Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2000-1024 | Medium | 5.1% | 10.0 | eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP … | |
| CVE-2021-34529 | Medium | 5.1% | 7.8 | Visual Studio Code Remote Code Execution Vulnerability | |
| CVE-2020-1171 | Medium | 5.0% | 8.8 | A remote code execution vulnerability exists in Visual Studio Code when the Python extensi… | |
| CVE-2026-10796 | Medium | 5.0% | 7.5 | nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings… | |
| CVE-2026-79697 | Medium | 4.9% | 9.9 | A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE… | |
| CVE-2020-36183 | Medium | 4.9% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2017-10684 | Medium | 4.9% | 9.8 | In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafte… | |
| CVE-2026-5027 | Medium | 4.8% | 8.8 | The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the mult… | |
| CVE-2006-1469 | Medium | 4.8% | 7.5 | Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attacker… | |
| CVE-2000-0818 | Medium | 4.7% | 10.0 | The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an… | |
| CVE-2026-18686 | Medium | 4.7% | 9.8 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the… | |
| CVE-2026-6516 | Medium | 4.7% | 10.0 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Re… | |
| CVE-2026-20840 | Medium | 4.7% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code l… | |
| CVE-2021-36965 | Medium | 4.6% | 8.8 | Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | |
| CVE-2020-9546 | Medium | 4.6% | 9.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2026-74849 | Medium | 4.6% | 9.8 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a re… | |
| CVE-2020-0909 | Medium | 4.6% | 7.5 | A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properl… | |
| CVE-2021-27053 | Medium | 4.6% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2024-1635 | Medium | 4.6% | 7.5 | A vulnerability was found in Undertow. This vulnerability impacts a server that supports t… | |
| CVE-2026-8632 | Medium | 4.6% | 7.8 | A potential security vulnerability has been identified in the HP Linux Imaging and Printin… | |
| CVE-2020-14195 | Medium | 4.5% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serializ… | |
| CVE-2018-0231 | Medium | 4.5% | 8.6 | A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security A… | |
| CVE-2026-34234 | Medium | 4.5% | 10.0 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and pri… | |
| CVE-2026-77806 | Medium | 4.5% | 9.8 | SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as e… | |
| CVE-2024-38257 | Medium | 4.5% | 7.5 | Microsoft AllJoyn API Information Disclosure Vulnerability | |
| CVE-2026-80428 | Medium | 4.5% | 9.8 | ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injecti… | |
| CVE-2020-14061 | Medium | 4.5% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serializ… | |
| CVE-2026-18599 | Medium | 4.4% | 8.0 | A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the functi… | |
| CVE-2024-27890 | Medium | 4.4% | 9.6 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can b… | |
| CVE-2021-34520 | Medium | 4.4% | 8.1 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| CVE-2018-15454 | Medium | 4.4% | 8.6 | A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adapti… | |
| CVE-2021-34470 | Medium | 4.4% | 8.0 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2026-82595 | Medium | 4.4% | 7.4 | A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the … | |
| CVE-2021-24089 | Medium | 4.3% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2021-27061 | Medium | 4.3% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2020-0901 | Medium | 4.3% | 9.8 | A remote code execution vulnerability exists in Microsoft Excel software when the software… | |
| CVE-2021-27081 | Medium | 4.3% | 7.8 | Visual Studio Code ESLint Extension Remote Code Execution Vulnerability | |
| CVE-2021-43208 | Medium | 4.3% | 7.8 | 3D Viewer Remote Code Execution Vulnerability | |
| CVE-2026-4480 | Medium | 4.3% | 9.0 | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job d… | |
| CVE-2026-67208 | Medium | 4.3% | 9.8 | Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenti… | |
| CVE-2017-10685 | Medium | 4.3% | 9.8 | In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafte… | |
| CVE-2023-36664 | Medium | 4.2% | 7.8 | Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with… | |
| CVE-2026-20871 | Medium | 4.2% | 7.8 | Use after free in Desktop Windows Manager allows an authorized attacker to elevate privile… | |
| CVE-2020-36185 | Medium | 4.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-36186 | Medium | 4.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2020-36187 | Medium | 4.2% | 8.1 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serializ… | |
| CVE-2021-42282 | Medium | 4.2% | 7.5 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2021-42291 | Medium | 4.2% | 7.5 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2026-49975 | Medium | 4.2% | 7.5 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http… | |
| CVE-2022-37967 | Medium | 4.1% | 7.2 | Windows Kerberos Elevation of Privilege Vulnerability |