Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40847 | Medium | 10.0% | — | — | |
| CVE-2008-7126 | Medium | 10.0% | — | — | |
| CVE-2014-5470 | Medium | 10.0% | — | — | |
| CVE-2018-6223 | Medium | 10.0% | — | — | |
| CVE-2026-3612 | Medium | 10.0% | — | — | |
| CVE-2011-0013 | Medium | 10.0% | — | — | |
| CVE-2018-20523 | Medium | 10.0% | — | — | |
| CVE-2018-20782 | Medium | 10.0% | — | — | |
| CVE-2013-2474 | Medium | 10.0% | — | — | |
| CVE-2008-2511 | Medium | 10.0% | — | — | |
| CVE-2025-48999 | Medium | 10.0% | — | — | |
| CVE-2006-2460 | Medium | 10.0% | — | — | |
| CVE-2018-19042 | Medium | 10.0% | — | — | |
| CVE-2018-19043 | Medium | 10.0% | — | — | |
| CVE-2013-0613 | Medium | 10.0% | — | — | |
| CVE-2016-4121 | Medium | 10.0% | — | — | |
| CVE-2015-1399 | Medium | 10.0% | — | — | |
| CVE-2026-19681 | Medium | 9.9% | 9.9 | An authenticated command injection vulnerability exists in Security Center related to file… | |
| CVE-2023-35359 | Medium | 9.9% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2000-0991 | Medium | 9.7% | 7.5 | Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows… | |
| CVE-2021-25329 | Medium | 9.5% | 7.0 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.… | |
| CVE-2025-13878 | Medium | 9.2% | 7.5 | Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affect… | |
| CVE-2026-4631 | Medium | 9.2% | 9.8 | Cockpit's remote login feature passes user-supplied hostnames and usernames from the web i… | |
| CVE-2018-15756 | Medium | 9.2% | 7.5 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3… | |
| CVE-2026-19632 | Medium | 9.0% | 9.8 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress… | |
| CVE-2024-12085 | Medium | 8.8% | 7.5 | A flaw was found in rsync which could be triggered when rsync compares file checksums. Thi… | |
| CVE-2020-36188 | Medium | 8.8% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2022-41113 | Medium | 8.8% | 7.8 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | |
| CVE-2025-20701 | Medium | 8.7% | 8.8 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device … | |
| CVE-2000-1023 | Medium | 8.6% | 7.5 | The Alabanza Control Panel does not require passwords to access administrative commands, w… | |
| CVE-2020-14060 | Medium | 8.6% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serializ… | |
| CVE-2022-25762 | Medium | 8.4% | 8.6 | If a web application sends a WebSocket message concurrently with the WebSocket connection … | |
| CVE-2026-20860 | Medium | 8.4% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Functio… | |
| CVE-2020-36184 | Medium | 8.4% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2022-41109 | Medium | 8.1% | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2020-14062 | Medium | 8.1% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serializ… | |
| CVE-2020-10673 | Medium | 8.0% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2018-8727 | Medium | 8.0% | 7.5 | Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacke… | |
| CVE-2019-10869 | Medium | 8.0% | 8.1 | Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23… | |
| CVE-2026-46368 | Medium | 7.8% | 8.8 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the htt… | |
| CVE-2020-35491 | Medium | 7.8% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-24616 | Medium | 7.6% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serializ… | |
| CVE-2000-1033 | Medium | 7.6% | 7.5 | Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first lo… | |
| CVE-2026-48030 | Medium | 7.5% | 9.9 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to be… | |
| CVE-2021-36947 | Medium | 7.5% | 8.8 | Windows Print Spooler Remote Code Execution Vulnerability | |
| CVE-2021-20190 | Medium | 7.5% | 8.1 | A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction… | |
| CVE-2021-36936 | Medium | 7.4% | 8.8 | Windows Print Spooler Remote Code Execution Vulnerability | |
| CVE-2021-40690 | Medium | 7.4% | 7.5 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vuln… | |
| CVE-2021-26896 | Medium | 7.4% | 7.5 | Windows DNS Server Denial of Service Vulnerability | |
| CVE-2026-10187 | Medium | 7.3% | 9.8 | A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issu… |