Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-21684 | Medium | 1.3% | 8.8 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | |
| CVE-2024-21327 | Medium | 1.3% | 7.6 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | |
| CVE-2026-42537 | Medium | 1.3% | 9.8 | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommend… | |
| CVE-2026-44680 | Medium | 1.3% | 7.6 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity M… | |
| CVE-2026-47117 | Medium | 1.3% | 9.8 | OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-fil… | |
| CVE-2026-81385 | Medium | 1.3% | 8.8 | Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized att… | |
| CVE-2000-0935 | Medium | 1.3% | 7.2 | Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitr… | |
| CVE-2026-7273 | Medium | 1.3% | 8.8 | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firm… | |
| CVE-2026-14900 | Medium | 1.3% | 9.8 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Executio… | |
| CVE-2026-12645 | Medium | 1.3% | 9.9 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a re… | |
| CVE-2024-38194 | Medium | 1.3% | 8.4 | An authenticated attacker can exploit an improper authorization vulnerability in Azure Web… | |
| CVE-2024-3727 | Medium | 1.3% | 8.3 | A flaw was found in the github.com/containers/image library. This flaw allows attackers to… | |
| CVE-2026-76193 | Medium | 1.3% | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerabi… | |
| CVE-2026-65608 | Medium | 1.3% | 8.8 | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. Fle… | |
| CVE-2026-52889 | Medium | 1.3% | 9.8 | Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-… | |
| CVE-2026-70553 | Medium | 1.3% | 9.8 | MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated att… | |
| CVE-2026-72577 | Medium | 1.3% | 9.8 | Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote … | |
| CVE-2026-35092 | Medium | 1.3% | 7.5 | A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message… | |
| CVE-2026-42027 | Medium | 1.3% | 9.8 | Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Ve… | |
| CVE-2026-50633 | Medium | 1.3% | 8.1 | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module,… | |
| CVE-2026-48273 | Medium | 1.3% | 9.9 | ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluate… | |
| CVE-2026-7537 | Medium | 1.3% | 7.2 | The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in a… | |
| CVE-2026-20803 | Medium | 1.3% | 7.2 | Missing authentication for critical function in SQL Server allows an authorized attacker t… | |
| CVE-2026-49959 | Medium | 1.3% | 8.8 | Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that a… | |
| CVE-2026-89036 | Medium | 1.3% | 8.8 | Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticat… | |
| CVE-2026-47783 | Medium | 1.3% | 8.1 | In memcached before 1.6.42, username data for SASL password database authentication has a … | |
| CVE-2026-9317 | Medium | 1.3% | 8.1 | Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC ser… | |
| CVE-2024-24786 | Medium | 1.3% | 7.5 | The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain form… | |
| CVE-2026-72776 | Medium | 1.3% | 9.8 | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerabili… | |
| CVE-2024-43474 | Medium | 1.3% | 7.6 | Microsoft SQL Server Information Disclosure Vulnerability | |
| CVE-2026-48276 | Medium | 1.3% | 10.0 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of … | |
| CVE-2026-48283 | Medium | 1.3% | 10.0 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of … | |
| CVE-2026-48440 | Medium | 1.3% | 8.1 | ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in … | |
| CVE-2026-76832 | Medium | 1.3% | 8.8 | Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerabili… | |
| CVE-2026-14282 | Medium | 1.3% | 9.8 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Ima… | |
| CVE-2026-50330 | Medium | 1.3% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to ele… | |
| CVE-2026-41605 | Medium | 1.3% | 7.3 | Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache … | |
| CVE-2026-67323 | Medium | 1.3% | 8.4 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arg… | |
| CVE-2019-1669 | Medium | 1.2% | 8.6 | A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense … | |
| CVE-2022-20757 | Medium | 1.2% | 8.6 | A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD… | |
| CVE-2025-50455 | Medium | 1.2% | 9.1 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endp… | |
| CVE-2026-73369 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Co… | |
| CVE-2026-75699 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Co… | |
| CVE-2026-75703 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Co… | |
| CVE-2026-75721 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Co… | |
| CVE-2026-84412 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Co… | |
| CVE-2026-89275 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Co… | |
| CVE-2026-42835 | Medium | 1.2% | 8.1 | Improper neutralization of special elements in output used by a downstream component ('inj… | |
| CVE-2026-86708 | Medium | 1.2% | 10.0 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to ex… | |
| CVE-2026-18264 | Medium | 1.2% | 8.8 | NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerabilit… |