Browse vulnerabilities
377,957 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-44180 | High | 0.6% | 9.8 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-27962 | High | 0.5% | 9.1 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to versio… | |
| CVE-2026-35053 | High | 0.5% | 9.8 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.4… | |
| CVE-2026-33229 | High | 0.5% | 9.8 | XWiki Platform is a generic wiki platform offering runtime services for applications built… | |
| CVE-2026-34934 | High | 0.5% | 9.8 | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads… | |
| CVE-2026-41586 | High | 0.5% | 9.8 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for de… | |
| CVE-2026-66421 | High | 0.5% | 9.3 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauth… | |
| CVE-2025-38089 | High | 0.5% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GA… | |
| CVE-2026-60113 | High | 0.5% | 9.8 | AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a … | |
| CVE-2026-49441 | High | 0.5% | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-54058 | High | 0.5% | 9.1 | Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McI… | |
| CVE-2026-66418 | High | 0.5% | 9.3 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows… | |
| CVE-2026-35579 | High | 0.5% | 9.8 | CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, a… | |
| CVE-2026-42880 | High | 0.5% | 9.6 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.… | |
| CVE-2026-44210 | High | 0.5% | 9.9 | Kata Containers is an open source project focusing on a standard implementation of lightwe… | |
| CVE-2026-8927 | High | 0.5% | 9.1 | When reusing a libcurl handle for sequential transfers driven by environment-variable prox… | |
| CVE-2026-34449 | High | 0.5% | 9.6 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious webs… | |
| CVE-2026-44182 | High | 0.5% | 10.0 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-51536 | High | 0.5% | 9.1 | In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) ne… | |
| CVE-2026-74899 | High | 0.5% | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPl… | |
| CVE-2026-34448 | High | 0.5% | 9.0 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who … | |
| CVE-2026-10050 | High | 0.5% | 9.1 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encod… | |
| CVE-2026-46624 | High | 0.5% | 9.9 | Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution … | |
| CVE-2026-51537 | High | 0.5% | 9.1 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection … | |
| CVE-2026-63293 | High | 0.5% | 9.9 | A link following vulnerability in LXD allows an attacker to achieve arbitrary file read an… | |
| CVE-2026-4599 | High | 0.5% | 9.1 | Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplet… | |
| CVE-2026-69263 | High | 0.5% | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-25896 | High | 0.5% | 9.3 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS… | |
| CVE-2026-63298 | High | 0.5% | 9.9 | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance conf… | |
| CVE-2026-48773 | High | 0.5% | 9.8 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 throug… | |
| CVE-2025-59703 | High | 0.5% | 9.1 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched… | |
| CVE-2026-69258 | High | 0.5% | 9.1 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2025-70152 | High | 0.4% | 9.8 | code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injectio… | |
| CVE-2026-85595 | High | 0.4% | 9.8 | Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentica… | |
| CVE-2026-34952 | High | 0.4% | 9.1 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway se… | |
| CVE-2026-8926 | High | 0.4% | 9.1 | When asking curl to use a `.netrc` file to find credentials and at the same time specifyin… | |
| CVE-2026-66898 | High | 0.4% | 9.9 | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths d… | |
| CVE-2026-8983 | High | 0.4% | 9.8 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication t… | |
| CVE-2026-78676 | High | 0.4% | 9.8 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during w… | |
| CVE-2026-79675 | High | 0.4% | 9.8 | NLTK before 3.10.3 fails to validate JVM options passed through the per-call options param… | |
| CVE-2026-28802 | High | 0.4% | 9.8 | Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.… | |
| CVE-2026-28373 | High | 0.4% | 9.6 | The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal v… | |
| CVE-2026-51540 | High | 0.4% | 9.8 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corrupt… | |
| CVE-2026-51541 | High | 0.4% | 9.1 | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when … | |
| CVE-2026-33950 | High | 0.4% | 9.4 | Signal K Server is a server application that runs on a central hub in a boat. Prior to ver… | |
| CVE-2026-34162 | High | 0.4% | 10.0 | FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tool… | |
| CVE-2026-44881 | High | 0.4% | 9.9 | Portainer Community Edition is a lightweight service delivery platform for containerized a… | |
| CVE-2026-49448 | High | 0.4% | 9.8 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and … | |
| CVE-2026-42601 | High | 0.4% | 9.8 | ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and pr… | |
| CVE-2026-63299 | High | 0.4% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated user to bypass projec… |