Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-71947 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-71948 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-71949 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-71950 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-71951 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-71952 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-71953 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-71954 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-71955 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_20260211004… | |
| CVE-2026-71956 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_20260211004… | |
| CVE-2026-89010 | Medium | 3.2% | 9.8 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an una… | |
| CVE-2026-15027 | Medium | 3.2% | 8.8 | CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticate… | |
| CVE-2021-27060 | Medium | 3.2% | 7.8 | Visual Studio Code Remote Code Execution Vulnerability | |
| CVE-2026-79698 | Medium | 3.2% | 9.9 | A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE… | |
| CVE-2022-38177 | Medium | 3.2% | 7.5 | By spoofing the target resolver with responses that have a malformed ECDSA signature, an a… | |
| CVE-2021-34442 | Medium | 3.1% | 8.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2020-1035 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine handles o… | |
| CVE-2020-1064 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the MSHTML engine improperly … | |
| CVE-2020-1093 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine handles o… | |
| CVE-2026-6893 | Medium | 3.1% | 7.5 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vul… | |
| CVE-2000-1077 | Medium | 3.1% | 10.0 | Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote… | |
| CVE-2021-34528 | Medium | 3.1% | 7.8 | Visual Studio Code Remote Code Execution Vulnerability | |
| CVE-2026-17179 | Medium | 3.1% | 8.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to caus… | |
| CVE-2020-1058 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine handles o… | |
| CVE-2020-1060 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine handles o… | |
| CVE-2020-1092 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists when Internet Explorer improperly accesses ob… | |
| CVE-2026-11840 | Medium | 3.1% | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 v… | |
| CVE-2026-93742 | Medium | 3.1% | 9.9 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this iss… | |
| CVE-2026-30815 | Medium | 3.1% | 8.0 | An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 al… | |
| CVE-2026-19747 | Medium | 3.1% | 9.8 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B1… | |
| CVE-2020-10672 | Medium | 3.1% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2021-26868 | Medium | 3.1% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2021-26859 | Medium | 3.0% | 7.7 | Microsoft Power BI Information Disclosure Vulnerability | |
| CVE-2000-0974 | Medium | 3.0% | 7.5 | GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple doc… | |
| CVE-2026-36576 | Medium | 3.0% | 9.8 | An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltop… | |
| CVE-2019-3774 | Medium | 3.0% | 9.8 | Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptibl… | |
| CVE-2023-54391 | Medium | 3.0% | 9.8 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnera… | |
| CVE-2026-43641 | Medium | 3.0% | 9.8 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection … | |
| CVE-2015-1862 | Medium | 3.0% | 7.0 | The crash reporting feature in Abrt allows local users to gain privileges by leveraging an… | |
| CVE-2023-35383 | Medium | 3.0% | 7.5 | Microsoft Message Queuing Information Disclosure Vulnerability | |
| CVE-2021-41356 | Medium | 3.0% | 7.5 | Windows Denial of Service Vulnerability | |
| CVE-2021-21009 | Medium | 3.0% | 8.6 | Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and e… | |
| CVE-2026-81467 | Medium | 3.0% | 9.8 | Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Sp… | |
| CVE-2026-18072 | Medium | 3.0% | 9.8 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin f… | |
| CVE-2022-38178 | Medium | 3.0% | 7.5 | By spoofing the target resolver with responses that have a malformed EdDSA signature, an a… | |
| CVE-2026-3296 | Medium | 3.0% | 9.8 | The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versio… | |
| CVE-2026-21441 | Medium | 3.0% | 7.5 | urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the … | |
| CVE-2006-2936 | Medium | 3.0% | 7.8 | The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possib… | |
| CVE-2026-48313 | Medium | 3.0% | 9.3 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of … | |
| CVE-2026-7693 | Medium | 3.0% | 7.2 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all ver… |