Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-12648 | Medium | 1.5% | 8.8 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2… | |
| CVE-2026-12651 | Medium | 1.5% | 8.8 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2… | |
| CVE-2026-24252 | Medium | 1.5% | 7.8 | NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command inje… | |
| CVE-2026-69085 | Medium | 1.5% | 10.0 | SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDoc… | |
| CVE-2024-38240 | Medium | 1.5% | 8.1 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
| CVE-2022-20745 | Medium | 1.5% | 8.6 | A vulnerability in the web services interface for remote access VPN features of Cisco Adap… | |
| CVE-2024-21350 | Medium | 1.5% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-59681 | Medium | 1.5% | 8.8 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls … | |
| CVE-2026-49481 | Medium | 1.5% | 9.6 | UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vuln… | |
| CVE-2026-9862 | Medium | 1.5% | 9.8 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerabi… | |
| CVE-2000-1028 | Medium | 1.5% | 7.2 | Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a… | |
| CVE-2026-14947 | Medium | 1.5% | 7.2 | A high-privileged remote attacker can upload malicious ZIP archive containing directory tr… | |
| CVE-2026-78167 | Medium | 1.5% | 10.0 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the … | |
| CVE-2026-78006 | Medium | 1.5% | 9.8 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all… | |
| CVE-2026-42461 | Medium | 1.5% | 7.5 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prio… | |
| CVE-2026-13147 | Medium | 1.5% | 9.1 | The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before req… | |
| CVE-2023-38184 | Medium | 1.5% | 7.5 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | |
| CVE-2024-21401 | Medium | 1.5% | 9.8 | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | |
| CVE-2026-75121 | Medium | 1.5% | 7.2 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command … | |
| CVE-2026-75123 | Medium | 1.5% | 7.2 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command … | |
| CVE-2026-33231 | Medium | 1.5% | 7.5 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and t… | |
| CVE-2026-5614 | Medium | 1.5% | 8.8 | A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function fo… | |
| CVE-2026-18129 | Medium | 1.5% | 8.1 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager bef… | |
| CVE-2026-44879 | Medium | 1.5% | 7.2 | A vulnerability in the command line interface of ECOS devices could allow a highly privile… | |
| CVE-2026-73722 | Medium | 1.5% | 7.2 | Command injection vulnerabilities in the web-based management interface of HPE Networking … | |
| CVE-2026-73766 | Medium | 1.5% | 7.2 | Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticat… | |
| CVE-2026-76675 | Medium | 1.5% | 9.1 | A command injection vulnerability exists in the command line interface of EdgeConnect SD-W… | |
| CVE-2026-34453 | Medium | 1.5% | 7.5 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish serv… | |
| CVE-2026-6721 | Medium | 1.4% | 9.8 | IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply speci… | |
| CVE-2026-16329 | Medium | 1.4% | 7.3 | A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of… | |
| CVE-2026-16332 | Medium | 1.4% | 7.3 | A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of … | |
| CVE-2026-92580 | Medium | 1.4% | 8.8 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection.… | |
| CVE-2022-20685 | Medium | 1.4% | 7.5 | A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an un… | |
| CVE-2024-37341 | Medium | 1.4% | 8.8 | Microsoft SQL Server Elevation of Privilege Vulnerability | |
| CVE-2026-14828 | Medium | 1.4% | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8… | |
| CVE-2026-77533 | Medium | 1.4% | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper … | |
| CVE-2026-77543 | Medium | 1.4% | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper … | |
| CVE-2026-77546 | Medium | 1.4% | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper … | |
| CVE-2026-77547 | Medium | 1.4% | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper … | |
| CVE-2026-77548 | Medium | 1.4% | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper … | |
| CVE-2026-86296 | Medium | 1.4% | 10.0 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the fu… | |
| CVE-2026-33000 | Medium | 1.4% | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper… | |
| CVE-2021-27077 | Medium | 1.4% | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2000-1211 | Medium | 1.4% | 7.5 | Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names … | |
| CVE-2026-64193 | Medium | 1.4% | 9.8 | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED… | |
| CVE-2026-85425 | Medium | 1.4% | 9.8 | MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOO… | |
| CVE-2026-85978 | Medium | 1.4% | 9.8 | An unauthenticated remote code execution vulnerability exists in the Policy Manager consol… | |
| CVE-2023-4853 | Medium | 1.4% | 8.1 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain charac… | |
| CVE-2020-3528 | Medium | 1.4% | 8.6 | A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security A… | |
| CVE-2021-34792 | Medium | 1.4% | 8.6 | A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Softwa… |