Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-34508 | Medium | 2.2% | 8.8 | Windows Kernel Remote Code Execution Vulnerability | |
| CVE-2021-34525 | Medium | 2.2% | 8.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2026-64881 | Medium | 2.2% | 8.8 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters t… | |
| CVE-2026-72603 | Medium | 2.2% | 9.9 | An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.crea… | |
| CVE-2020-15871 | Medium | 2.2% | 8.8 | Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Executi… | |
| CVE-2017-11112 | Medium | 2.2% | 7.5 | In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function… | |
| CVE-2026-67325 | Medium | 2.2% | 8.8 | GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to a… | |
| CVE-2021-34452 | Medium | 2.2% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2021-36941 | Medium | 2.2% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2020-3550 | Medium | 2.2% | 8.1 | A vulnerability in the sfmgr daemon of Cisco Firepower Management Center (FMC) Software an… | |
| CVE-2026-10870 | Medium | 2.2% | 7.2 | A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of… | |
| CVE-2026-10871 | Medium | 2.2% | 7.2 | A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the … | |
| CVE-2020-1125 | Medium | 2.2% | 7.0 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles… | |
| CVE-2020-1149 | Medium | 2.2% | 7.0 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles… | |
| CVE-2020-1151 | Medium | 2.2% | 7.0 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles… | |
| CVE-2020-1164 | Medium | 2.2% | 7.0 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles… | |
| CVE-2021-34438 | Medium | 2.2% | 7.8 | Windows Font Driver Host Remote Code Execution Vulnerability | |
| CVE-2021-34441 | Medium | 2.2% | 7.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | |
| CVE-2024-21400 | Medium | 2.2% | 9.0 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerabi… | |
| CVE-2026-90822 | Medium | 2.2% | 9.8 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r… | |
| CVE-2024-37966 | Medium | 2.2% | 7.1 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | |
| CVE-2026-12745 | Medium | 2.2% | 9.8 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2… | |
| CVE-2026-82668 | Medium | 2.2% | 7.3 | A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by thi… | |
| CVE-2026-90843 | Medium | 2.2% | 8.3 | A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c0… | |
| CVE-2025-68428 | Medium | 2.2% | 7.5 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of… | |
| CVE-2024-21348 | Medium | 2.2% | 7.5 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | |
| CVE-2025-61726 | Medium | 2.2% | 7.5 | The net/url package does not set a limit on the number of query parameters in a query. Whi… | |
| CVE-2026-45447 | Medium | 2.2% | 8.8 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-aft… | |
| CVE-2026-49199 | Medium | 2.2% | 9.8 | Crafted MQTT messages can trigger command injection, resulting in root-level code executio… | |
| CVE-2026-53435 | Medium | 2.2% | 8.8 | In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to hav… | |
| CVE-2026-30311 | Medium | 2.2% | 9.8 | Ridvay Code's command auto-approval module contains a critical OS command injection vulner… | |
| CVE-2026-30314 | Medium | 2.2% | 9.8 | Ridvay Code's command auto-approval module contains a critical OS command injection vulner… | |
| CVE-2021-34474 | Medium | 2.2% | 8.0 | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | |
| CVE-2023-29328 | Medium | 2.2% | 8.8 | Microsoft Teams Remote Code Execution Vulnerability | |
| CVE-2026-63766 | Medium | 2.1% | 9.8 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.p… | |
| CVE-2013-0335 | Medium | 2.1% | 7.6 | OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authen… | |
| CVE-2026-28316 | Medium | 2.1% | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability … | |
| CVE-2026-30312 | Medium | 2.1% | 9.8 | DSAI-Cline's command auto-approval module contains a critical OS command injection vulnera… | |
| CVE-2026-67206 | Medium | 2.1% | 8.8 | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerCont… | |
| CVE-2021-34468 | Medium | 2.1% | 7.1 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| CVE-2026-19263 | Medium | 2.1% | 7.3 | A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8a… | |
| CVE-2026-90617 | Medium | 2.1% | 7.3 | A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5… | |
| CVE-2026-90618 | Medium | 2.1% | 7.3 | A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e54263156… | |
| CVE-2000-1239 | Medium | 2.1% | 9.0 | The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management F… | |
| CVE-2026-10768 | Medium | 2.1% | 9.8 | Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing.… | |
| CVE-2026-40280 | Medium | 2.1% | 7.5 | Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the de… | |
| CVE-2026-5802 | Medium | 2.1% | 7.3 | A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown f… | |
| CVE-2026-76761 | Medium | 2.1% | 7.3 | A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the functio… | |
| CVE-2026-79912 | Medium | 2.1% | 8.3 | A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted elemen… | |
| CVE-2026-90690 | Medium | 2.1% | 7.3 | A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e9… |