Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-10214 | Medium | 1.3% | 7.3 | A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affec… | |
| CVE-2026-10219 | Medium | 1.3% | 7.3 | A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the functi… | |
| CVE-2026-19977 | Medium | 1.3% | 10.0 | A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the fun… | |
| CVE-2026-78168 | Medium | 1.3% | 9.8 | A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affec… | |
| CVE-2026-47101 | Medium | 1.3% | 8.8 | LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with acc… | |
| CVE-2025-12548 | Medium | 1.3% | 9.0 | A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticate… | |
| CVE-2026-0596 | Medium | 1.3% | 7.8 | A command injection vulnerability exists in mlflow/mlflow when serving a model with `enabl… | |
| CVE-2026-26731 | Medium | 1.3% | 8.8 | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer over… | |
| CVE-2026-40029 | Medium | 1.3% | 7.8 | parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where … | |
| CVE-2024-8176 | Medium | 1.3% | 7.5 | A stack overflow vulnerability exists in the libexpat library due to the way it handles re… | |
| CVE-2026-45140 | Medium | 1.3% | 9.8 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allo… | |
| CVE-2025-38191 | Medium | 1.3% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null point… | |
| CVE-2026-22223 | Medium | 1.3% | 8.0 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modu… | |
| CVE-2021-38651 | Medium | 1.3% | 7.6 | Microsoft SharePoint Server Spoofing Vulnerability | |
| CVE-2021-38652 | Medium | 1.3% | 7.6 | Microsoft SharePoint Server Spoofing Vulnerability | |
| CVE-2026-1584 | Medium | 1.3% | 7.5 | A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerabil… | |
| CVE-2026-37003 | Medium | 1.3% | 9.8 | Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt inj… | |
| CVE-2023-38169 | Medium | 1.3% | 8.8 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | |
| CVE-2026-90770 | Medium | 1.3% | 8.8 | Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check functi… | |
| CVE-2026-44402 | Medium | 1.3% | 9.8 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnera… | |
| CVE-2024-21328 | Medium | 1.3% | 7.6 | Dynamics 365 Sales Spoofing Vulnerability | |
| CVE-2026-4003 | Medium | 1.3% | 9.8 | The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbi… | |
| CVE-2021-36975 | Medium | 1.3% | 7.8 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2026-18438 | Medium | 1.3% | 8.8 | The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates … | |
| CVE-2026-34180 | Medium | 1.3% | 7.5 | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whos… | |
| CVE-2026-54874 | Medium | 1.3% | 7.5 | Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress… | |
| CVE-2026-85430 | Medium | 1.3% | 9.1 | MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pSha… | |
| CVE-2026-45629 | Medium | 1.3% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, auth… | |
| CVE-2021-1573 | Medium | 1.3% | 8.6 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) S… | |
| CVE-2021-34704 | Medium | 1.3% | 8.6 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) S… | |
| CVE-2026-41316 | Medium | 1.3% | 8.1 | ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygem… | |
| CVE-2026-59111 | Medium | 1.3% | 9.3 | Improper neutralization of special elements used in an OS command ('OS command injection')… | |
| CVE-2024-36886 | Medium | 1.3% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in erro… | |
| CVE-2026-2332 | Medium | 1.3% | 7.4 | In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extens… | |
| CVE-2023-38186 | Medium | 1.3% | 8.8 | Windows Mobile Device Management Elevation of Privilege Vulnerability | |
| CVE-2026-22244 | Medium | 1.3% | 7.2 | OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable … | |
| CVE-2026-4327 | Medium | 1.3% | 8.8 | The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all vers… | |
| CVE-2017-20241 | Medium | 1.3% | 9.8 | Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unaut… | |
| CVE-2017-20242 | Medium | 1.3% | 9.8 | Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unau… | |
| CVE-2026-18274 | Medium | 1.3% | 7.2 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerabi… | |
| CVE-2026-42302 | Medium | 1.3% | 9.8 | FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, … | |
| CVE-2026-48277 | Medium | 1.3% | 10.0 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validati… | |
| CVE-2026-6722 | Medium | 1.3% | 9.8 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* b… | |
| CVE-2021-34516 | Medium | 1.3% | 7.8 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2026-77535 | Medium | 1.3% | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper… | |
| CVE-2026-77539 | Medium | 1.3% | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper… | |
| CVE-2026-77540 | Medium | 1.3% | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper… | |
| CVE-2026-77542 | Medium | 1.3% | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper… | |
| CVE-2026-94127 | Medium | 1.3% | 9.8 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, s… | |
| CVE-2026-44249 | Medium | 1.3% | 8.1 | Netty is a network application framework for development of protocol servers and clients. … |