Browse vulnerabilities
155 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-74900 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM… | |
| CVE-2026-59251 | Medium | 0.3% | 7.5 | Allocation of resources without limits in Erlang/OTP public_key certificate path validatio… | |
| CVE-2026-81705 | Medium | 0.3% | 7.5 | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump wh… | |
| CVE-2026-28386 | Medium | 0.3% | 7.5 | Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-… | |
| CVE-2026-58101 | Medium | 0.3% | 7.5 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL point… | |
| CVE-2026-74880 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in key… | |
| CVE-2026-74892 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standa… | |
| CVE-2026-81719 | Medium | 0.3% | 7.8 | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient cont… | |
| CVE-2026-81701 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins,… | |
| CVE-2026-66402 | Medium | 0.3% | 9.8 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate iden… | |
| CVE-2026-74891 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone… | |
| CVE-2026-81698 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info … | |
| CVE-2026-74884 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_sa… | |
| CVE-2026-74893 | Medium | 0.3% | 8.8 | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in con… | |
| CVE-2026-54876 | Medium | 0.3% | 7.5 | Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has ena… | |
| CVE-2026-45363 | Medium | 0.3% | 9.1 | ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to … | |
| CVE-2026-74879 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in t… | |
| CVE-2026-74883 | Medium | 0.3% | 8.8 | openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plu… | |
| CVE-2026-74874 | Medium | 0.3% | 7.5 | openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for ste… | |
| CVE-2022-4991 | Medium | 0.3% | 7.4 | Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirecto… | |
| CVE-2026-74877 | Medium | 0.2% | 8.8 | openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerabili… | |
| CVE-2026-31789 | Medium | 0.2% | 9.8 | Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string … | |
| CVE-2026-81700 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gp… | |
| CVE-2026-34181 | Medium | 0.2% | 7.4 | Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation fo… | |
| CVE-2026-57163 | Medium | 0.2% | 9.1 | PJSIP is a free and open source multimedia communication library written in C. Prior to co… | |
| CVE-2026-74901 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pq… | |
| CVE-2026-75803 | Medium | 0.2% | 9.1 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can repor… | |
| CVE-2026-52767 | Medium | 0.2% | 8.2 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpS… | |
| CVE-2026-74876 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict… | |
| CVE-2026-74889 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in k… | |
| CVE-2026-81688 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in th… | |
| CVE-2026-81689 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKD… | |
| CVE-2026-81691 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_w… | |
| CVE-2026-81704 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D… | |
| CVE-2026-70454 | Medium | 0.2% | 8.0 | rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contai… | |
| CVE-2026-74875 | Medium | 0.2% | 9.8 | openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonsc… | |
| CVE-2026-74888 | Medium | 0.2% | 7.5 | openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation constructio… | |
| CVE-2026-48697 | Medium | 0.2% | 7.4 | FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HT… | |
| CVE-2026-62243 | Medium | 0.2% | 7.5 | Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions… | |
| CVE-2026-84975 | Medium | 0.2% | 7.4 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and… | |
| CVE-2026-6958 | Medium | 0.1% | 7.8 | Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability i… | |
| CVE-2026-81702 | Medium | 0.1% | 9.8 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading ide… | |
| CVE-2026-81714 | Medium | 0.1% | 7.0 | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint m… | |
| CVE-2026-45784 | Medium | 0.1% | 7.1 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 unt… | |
| CVE-2026-81718 | Medium | 0.1% | 7.5 | openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only… | |
| CVE-2026-45221 | Medium | 0.1% | 7.8 | Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privilege… | |
| CVE-2026-74882 | Medium | 0.1% | 7.5 | openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trust… | |
| CVE-2022-49036 | Medium | 0.1% | 7.8 | An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL confi… | |
| CVE-2026-41447 | Medium | 0.1% | 7.8 | FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows lo… | |
| CVE-2026-41859 | Medium | 0.1% | 7.8 | A network man-in-the-middle between nats-sync and the BOSH director can steal the director… |