Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-19981 | Medium | 1.8% | 7.4 | A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, … | |
| CVE-2026-19982 | Medium | 1.8% | 7.4 | A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulner… | |
| CVE-2026-63108 | Medium | 1.8% | 8.8 | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve exe… | |
| CVE-2026-76582 | Medium | 1.8% | 7.4 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function … | |
| CVE-2026-77004 | Medium | 1.8% | 7.4 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the… | |
| CVE-2026-77945 | Medium | 1.8% | 7.4 | A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown functio… | |
| CVE-2026-13206 | Medium | 1.8% | 9.8 | Improper neutralization of special elements used in an OS command ('OS command injection')… | |
| CVE-2026-16053 | Medium | 1.8% | 8.5 | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are aff… | |
| CVE-2026-71376 | Medium | 1.8% | 9.8 | OS command injection vulnerability in Cosminexus Component Container. This issue affects … | |
| CVE-2023-21803 | Medium | 1.8% | 9.8 | Windows iSCSI Discovery Service Remote Code Execution Vulnerability | |
| CVE-2026-25639 | Medium | 1.8% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3… | |
| CVE-2026-66147 | Medium | 1.8% | 9.4 | An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Se… | |
| CVE-2020-3533 | Medium | 1.8% | 8.6 | A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of… | |
| CVE-2026-34615 | Medium | 1.8% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untr… | |
| CVE-2023-21713 | Medium | 1.8% | 8.8 | Microsoft SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-44185 | Medium | 1.8% | 7.3 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an atta… | |
| CVE-2017-17537 | Medium | 1.8% | 7.5 | MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to caus… | |
| CVE-2026-4408 | Medium | 1.8% | 9.0 | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file … | |
| CVE-2024-38239 | Medium | 1.7% | 7.2 | Windows Kerberos Elevation of Privilege Vulnerability | |
| CVE-2026-51134 | Medium | 1.7% | 7.5 | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Tr… | |
| CVE-2026-87911 | Medium | 1.7% | 9.6 | An OS command injection weakness in the read-only enforcement of the SQL validation compon… | |
| CVE-2023-21816 | Medium | 1.7% | 7.5 | Windows Active Directory Domain Services API Denial of Service Vulnerability | |
| CVE-2024-21420 | Medium | 1.7% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-50652 | Medium | 1.7% | 7.5 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacke… | |
| CVE-2026-82456 | Medium | 1.7% | 10.0 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessi… | |
| CVE-2026-41104 | Medium | 1.7% | 10.0 | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthoriz… | |
| CVE-2024-21380 | Medium | 1.7% | 8.0 | Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | |
| CVE-2026-71364 | Medium | 1.7% | 7.2 | A path traversal vulnerability was found in AWX's project archive extraction. The project_… | |
| CVE-2024-21379 | Medium | 1.7% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2026-66713 | Medium | 1.7% | 9.8 | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in… | |
| CVE-2020-11753 | Medium | 1.7% | 8.8 | An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0… | |
| CVE-2026-75791 | Medium | 1.7% | 8.6 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an a… | |
| CVE-2026-59764 | Medium | 1.7% | 7.2 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vuln… | |
| CVE-2026-61376 | Medium | 1.7% | 7.2 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vuln… | |
| CVE-2026-32475 | Medium | 1.7% | 9.0 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro a… | |
| CVE-2023-36911 | Medium | 1.7% | 9.8 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
| CVE-2026-44170 | Medium | 1.7% | 9.8 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to befo… | |
| CVE-2024-37965 | Medium | 1.7% | 8.8 | Microsoft SQL Server Elevation of Privilege Vulnerability | |
| CVE-2026-3396 | Medium | 1.7% | 7.5 | WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection v… | |
| CVE-2026-27833 | Medium | 1.7% | 7.5 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, t… | |
| CVE-2023-36897 | Medium | 1.7% | 8.1 | Visual Studio Tools for Office Runtime Spoofing Vulnerability | |
| CVE-2026-68861 | Medium | 1.7% | 8.8 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of … | |
| CVE-2026-5946 | Medium | 1.7% | 7.5 | Multiple flaws have been identified in `named` related to the handling of DNS messages who… | |
| CVE-2026-50515 | Medium | 1.7% | 9.9 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to ex… | |
| CVE-2026-50517 | Medium | 1.7% | 9.9 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute… | |
| CVE-2026-65665 | Medium | 1.7% | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2026-65815 | Medium | 1.7% | 8.8 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an author… | |
| CVE-2026-70321 | Medium | 1.7% | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2026-77484 | Medium | 1.7% | 8.8 | Deserialization of untrusted data in SQL Server allows an authorized attacker to execute c… | |
| CVE-2026-65772 | Medium | 1.7% | 8.8 | Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker … |