Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-86148 | Medium | 2.9% | 9.1 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects t… | |
| CVE-2026-86149 | Medium | 2.9% | 9.1 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown p… | |
| CVE-2026-86151 | Medium | 2.9% | 9.1 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the functio… | |
| CVE-2026-19900 | Medium | 2.9% | 8.1 | A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is a… | |
| CVE-2026-19188 | Medium | 2.9% | 10.0 | A critical OS command injection vulnerability has been identified in the Haiwell IoT Clou… | |
| CVE-2026-37751 | Medium | 2.9% | 9.8 | An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.t… | |
| CVE-2026-52102 | Medium | 2.9% | 9.8 | An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8… | |
| CVE-2024-5971 | Medium | 2.9% | 7.5 | A vulnerability was found in Undertow, where the chunked response hangs after the body was… | |
| CVE-2026-27548 | Medium | 2.9% | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /ind… | |
| CVE-2026-27558 | Medium | 2.9% | 8.8 | A low-privileged remote attacker can exploit a command injection vulnerability in the /ind… | |
| CVE-2026-20929 | Medium | 2.9% | 7.5 | Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privi… | |
| CVE-2026-80099 | Medium | 2.9% | 8.8 | Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists … | |
| CVE-2026-61400 | Medium | 2.9% | 8.8 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulner… | |
| CVE-2019-1687 | Medium | 2.9% | 7.5 | A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA)… | |
| CVE-2019-1703 | Medium | 2.9% | 8.6 | A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat … | |
| CVE-2026-77683 | Medium | 2.9% | 9.9 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is … | |
| CVE-2026-29146 | Medium | 2.9% | 7.5 | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configurat… | |
| CVE-2026-86152 | Medium | 2.9% | 10.0 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAuto… | |
| CVE-2026-87902 | Medium | 2.9% | 8.1 | An unauthenticated attacker can make `get_page_template()` page-template resolution includ… | |
| CVE-2026-38820 | Medium | 2.9% | 8.3 | openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell com… | |
| CVE-2026-19599 | Medium | 2.9% | 9.9 | ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remot… | |
| CVE-2021-33758 | Medium | 2.8% | 7.7 | Windows Hyper-V Denial of Service Vulnerability | |
| CVE-2026-85431 | Medium | 2.8% | 7.5 | MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injectio… | |
| CVE-2021-26867 | Medium | 2.8% | 9.9 | Windows Hyper-V Remote Code Execution Vulnerability | |
| CVE-2026-44825 | Medium | 2.8% | 8.1 | Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apa… | |
| CVE-2026-19682 | Medium | 2.8% | 9.9 | A command injection vulnerability exists in Security Center where a remote, unauthenticate… | |
| CVE-2026-9103 | Medium | 2.8% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized a… | |
| CVE-2026-23631 | Medium | 2.8% | 8.1 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scrip… | |
| CVE-2026-73680 | Medium | 2.8% | 8.8 | Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg inte… | |
| CVE-2026-80143 | Medium | 2.8% | 9.9 | Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and … | |
| CVE-2026-80144 | Medium | 2.8% | 9.9 | Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and … | |
| CVE-2026-69694 | Medium | 2.8% | 7.0 | Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows a… | |
| CVE-2026-71921 | Medium | 2.8% | 9.8 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnera… | |
| CVE-2026-38708 | Medium | 2.8% | 9.8 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3… | |
| CVE-2026-38709 | Medium | 2.8% | 9.8 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3… | |
| CVE-2026-38711 | Medium | 2.8% | 9.8 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3… | |
| CVE-2026-38713 | Medium | 2.8% | 9.8 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3… | |
| CVE-2026-77031 | Medium | 2.7% | 7.4 | A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function… | |
| CVE-2026-78063 | Medium | 2.7% | 7.4 | A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the fun… | |
| CVE-2026-78141 | Medium | 2.7% | 7.4 | A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCom… | |
| CVE-2026-69251 | Medium | 2.7% | 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-9290 | Medium | 2.7% | 7.5 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable… | |
| CVE-2021-33740 | Medium | 2.7% | 7.8 | Windows Media Remote Code Execution Vulnerability | |
| CVE-2026-25555 | Medium | 2.7% | 9.8 | OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the A… | |
| CVE-2024-58376 | Medium | 2.7% | 8.8 | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in th… | |
| CVE-2026-19346 | Medium | 2.7% | 8.8 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the funct… | |
| CVE-2026-27563 | Medium | 2.7% | 7.2 | A high-privileged remote attacker can exploit a command injection vulnerability in the /ap… | |
| CVE-2026-86167 | Medium | 2.7% | 9.9 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponC… | |
| CVE-2000-1238 | Medium | 2.7% | 7.5 | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to by… | |
| CVE-2021-34449 | Medium | 2.7% | 7.0 | Win32k Elevation of Privilege Vulnerability |