Browse vulnerabilities
377,957 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-70149 | High | 0.4% | 9.8 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_members… | |
| CVE-2026-38431 | High | 0.4% | 9.8 | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An at… | |
| CVE-2025-52221 | High | 0.4% | 9.8 | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function vi… | |
| CVE-2026-51538 | High | 0.4% | 9.1 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulne… | |
| CVE-2026-28798 | High | 0.4% | 9.0 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with U… | |
| CVE-2026-67324 | High | 0.4% | 9.8 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short… | |
| CVE-2026-31818 | High | 0.4% | 9.6 | Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side reque… | |
| CVE-2026-39397 | High | 0.4% | 9.4 | @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page build… | |
| CVE-2026-34953 | High | 0.4% | 9.1 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_to… | |
| CVE-2026-34931 | High | 0.4% | 9.6 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there i… | |
| CVE-2026-62420 | High | 0.4% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass ta… | |
| CVE-2026-38428 | High | 0.4% | 9.8 | Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because … | |
| CVE-2025-66024 | High | 0.4% | 9.0 | The XWiki blog application allows users of the XWiki platform to create and manage blog po… | |
| CVE-2026-11564 | High | 0.4% | 9.1 | libcurl keeps previously used connections in a connection pool for subsequent transfers to… | |
| CVE-2026-54526 | High | 0.4% | 9.9 | Argo Workflows is an open source container-native workflow engine for orchestrating parall… | |
| CVE-2026-48491 | High | 0.4% | 10.0 | Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a hig… | |
| CVE-2026-63300 | High | 0.4% | 9.9 | An improper validation vulnerability in the instancePostMigration function in lxd/instance… | |
| CVE-2026-35184 | High | 0.4% | 9.8 | EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injectio… | |
| CVE-2026-87528 | High | 0.3% | 9.6 | Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a rem… | |
| CVE-2026-34758 | High | 0.3% | 9.1 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.4… | |
| CVE-2026-2651 | High | 0.3% | 9.0 | A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart u… | |
| CVE-2026-67622 | High | 0.3% | 9.9 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the Op… | |
| CVE-2026-59151 | High | 0.3% | 9.6 | Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow … | |
| CVE-2025-9497 | High | 0.3% | 9.8 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicio… | |
| CVE-2026-39355 | High | 0.3% | 9.9 | Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access contr… | |
| CVE-2026-63296 | High | 0.3% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass ta… | |
| CVE-2026-34361 | High | 0.3% | 9.3 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperab… | |
| CVE-2026-45372 | High | 0.3% | 9.9 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to… | |
| CVE-2026-78155 | High | 0.3% | 9.9 | privilege escalation in StackGres operator allows a low-privilege tenant who owns a databa… | |
| CVE-2026-12605 | High | 0.3% | 9.6 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSo… | |
| CVE-2026-78683 | High | 0.3% | 9.6 | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization v… | |
| CVE-2026-32253 | High | 0.3% | 9.8 | Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.14… | |
| CVE-2026-33642 | High | 0.3% | 9.9 | Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_com… | |
| CVE-2026-35459 | High | 0.3% | 9.1 | pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and … | |
| CVE-2026-46441 | High | 0.3% | 9.6 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-85594 | High | 0.3% | 9.8 | Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the t… | |
| CVE-2026-42861 | High | 0.3% | 9.6 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-85596 | High | 0.2% | 9.8 | Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernet… | |
| CVE-2026-63297 | High | 0.2% | 9.9 | An authorization bypass vulnerability in LXD due to a timing flaw during configuration mer… | |
| CVE-2026-48772 | High | 0.2% | 10.0 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 thro… | |
| CVE-2026-85597 | High | 0.2% | 9.1 | Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolutio… | |
| CVE-2026-44985 | High | 0.2% | 9.6 | Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgra… | |
| CVE-2026-44211 | High | 0.2% | 9.6 | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In version… | |
| CVE-2007-2386 | Medium | 50.0% | — | — | |
| CVE-2022-24260 | Medium | 50.0% | — | — | |
| CVE-2021-21342 | Medium | 50.0% | — | — | |
| CVE-2016-5118 | Medium | 50.0% | — | — | |
| CVE-2003-0309 | Medium | 50.0% | — | — | |
| CVE-2019-15980 | Medium | 50.0% | — | — | |
| CVE-2019-17120 | Medium | 50.0% | — | — |