Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-61515 | Medium | 2.4% | 9.8 | Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command inj… | |
| CVE-2026-28389 | Medium | 2.4% | 7.5 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecip… | |
| CVE-2026-28390 | Medium | 2.4% | 7.5 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportR… | |
| CVE-2021-2351 | Medium | 2.4% | 8.3 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Suppo… | |
| CVE-2026-67599 | Medium | 2.4% | 7.2 | ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component tha… | |
| CVE-2026-67608 | Medium | 2.4% | 7.2 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions,… | |
| CVE-2026-46300 | Medium | 2.4% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve… | |
| CVE-2022-41106 | Medium | 2.4% | 8.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2021-34530 | Medium | 2.4% | 7.8 | Windows Graphics Component Remote Code Execution Vulnerability | |
| CVE-2021-34533 | Medium | 2.4% | 7.8 | Windows Graphics Component Font Parsing Remote Code Execution Vulnerability | |
| CVE-2026-93616 | Medium | 2.4% | 9.8 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to … | |
| CVE-2026-66297 | Medium | 2.4% | 8.0 | Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) v… | |
| CVE-2021-33781 | Medium | 2.4% | 8.1 | Azure AD Security Feature Bypass Vulnerability | |
| CVE-2000-1244 | Medium | 2.4% | 7.5 | Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail vir… | |
| CVE-2017-16879 | Medium | 2.4% | 7.8 | Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncur… | |
| CVE-2026-76904 | Medium | 2.4% | 9.8 | GeoTools is an open source Java library that provides tools for geospatial data. Starting … | |
| CVE-2024-21386 | Medium | 2.4% | 7.5 | .NET Denial of Service Vulnerability | |
| CVE-2026-49003 | Medium | 2.4% | 9.6 | Attackers can exploit command injection vulnerabilities to delete core system runtime file… | |
| CVE-2018-0230 | Medium | 2.4% | 8.6 | A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat … | |
| CVE-2021-33749 | Medium | 2.4% | 8.8 | Windows DNS Snap-in Remote Code Execution Vulnerability | |
| CVE-2021-33750 | Medium | 2.4% | 8.8 | Windows DNS Snap-in Remote Code Execution Vulnerability | |
| CVE-2021-33752 | Medium | 2.4% | 8.8 | Windows DNS Snap-in Remote Code Execution Vulnerability | |
| CVE-2017-6632 | Medium | 2.4% | 7.5 | A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Ci… | |
| CVE-2026-59867 | Medium | 2.4% | 7.1 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota re… | |
| CVE-2021-33779 | Medium | 2.4% | 8.1 | Windows AD FS Security Feature Bypass Vulnerability | |
| CVE-2017-11113 | Medium | 2.4% | 7.5 | In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tin… | |
| CVE-2026-6279 | Medium | 2.4% | 9.8 | The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated R… | |
| CVE-2000-0961 | Medium | 2.4% | 10.0 | Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local user… | |
| CVE-2021-33756 | Medium | 2.4% | 8.8 | Windows DNS Snap-in Remote Code Execution Vulnerability | |
| CVE-2026-12197 | Medium | 2.4% | 7.2 | A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the … | |
| CVE-2019-25029 | Medium | 2.4% | 9.8 | In Versa Director, the command injection is an attack in which the goal is execution of ar… | |
| CVE-2026-76060 | Medium | 2.4% | 8.8 | An authenticated OS command injection vulnerability exists in ZoneMinder's event export fu… | |
| CVE-2021-33775 | Medium | 2.4% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2021-33776 | Medium | 2.4% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2021-33777 | Medium | 2.4% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2021-33778 | Medium | 2.4% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2021-34521 | Medium | 2.4% | 7.8 | Raw Image Extension Remote Code Execution Vulnerability | |
| CVE-2022-34821 | Medium | 2.4% | 7.6 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), R… | |
| CVE-2022-38023 | Medium | 2.4% | 8.1 | Netlogon RPC Elevation of Privilege Vulnerability | |
| CVE-2026-42055 | Medium | 2.4% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and … | |
| CVE-2026-81048 | Medium | 2.4% | 9.6 | Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Spec… | |
| CVE-2026-35868 | Medium | 2.3% | 9.8 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the li… | |
| CVE-2026-35869 | Medium | 2.3% | 9.8 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the li… | |
| CVE-2021-42316 | Medium | 2.3% | 8.8 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | |
| CVE-2026-71362 | Medium | 2.3% | 9.1 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result i… | |
| CVE-2026-38710 | Medium | 2.3% | 7.2 | TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerabi… | |
| CVE-2021-34518 | Medium | 2.3% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2000-0803 | Medium | 2.3% | 10.0 | GNU Groff uses the current working directory to find a device description file, which allo… | |
| CVE-2025-9784 | Medium | 2.3% | 7.5 | A flaw was found in Undertow where malformed client requests can trigger server-side strea… | |
| CVE-2021-40143 | Medium | 2.3% | 8.2 | Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection.… |