Browse vulnerabilities

377,957 results

CVEPriorityEPSSCVSSKEVWhat
CVE-2025-70149 High 0.4% 9.8 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_members…
CVE-2026-38431 High 0.4% 9.8 ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An at…
CVE-2025-52221 High 0.4% 9.8 Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function vi…
CVE-2026-51538 High 0.4% 9.1 EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulne…
CVE-2026-28798 High 0.4% 9.0 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with U…
CVE-2026-67324 High 0.4% 9.8 GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short…
CVE-2026-31818 High 0.4% 9.6 Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side reque…
CVE-2026-39397 High 0.4% 9.4 @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page build…
CVE-2026-34953 High 0.4% 9.1 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_to…
CVE-2026-34931 High 0.4% 9.6 hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there i…
CVE-2026-62420 High 0.4% 9.9 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass ta…
CVE-2026-38428 High 0.4% 9.8 Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because …
CVE-2025-66024 High 0.4% 9.0 The XWiki blog application allows users of the XWiki platform to create and manage blog po…
CVE-2026-11564 High 0.4% 9.1 libcurl keeps previously used connections in a connection pool for subsequent transfers to…
CVE-2026-54526 High 0.4% 9.9 Argo Workflows is an open source container-native workflow engine for orchestrating parall…
CVE-2026-48491 High 0.4% 10.0 Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a hig…
CVE-2026-63300 High 0.4% 9.9 An improper validation vulnerability in the instancePostMigration function in lxd/instance…
CVE-2026-35184 High 0.4% 9.8 EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injectio…
CVE-2026-87528 High 0.3% 9.6 Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a rem…
CVE-2026-34758 High 0.3% 9.1 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.4…
CVE-2026-2651 High 0.3% 9.0 A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart u…
CVE-2026-67622 High 0.3% 9.9 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the Op…
CVE-2026-59151 High 0.3% 9.6 Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow …
CVE-2025-9497 High 0.3% 9.8 Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicio…
CVE-2026-39355 High 0.3% 9.9 Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access contr…
CVE-2026-63296 High 0.3% 9.9 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass ta…
CVE-2026-34361 High 0.3% 9.3 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperab…
CVE-2026-45372 High 0.3% 9.9 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to…
CVE-2026-78155 High 0.3% 9.9 privilege escalation in StackGres operator allows a low-privilege tenant who owns a databa…
CVE-2026-12605 High 0.3% 9.6 In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSo…
CVE-2026-78683 High 0.3% 9.6 NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization v…
CVE-2026-32253 High 0.3% 9.8 Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.14…
CVE-2026-33642 High 0.3% 9.9 Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_com…
CVE-2026-35459 High 0.3% 9.1 pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and …
CVE-2026-46441 High 0.3% 9.6 Flowise is a drag & drop user interface to build a customized large language model flow. P…
CVE-2026-85594 High 0.3% 9.8 Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the t…
CVE-2026-42861 High 0.3% 9.6 Flowise is a drag & drop user interface to build a customized large language model flow. P…
CVE-2026-85596 High 0.2% 9.8 Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernet…
CVE-2026-63297 High 0.2% 9.9 An authorization bypass vulnerability in LXD due to a timing flaw during configuration mer…
CVE-2026-48772 High 0.2% 10.0 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 thro…
CVE-2026-85597 High 0.2% 9.1 Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolutio…
CVE-2026-44985 High 0.2% 9.6 Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgra…
CVE-2026-44211 High 0.2% 9.6 Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In version…
CVE-2007-2386 Medium 50.0%
CVE-2022-24260 Medium 50.0%
CVE-2021-21342 Medium 50.0%
CVE-2016-5118 Medium 50.0%
CVE-2003-0309 Medium 50.0%
CVE-2019-15980 Medium 50.0%
CVE-2019-17120 Medium 50.0%
← Prev Page 108 of 7,560 Next →