Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-67261 | Medium | 2.3% | 9.8 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, co… | |
| CVE-2026-75486 | Medium | 2.3% | 8.0 | Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an a… | |
| CVE-2024-38236 | Medium | 2.3% | 7.5 | DHCP Server Service Denial of Service Vulnerability | |
| CVE-2024-7387 | Medium | 2.3% | 9.1 | A flaw was found in openshift/builder. This vulnerability allows command injection via pat… | |
| CVE-2026-75604 | Medium | 2.3% | 9.0 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 1… | |
| CVE-2026-86295 | Medium | 2.3% | 8.3 | A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK … | |
| CVE-2021-34503 | Medium | 2.3% | 7.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | |
| CVE-2026-3039 | Medium | 2.3% | 7.5 | BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are v… | |
| CVE-2026-45484 | Medium | 2.3% | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2019-1895 | Medium | 2.3% | 9.8 | A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Ent… | |
| CVE-2026-54795 | Medium | 2.3% | 8.8 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization o… | |
| CVE-2021-36937 | Medium | 2.3% | 7.8 | Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | |
| CVE-2026-38822 | Medium | 2.3% | 7.6 | In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to se… | |
| CVE-2026-36828 | Medium | 2.3% | 8.8 | A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabi… | |
| CVE-2026-75002 | Medium | 2.3% | 7.1 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-c… | |
| CVE-2021-38644 | Medium | 2.3% | 7.8 | Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | |
| CVE-2021-38660 | Medium | 2.3% | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | |
| CVE-2021-38661 | Medium | 2.3% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2021-40442 | Medium | 2.3% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2025-4334 | Medium | 2.3% | 9.8 | The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in… | |
| CVE-2026-71905 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSet… | |
| CVE-2026-71906 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan fu… | |
| CVE-2026-71907 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset… | |
| CVE-2026-71908 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_star… | |
| CVE-2026-71909 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTi… | |
| CVE-2026-71910 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotes… | |
| CVE-2026-71915 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsons… | |
| CVE-2026-71917 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingt… | |
| CVE-2026-71918 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBa… | |
| CVE-2026-71919 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysre… | |
| CVE-2026-71923 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_… | |
| CVE-2026-71924 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVi… | |
| CVE-2026-71925 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDe… | |
| CVE-2026-71926 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDe… | |
| CVE-2026-71927 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDe… | |
| CVE-2026-71928 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftD… | |
| CVE-2026-71929 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDe… | |
| CVE-2026-71930 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTi… | |
| CVE-2026-71943 | Medium | 2.3% | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDe… | |
| CVE-2026-85012 | Medium | 2.3% | 8.0 | Improper neutralization of special elements used in an OS command (CWE-78) in the blueprin… | |
| CVE-2026-64879 | Medium | 2.3% | 9.9 | A filename supplied during file upload is not properly sanitized before being used in syst… | |
| CVE-2026-48573 | Medium | 2.3% | 7.9 | No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a sec… | |
| CVE-2026-48576 | Medium | 2.3% | 7.9 | No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a sec… | |
| CVE-2026-43500 | Medium | 2.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare D… | |
| CVE-2026-12744 | Medium | 2.3% | 9.8 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2… | |
| CVE-2025-29296 | Medium | 2.3% | 9.8 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3… | |
| CVE-2026-82222 | Medium | 2.3% | 10.0 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Ob… | |
| CVE-2026-24486 | Medium | 2.2% | 8.6 | Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Pa… | |
| CVE-2026-73694 | Medium | 2.2% | 7.2 | FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op r… | |
| CVE-2019-1704 | Medium | 2.2% | 7.5 | Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection… |