Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-73693 | Medium | 2.7% | 8.8 | FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSh… | |
| CVE-2021-26876 | Medium | 2.7% | 8.8 | OpenType Font Parsing Remote Code Execution Vulnerability | |
| CVE-2021-33780 | Medium | 2.7% | 8.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2024-21404 | Medium | 2.7% | 7.5 | .NET Denial of Service Vulnerability | |
| CVE-2026-71961 | Medium | 2.7% | 8.8 | Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerabil… | |
| CVE-2026-93958 | Medium | 2.7% | 9.1 | A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the fun… | |
| CVE-2021-34522 | Medium | 2.7% | 7.8 | Microsoft Defender Remote Code Execution Vulnerability | |
| CVE-2026-9256 | Medium | 2.7% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module modul… | |
| CVE-2026-10873 | Medium | 2.7% | 7.2 | A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats… | |
| CVE-2026-42536 | Medium | 2.7% | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2Start… | |
| CVE-2021-26861 | Medium | 2.7% | 7.8 | Windows Graphics Component Remote Code Execution Vulnerability | |
| CVE-2021-27047 | Medium | 2.7% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2023-38185 | Medium | 2.7% | 8.8 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2020-3554 | Medium | 2.7% | 7.5 | A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) So… | |
| CVE-2026-18641 | Medium | 2.7% | 7.3 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management Sy… | |
| CVE-2026-19379 | Medium | 2.7% | 7.3 | A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function pop… | |
| CVE-2026-9367 | Medium | 2.7% | 7.3 | A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdeb… | |
| CVE-2026-34355 | Medium | 2.7% | 7.5 | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an att… | |
| CVE-2026-94106 | Medium | 2.7% | 8.8 | getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers … | |
| CVE-2021-34439 | Medium | 2.6% | 7.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | |
| CVE-2024-7885 | Medium | 2.6% | 7.5 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same … | |
| CVE-2021-34464 | Medium | 2.6% | 7.8 | Microsoft Defender Remote Code Execution Vulnerability | |
| CVE-2026-85688 | Medium | 2.6% | 9.8 | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabiliti… | |
| CVE-2026-10872 | Medium | 2.6% | 7.2 | A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function star… | |
| CVE-2026-35196 | Medium | 2.6% | 8.8 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3,… | |
| CVE-2025-1244 | Medium | 2.6% | 8.8 | A command injection flaw was found in the text editor Emacs. It could allow a remote, unau… | |
| CVE-2026-28672 | Medium | 2.6% | 9.8 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulner… | |
| CVE-2021-34458 | Medium | 2.6% | 9.9 | Windows Kernel Remote Code Execution Vulnerability | |
| CVE-2021-26881 | Medium | 2.6% | 7.5 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | |
| CVE-2026-39363 | Medium | 2.6% | 7.5 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, an… | |
| CVE-2026-4800 | Medium | 2.6% | 8.1 | Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) ad… | |
| CVE-2026-8450 | Medium | 2.6% | 9.1 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). se… | |
| CVE-2026-53976 | Medium | 2.6% | 9.1 | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /… | |
| CVE-2026-65091 | Medium | 2.6% | 8.8 | NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway coul… | |
| CVE-2026-20820 | Medium | 2.6% | 7.8 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized a… | |
| CVE-2026-30818 | Medium | 2.6% | 8.0 | An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 al… | |
| CVE-2023-38178 | Medium | 2.6% | 7.5 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| CVE-2026-16766 | Medium | 2.6% | 9.8 | Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (… | |
| CVE-2026-85672 | Medium | 2.6% | 9.8 | zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism… | |
| CVE-2026-85696 | Medium | 2.6% | 9.8 | SadTalker contains an OS command injection vulnerability in the video muxing process where… | |
| CVE-2026-71914 | Medium | 2.6% | 9.8 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm … | |
| CVE-2026-24207 | Medium | 2.6% | 9.8 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an a… | |
| CVE-2026-14863 | Medium | 2.5% | 8.8 | FileRun up to and including version 2026.2.0 contains an OS command injection vulnerabilit… | |
| CVE-2021-24110 | Medium | 2.5% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2021-31947 | Medium | 2.5% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2000-0947 | Medium | 2.5% | 10.0 | Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers… | |
| CVE-2020-1067 | Medium | 2.5% | 7.8 | A remote code execution vulnerability exists in the way that Windows handles objects in me… | |
| CVE-2022-37966 | Medium | 2.5% | 8.1 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | |
| CVE-2019-1694 | Medium | 2.5% | 8.6 | A vulnerability in the TCP processing engine of Cisco Adaptive Security Appliance (ASA) So… | |
| CVE-2026-55009 | Medium | 2.5% | 7.8 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attack… |