Browse vulnerabilities
377,957 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-32625 | High | 2.9% | 9.6 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up… | |
| CVE-2026-25244 | High | 2.8% | 9.8 | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDr… | |
| CVE-2025-15379 | High | 2.4% | 10.0 | A command injection vulnerability exists in MLflow's model serving container initializatio… | |
| CVE-2026-60121 | High | 2.3% | 9.8 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in th… | |
| CVE-2026-57827 | High | 2.3% | 9.8 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.… | |
| CVE-2026-8986 | High | 2.3% | 9.8 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection … | |
| CVE-2026-34243 | High | 2.2% | 9.8 | wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or… | |
| CVE-2026-86426 | High | 2.1% | 9.8 | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API tha… | |
| CVE-2026-33937 | High | 1.7% | 9.8 | Handlebars provides the power necessary to let users build semantic templates. In versions… | |
| CVE-2018-25357 | High | 1.7% | 9.8 | Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthen… | |
| CVE-2024-28056 | High | 1.7% | 9.8 | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM … | |
| CVE-2024-31823 | High | 1.7% | 9.8 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479… | |
| CVE-2026-48687 | High | 1.6% | 9.8 | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability … | |
| CVE-2026-7853 | High | 1.5% | 9.8 | A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function spri… | |
| CVE-2026-27606 | High | 1.5% | 9.8 | Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of… | |
| CVE-2019-25687 | High | 1.4% | 9.8 | Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plu… | |
| CVE-2026-47103 | High | 1.4% | 9.8 | Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerabi… | |
| CVE-2023-27168 | High | 1.3% | 9.8 | An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attack… | |
| CVE-2021-27080 | High | 1.3% | 9.3 | Azure Sphere Unsigned Code Execution Vulnerability | |
| CVE-2026-79657 | High | 1.2% | 9.8 | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted p… | |
| CVE-2026-63294 | High | 1.2% | 9.9 | A link following vulnerability in LXD allows an attacker to achieve root command execution… | |
| CVE-2025-62718 | High | 1.2% | 9.9 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31… | |
| CVE-2026-19931 | High | 1.2% | 9.8 | A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname usi… | |
| CVE-2026-69264 | High | 1.2% | 9.8 | Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFil… | |
| CVE-2025-71338 | High | 1.2% | 10.0 | Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoin… | |
| CVE-2022-31340 | High | 1.1% | 9.8 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax… | |
| CVE-2026-29063 | High | 1.0% | 9.8 | Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, … | |
| CVE-2026-43997 | High | 1.0% | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain th… | |
| CVE-2026-43999 | High | 1.0% | 9.9 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist … | |
| CVE-2026-44007 | High | 1.0% | 9.1 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created wi… | |
| CVE-2026-73487 | High | 1.0% | 9.8 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtab… | |
| CVE-2021-47103 | High | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: inet: fully convert s… | |
| CVE-2016-20052 | High | 1.0% | 9.8 | Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticat… | |
| CVE-2026-47429 | High | 0.9% | 9.8 | Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API… | |
| CVE-2018-25254 | High | 0.9% | 9.8 | NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability th… | |
| CVE-2025-59693 | High | 0.9% | 9.8 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi t… | |
| CVE-2026-18924 | High | 0.9% | 9.1 | A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set … | |
| CVE-2026-70470 | High | 0.9% | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-44008 | High | 0.9% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeAr… | |
| CVE-2026-64620 | High | 0.9% | 9.8 | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_… | |
| CVE-2021-47107 | High | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buf… | |
| CVE-2026-73602 | High | 0.8% | 9.9 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox… | |
| CVE-2026-2586 | High | 0.8% | 9.1 | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's A… | |
| CVE-2026-44005 | High | 0.8% | 10.0 | vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes m… | |
| CVE-2023-43902 | High | 0.8% | 9.8 | Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 a… | |
| CVE-2026-34935 | High | 0.8% | 9.8 | PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the… | |
| CVE-2025-57631 | High | 0.8% | 9.8 | SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitr… | |
| CVE-2026-44006 | High | 0.8% | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach Bas… | |
| CVE-2026-27727 | High | 0.8% | 9.8 | mchange-commons-java, a library that provides Java utilities, includes code that mirrors e… | |
| CVE-2026-44009 | High | 0.8% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixe… |