 8.5 CVE-2026-47198 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperl… No fix yet Fix from $1,9502026-07-20 MEDIUM 5.3 CVE-2026-44978 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. … Xrdp 0.10.6.1+ Fix from $1,6002026-07-20 CRITICAL 9.8 CVE-2026-35048 The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configurat… Mitigation only Fix from $2,3002026-07-20 MEDIUM 5.8 CVE-2026-63428 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from th… No fix yet Fix from $1,6002026-07-20 HIGH 7.5 CVE-2026-42566 Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a ma… Meshtastic Firmware No fix yet Fix from $1,9502026-07-20 CRITICAL 10.0 CVE-2026-16117 Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's … Fastify\/http Proxy 11.6.0+ Fix from $2,3002026-07-18 HIGH 8.8 CVE-2026-7755 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration… Langflow 1.10.1+ Fix from $1,9502026-07-17 MEDIUM 5.3 CVE-2026-49208 Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit… Ux 2.36.0+ Fix from $1,6002026-07-17 HIGH 7.0 CVE-2026-53411 A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow… Workplace Virtual Desktop Infrastructure 6.6.14+ Fix from $1,9502026-07-16 CRITICAL 9.8 CVE-2026-53412 Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthentica… Workplace Desktop 6.5.18 / 6.6.15+ Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-44180 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Vers… Enterprise Gateway 3.3.0+ Fix from $2,3002026-07-16 HIGH 7.8 CVE-2026-53409 Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege vi… Rooms No fix yet Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-33692 WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose c… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.1 CVE-2026-54728 bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host … No fix yet Fix from $1,6002026-07-16 MEDIUM 6.1 CVE-2026-46341 The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.5 CVE-2026-50012 Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in s… Squid 7.6+ Fix from $1,6002026-07-16