Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2020-3298 | Medium | 2.0% | 7.5 | A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Se… | |
| CVE-2026-12186 | Medium | 2.0% | 8.8 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function … | |
| CVE-2021-33754 | Medium | 2.0% | 8.0 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2026-53822 | Medium | 2.0% | 8.8 | OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper a… | |
| CVE-2026-74770 | Medium | 2.0% | 8.8 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of … | |
| CVE-2005-10004 | Medium | 2.0% | 8.8 | Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the gr… | |
| CVE-2026-54646 | Medium | 1.9% | 7.2 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.inde… | |
| CVE-2026-54647 | Medium | 1.9% | 7.2 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.i… | |
| CVE-2026-72589 | Medium | 1.9% | 9.8 | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an u… | |
| CVE-2026-18729 | Medium | 1.9% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execu… | |
| CVE-2026-53595 | Medium | 1.9% | 9.4 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior t… | |
| CVE-2026-94450 | Medium | 1.9% | 7.5 | Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier… | |
| CVE-2026-12187 | Medium | 1.9% | 8.8 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by t… | |
| CVE-2026-39929 | Medium | 1.9% | 7.5 | Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 conta… | |
| CVE-2026-50979 | Medium | 1.9% | 8.1 | A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPa… | |
| CVE-2000-0981 | Medium | 1.9% | 7.2 | MySQL Database Engine uses a weak authentication method which leaks information that could… | |
| CVE-2020-3436 | Medium | 1.9% | 8.6 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) a… | |
| CVE-2026-46522 | Medium | 1.9% | 7.5 | ImageMagick is free and open-source software used for editing and manipulating digital ima… | |
| CVE-2000-1236 | Medium | 1.9% | 7.5 | SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 a… | |
| CVE-2026-90880 | Medium | 1.9% | 7.4 | A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the … | |
| CVE-2021-31984 | Medium | 1.9% | 7.6 | Power BI Remote Code Execution Vulnerability | |
| CVE-2026-71209 | Medium | 1.9% | 7.5 | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthent… | |
| CVE-2026-82636 | Medium | 1.9% | 7.9 | Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy… | |
| CVE-2020-3195 | Medium | 1.9% | 7.5 | A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Se… | |
| CVE-2020-3196 | Medium | 1.9% | 8.6 | A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler o… | |
| CVE-2026-94089 | Medium | 1.9% | 10.0 | A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function… | |
| CVE-2026-55584 | Medium | 1.9% | 7.5 | phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, … | |
| CVE-2026-81942 | Medium | 1.9% | 8.8 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412… | |
| CVE-2023-35381 | Medium | 1.9% | 8.8 | Windows Fax Service Remote Code Execution Vulnerability | |
| CVE-2026-44578 | Medium | 1.9% | 8.6 | Next.js is a React framework for building full-stack web applications. From 13.4.13 to bef… | |
| CVE-2024-38259 | Medium | 1.9% | 8.8 | Microsoft Management Console Remote Code Execution Vulnerability | |
| CVE-2026-34792 | Medium | 1.9% | 8.8 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS… | |
| CVE-2026-34793 | Medium | 1.9% | 8.8 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS… | |
| CVE-2026-34794 | Medium | 1.9% | 8.8 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS… | |
| CVE-2026-34795 | Medium | 1.9% | 8.8 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS… | |
| CVE-2026-34796 | Medium | 1.9% | 8.8 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS… | |
| CVE-2026-34797 | Medium | 1.9% | 8.8 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS… | |
| CVE-2026-77853 | Medium | 1.9% | 8.8 | Improper neutralization of special elements used in an OS command ('OS Command Injection')… | |
| CVE-2026-15981 | Medium | 1.9% | 9.8 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication B… | |
| CVE-2021-36945 | Medium | 1.9% | 7.3 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| CVE-2026-51190 | Medium | 1.9% | 9.8 | The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized us… | |
| CVE-2026-27303 | Medium | 1.9% | 9.6 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untr… | |
| CVE-2026-34659 | Medium | 1.9% | 9.6 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization… | |
| CVE-2026-69806 | Medium | 1.9% | 7.0 | Exposure of sensitive information to an unauthorized actor in .NET allows an authorized at… | |
| CVE-2024-12254 | Medium | 1.9% | 7.5 | Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would… | |
| CVE-2026-27130 | Medium | 1.9% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below h… | |
| CVE-2026-70374 | Medium | 1.9% | 8.8 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the… | |
| CVE-2026-70375 | Medium | 1.9% | 8.8 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the… | |
| CVE-2026-78037 | Medium | 1.9% | 8.8 | Xiiaozet LK100W is vulnerable to OS command injection through its web-based management in… | |
| CVE-2026-82762 | Medium | 1.9% | 8.8 | Improper neutralization of special elements used in an OS command ('OS Command Injection')… |