Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-38045 | Medium | 1.4% | 8.1 | Windows TCP/IP Remote Code Execution Vulnerability | |
| CVE-2025-4517 | Medium | 1.4% | 9.4 | Allows arbitrary filesystem writes outside the extraction directory during extraction with… | |
| CVE-2026-5121 | Medium | 1.4% | 7.5 | A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exist… | |
| CVE-2026-19949 | Medium | 1.4% | 8.8 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection… | |
| CVE-2026-36723 | Medium | 1.4% | 8.8 | An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8… | |
| CVE-2026-5917 | Medium | 1.4% | 8.8 | libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (U… | |
| CVE-2026-83627 | Medium | 1.4% | 9.8 | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress… | |
| CVE-2023-21691 | Medium | 1.4% | 7.5 | Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulne… | |
| CVE-2024-33775 | Medium | 1.4% | 8.8 | An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker t… | |
| CVE-2026-25550 | Medium | 1.4% | 9.8 | Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code exe… | |
| CVE-2026-48281 | Medium | 1.4% | 10.0 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validati… | |
| CVE-2021-26871 | Medium | 1.4% | 7.8 | Windows WalletService Elevation of Privilege Vulnerability | |
| CVE-2024-3154 | Medium | 1.4% | 7.2 | A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod a… | |
| CVE-2026-76071 | Medium | 1.4% | 9.8 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerabili… | |
| CVE-2026-49435 | Medium | 1.4% | 9.8 | Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow.… | |
| CVE-2020-3563 | Medium | 1.4% | 8.6 | A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (… | |
| CVE-2026-19924 | Medium | 1.4% | 9.8 | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vul… | |
| CVE-2026-82693 | Medium | 1.4% | 10.0 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the… | |
| CVE-2026-82694 | Medium | 1.4% | 10.0 | A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the functio… | |
| CVE-2000-0988 | Medium | 1.4% | 7.2 | WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access t… | |
| CVE-2026-64564 | Medium | 1.4% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the … | |
| CVE-2026-20868 | Medium | 1.4% | 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an u… | |
| CVE-2023-21553 | Medium | 1.4% | 7.5 | Azure DevOps Server Remote Code Execution Vulnerability | |
| CVE-2026-82695 | Medium | 1.4% | 10.0 | A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown func… | |
| CVE-2026-56121 | Medium | 1.4% | 9.8 | Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthent… | |
| CVE-2026-76850 | Medium | 1.4% | 9.8 | LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv… | |
| CVE-2025-0624 | Medium | 1.4% | 7.6 | A flaw was found in grub2. During the network boot process, when trying to search for the … | |
| CVE-2000-0994 | Medium | 1.4% | 7.2 | Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operati… | |
| CVE-2026-38999 | Medium | 1.4% | 7.5 | A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c)… | |
| CVE-2000-1241 | Medium | 1.4% | 10.0 | Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) bef… | |
| CVE-2026-12263 | Medium | 1.4% | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions befor… | |
| CVE-2023-36882 | Medium | 1.4% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-24893 | Medium | 1.4% | 8.8 | openITCOCKPIT is an open source monitoring tool built for different monitoring engines. op… | |
| CVE-2026-57499 | Medium | 1.4% | 9.1 | Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command inje… | |
| CVE-2026-80127 | Medium | 1.4% | 7.2 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions … | |
| CVE-2026-84387 | Medium | 1.4% | 7.2 | A improper neutralization of special elements used in a command ('command injection') vuln… | |
| CVE-2026-67260 | Medium | 1.4% | 7.3 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_i… | |
| CVE-2026-88622 | Medium | 1.4% | 8.8 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_priv… | |
| CVE-2025-9086 | Medium | 1.4% | 7.5 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected t… | |
| CVE-2026-78159 | Medium | 1.4% | 9.8 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all… | |
| CVE-2026-20846 | Medium | 1.4% | 7.5 | Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a ne… | |
| CVE-2021-34781 | Medium | 1.4% | 8.6 | A vulnerability in the processing of SSH connections for multi-instance deployments of Cis… | |
| CVE-2021-40116 | Medium | 1.4% | 8.6 | Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an… | |
| CVE-2021-36949 | Medium | 1.4% | 7.1 | Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | |
| CVE-2024-50492 | Medium | 1.4% | 8.3 | Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson … | |
| CVE-2026-15429 | Medium | 1.4% | 8.8 | A privilege escalation vulnerability exists in the HTTP authentication component in Archer… | |
| CVE-2021-1402 | Medium | 1.4% | 8.6 | A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat De… | |
| CVE-2025-4138 | Medium | 1.4% | 7.5 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the … | |
| CVE-2023-38167 | Medium | 1.4% | 7.2 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| CVE-2024-21416 | Medium | 1.4% | 8.1 | Windows TCP/IP Remote Code Execution Vulnerability |