Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-56292 | Medium | 1.4% | 7.5 | Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQ… | |
| CVE-2025-41269 | Medium | 1.4% | 9.8 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41270 | Medium | 1.4% | 9.8 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41272 | Medium | 1.4% | 9.8 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41274 | Medium | 1.4% | 9.8 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41275 | Medium | 1.4% | 9.8 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41276 | Medium | 1.4% | 9.8 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41277 | Medium | 1.4% | 9.8 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2026-41602 | Medium | 1.4% | 7.5 | Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language… | |
| CVE-2026-59862 | Medium | 1.4% | 7.5 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's … | |
| CVE-2026-47717 | Medium | 1.4% | 7.5 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server v… | |
| CVE-2020-3571 | Medium | 1.4% | 8.6 | A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (F… | |
| CVE-2024-21347 | Medium | 1.4% | 7.5 | Microsoft ODBC Driver Remote Code Execution Vulnerability | |
| CVE-2026-17581 | Medium | 1.4% | 7.2 | The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable … | |
| CVE-2026-48323 | Medium | 1.4% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2025-6021 | Medium | 1.4% | 7.5 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer si… | |
| CVE-2026-10273 | Medium | 1.4% | 7.3 | A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of t… | |
| CVE-2024-37980 | Medium | 1.4% | 8.8 | Microsoft SQL Server Elevation of Privilege Vulnerability | |
| CVE-2024-38225 | Medium | 1.4% | 8.8 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| CVE-2026-67918 | Medium | 1.4% | 7.5 | Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to ob… | |
| CVE-2024-20667 | Medium | 1.4% | 7.5 | Azure DevOps Server Remote Code Execution Vulnerability | |
| CVE-2024-3884 | Medium | 1.4% | 7.5 | A flaw was found in Undertow that can cause remote denial of service attacks. When the ser… | |
| CVE-2026-22221 | Medium | 1.4% | 8.0 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600… | |
| CVE-2026-66786 | Medium | 1.4% | 9.1 | A flaw was found in submariner. In cert-auth mode, the connection configuration is built u… | |
| CVE-2026-48319 | Medium | 1.4% | 9.1 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory (… | |
| CVE-2025-71389 | Medium | 1.4% | 10.0 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code executi… | |
| CVE-2026-11526 | Medium | 1.4% | 9.8 | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg… | |
| CVE-2021-38639 | Medium | 1.4% | 7.8 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2025-12543 | Medium | 1.4% | 9.6 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, an… | |
| CVE-2026-18855 | Medium | 1.4% | 9.1 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insu… | |
| CVE-2026-6555 | Medium | 1.4% | 9.8 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in v… | |
| CVE-2021-40118 | Medium | 1.4% | 8.6 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) S… | |
| CVE-2026-7210 | Medium | 1.4% | 7.5 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-fl… | |
| CVE-2021-41164 | Medium | 1.3% | 8.2 | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has … | |
| CVE-2022-20715 | Medium | 1.3% | 8.6 | A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance… | |
| CVE-2022-20746 | Medium | 1.3% | 8.6 | A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Sof… | |
| CVE-2022-20751 | Medium | 1.3% | 8.6 | A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defen… | |
| CVE-2026-21571 | Medium | 1.3% | 8.8 | This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0… | |
| CVE-2026-3535 | Medium | 1.3% | 9.8 | The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file uploa… | |
| CVE-2021-1501 | Medium | 1.3% | 8.6 | A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) So… | |
| CVE-2022-29458 | Medium | 1.3% | 7.1 | ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in … | |
| CVE-2026-94493 | Medium | 1.3% | 10.0 | A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects … | |
| CVE-2026-0273 | Medium | 1.3% | 7.2 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authen… | |
| CVE-2026-65089 | Medium | 1.3% | 7.8 | NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands,… | |
| CVE-2026-65090 | Medium | 1.3% | 7.8 | NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where … | |
| CVE-2026-65096 | Medium | 1.3% | 7.8 | NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where… | |
| CVE-2026-65099 | Medium | 1.3% | 7.8 | NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an… | |
| CVE-2024-21403 | Medium | 1.3% | 9.0 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerabi… | |
| CVE-2026-23455 | Medium | 1.3% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntra… | |
| CVE-2026-76070 | Medium | 1.3% | 9.8 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerabili… |