Browse vulnerabilities
377,957 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-55526 | High | 0.8% | 9.1 | n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via th… | |
| CVE-2026-33228 | High | 0.8% | 9.8 | flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted… | |
| CVE-2026-41473 | High | 0.8% | 9.1 | CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the A… | |
| CVE-2023-27202 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27203 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27204 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27205 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2026-48020 | High | 0.8% | 10.0 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, t… | |
| CVE-2026-41242 | High | 0.8% | 9.8 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior… | |
| CVE-2018-25412 | High | 0.8% | 9.8 | Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticate… | |
| CVE-2026-8984 | High | 0.8% | 9.8 | Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code exe… | |
| CVE-2026-13716 | High | 0.7% | 9.1 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remot… | |
| CVE-2026-48024 | High | 0.7% | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-34084 | High | 0.7% | 9.8 | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 … | |
| CVE-2026-44181 | High | 0.7% | 10.0 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-30281 | High | 0.7% | 9.8 | An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to over… | |
| CVE-2025-70141 | High | 0.7% | 9.4 | SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerabil… | |
| CVE-2026-11856 | High | 0.7% | 9.8 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Dig… | |
| CVE-2023-27172 | High | 0.7% | 9.1 | Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows a… | |
| CVE-2026-39906 | High | 0.7% | 10.0 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecat… | |
| CVE-2026-35392 | High | 0.7% | 9.8 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver… | |
| CVE-2026-35393 | High | 0.7% | 9.8 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart uploa… | |
| CVE-2026-35471 | High | 0.7% | 9.8 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing re… | |
| CVE-2026-22872 | High | 0.7% | 9.1 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controll… | |
| CVE-2026-48689 | High | 0.7% | 9.8 | FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overfl… | |
| CVE-2026-8925 | High | 0.7% | 9.8 | The curl logic that works with SASL authentication could end up cleaning up the GSASL cont… | |
| CVE-2025-59695 | High | 0.7% | 9.8 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched… | |
| CVE-2026-30276 | High | 0.7% | 9.8 | An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows atta… | |
| CVE-2026-66897 | High | 0.7% | 9.9 | A path traversal vulnerability in LXD's instance template processing allows an attacker wi… | |
| CVE-2026-8924 | High | 0.7% | 9.1 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies… | |
| CVE-2025-70150 | High | 0.7% | 9.8 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability… | |
| CVE-2026-34612 | High | 0.7% | 9.9 | Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kes… | |
| CVE-2026-28384 | High | 0.7% | 9.9 | An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an… | |
| CVE-2026-27634 | High | 0.7% | 9.8 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, t… | |
| CVE-2026-2587 | High | 0.6% | 9.6 | A critical Remote Code Execution (RCE) vulnerability was identified in the server-side tem… | |
| CVE-2026-5067 | High | 0.6% | 9.8 | A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server W… | |
| CVE-2026-53622 | High | 0.6% | 10.0 | Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2… | |
| CVE-2026-34745 | High | 0.6% | 9.1 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix … | |
| CVE-2026-39907 | High | 0.6% | 10.0 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthe… | |
| CVE-2026-30285 | High | 0.6% | 9.8 | An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows… | |
| CVE-2026-61800 | High | 0.6% | 9.1 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for en… | |
| CVE-2026-10536 | High | 0.6% | 9.8 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 … | |
| CVE-2026-5241 | High | 0.6% | 9.6 | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.… | |
| CVE-2026-42074 | High | 0.6% | 9.8 | OpenClaude is an open-source coding-agent command line interface for cloud and local model… | |
| CVE-2026-9079 | High | 0.6% | 9.8 | libcurl had a flaw that when instructed to clear proxy authentication credentials which ma… | |
| CVE-2026-62948 | High | 0.6% | 9.6 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd w… | |
| CVE-2025-70146 | High | 0.6% | 9.1 | Missing authentication in multiple administrative action scripts under /admin/ in ProjectW… | |
| CVE-2026-48162 | High | 0.6% | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-45411 | High | 0.6% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a h… | |
| CVE-2026-40035 | High | 0.6% | 9.1 | Unfurl through 2025.08 contains an improper input validation vulnerability in config parsi… |