Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-7467 | Medium | 1.6% | 8.8 | The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in al… | |
| CVE-2026-8836 | Medium | 1.6% | 9.8 | A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound… | |
| CVE-2026-48933 | Medium | 1.6% | 7.5 | A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.e… | |
| CVE-2026-12650 | Medium | 1.6% | 9.9 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2… | |
| CVE-2021-41378 | Medium | 1.6% | 7.8 | Windows NTFS Remote Code Execution Vulnerability | |
| CVE-2024-1132 | Medium | 1.6% | 8.1 | A flaw was found in Keycloak, where it does not properly validate URLs included in a redir… | |
| CVE-2026-66733 | Medium | 1.6% | 7.5 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability… | |
| CVE-2026-14959 | Medium | 1.6% | 9.1 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to … | |
| CVE-2026-23869 | Medium | 1.6% | 7.5 | A denial of service vulnerability exists in React Server Components, affecting the followi… | |
| CVE-2026-5433 | Medium | 1.6% | 9.1 | Honeywell Control Network Module (CNM) contains command injection vulnerability in the web… | |
| CVE-2026-71171 | Medium | 1.6% | 7.2 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization … | |
| CVE-2026-78327 | Medium | 1.6% | 9.1 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injectio… | |
| CVE-2024-21369 | Medium | 1.5% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-18798 | Medium | 1.5% | 7.5 | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel … | |
| CVE-2026-3018 | Medium | 1.5% | 7.5 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wp… | |
| CVE-2026-39364 | Medium | 1.5% | 7.5 | Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5,… | |
| CVE-2026-40860 | Medium | 1.5% | 9.8 | JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel… | |
| CVE-2024-1394 | Medium | 1.5% | 7.5 | A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might … | |
| CVE-2026-23870 | Medium | 1.5% | 7.5 | A denial of service vulnerability could be triggered by sending specially crafted HTTP req… | |
| CVE-2026-53804 | Medium | 1.5% | 7.2 | OTRS Community Edition contains an authenticated OS command injection vulnerability in the… | |
| CVE-2026-26142 | Medium | 1.5% | 9.8 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to… | |
| CVE-2026-54117 | Medium | 1.5% | 9.8 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute… | |
| CVE-2026-54118 | Medium | 1.5% | 9.8 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute… | |
| CVE-2026-55944 | Medium | 1.5% | 9.8 | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacke… | |
| CVE-2026-59124 | Medium | 1.5% | 9.8 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allow… | |
| CVE-2026-69836 | Medium | 1.5% | 10.0 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to… | |
| CVE-2021-40117 | Medium | 1.5% | 8.6 | A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Sof… | |
| CVE-2026-13153 | Medium | 1.5% | 7.5 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to … | |
| CVE-2026-63722 | Medium | 1.5% | 9.8 | ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows u… | |
| CVE-2026-6837 | Medium | 1.5% | 7.2 | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Z… | |
| CVE-2026-6952 | Medium | 1.5% | 7.2 | A post-authentication command injection vulnerability in the "LogServer" field of the sysl… | |
| CVE-2026-28325 | Medium | 1.5% | 8.8 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote… | |
| CVE-2026-65700 | Medium | 1.5% | 9.8 | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible file… | |
| CVE-2026-36829 | Medium | 1.5% | 9.8 | An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-X… | |
| CVE-2026-12370 | Medium | 1.5% | 7.6 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versi… | |
| CVE-2026-49121 | Medium | 1.5% | 8.1 | AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code e… | |
| CVE-2026-0631 | Medium | 1.5% | 8.0 | An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3… | |
| CVE-2026-6473 | Medium | 1.5% | 8.8 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database … | |
| CVE-2024-26192 | Medium | 1.5% | 8.2 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | |
| CVE-2026-23479 | Medium | 1.5% | 8.8 | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the un… | |
| CVE-2023-36873 | Medium | 1.5% | 7.4 | .NET Framework Spoofing Vulnerability | |
| CVE-2026-15013 | Medium | 1.5% | 9.8 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication B… | |
| CVE-2026-48168 | Medium | 1.5% | 10.0 | PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude G… | |
| CVE-2023-39533 | Medium | 1.5% | 7.5 | go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.… | |
| CVE-2026-5208 | Medium | 1.5% | 8.2 | Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated at… | |
| CVE-2026-18912 | Medium | 1.5% | 7.7 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL… | |
| CVE-2026-16850 | Medium | 1.5% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arb… | |
| CVE-2026-61409 | Medium | 1.5% | 7.3 | Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains … | |
| CVE-2026-75743 | Medium | 1.5% | 7.1 | Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vuln… | |
| CVE-2025-5987 | Medium | 1.5% | 8.1 | A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an … |