Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-44416 | Medium | 1.2% | 9.8 | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry componen… | |
| CVE-2026-73519 | Medium | 1.2% | 9.8 | WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into … | |
| CVE-2026-7857 | Medium | 1.2% | 7.2 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects th… | |
| CVE-2026-15006 | Medium | 1.2% | 7.5 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automatio… | |
| CVE-2023-6563 | Medium | 1.2% | 7.7 | An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be tr… | |
| CVE-2026-81995 | Medium | 1.2% | 9.1 | Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerabili… | |
| CVE-2025-7424 | Medium | 1.2% | 7.5 | A flaw was found in the libxslt library. The same memory field, psvi, is used for both sty… | |
| CVE-2024-5154 | Medium | 1.2% | 8.1 | A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary f… | |
| CVE-2026-12646 | Medium | 1.2% | 9.9 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a re… | |
| CVE-2026-12647 | Medium | 1.2% | 9.9 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a re… | |
| CVE-2021-33768 | Medium | 1.2% | 8.0 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2026-75430 | Medium | 1.2% | 9.8 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployCont… | |
| CVE-2020-3303 | Medium | 1.2% | 7.5 | A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive S… | |
| CVE-2020-3305 | Medium | 1.2% | 7.5 | A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco… | |
| CVE-2020-3306 | Medium | 1.2% | 7.5 | A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and… | |
| CVE-2026-70554 | Medium | 1.2% | 9.8 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated atta… | |
| CVE-2026-50524 | Medium | 1.2% | 7.5 | Improper validation of specified type of input in .NET Framework allows an unauthorized at… | |
| CVE-2026-62901 | Medium | 1.2% | 7.5 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service… | |
| CVE-2024-21399 | Medium | 1.2% | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| CVE-2026-81476 | Medium | 1.2% | 8.1 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neu… | |
| CVE-2026-7654 | Medium | 1.2% | 8.8 | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Re… | |
| CVE-2026-7856 | Medium | 1.2% | 7.2 | A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the fi… | |
| CVE-2026-76834 | Medium | 1.2% | 8.1 | b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 w… | |
| CVE-2026-54513 | Medium | 1.2% | 8.1 | jackson-databind contains the general-purpose data-binding functionality and tree-model fo… | |
| CVE-2026-61539 | Medium | 1.2% | 10.0 | Xinference is an inference API for running open-source, speech, and multimodal models. In … | |
| CVE-2026-40858 | Medium | 1.2% | 8.8 | The camel-infinispan component's ProtoStream-based remote aggregation repository deseriali… | |
| CVE-2026-22739 | Medium | 1.2% | 8.6 | Vulnerability in Spring Cloud when substituting the profile parameter from a request made … | |
| CVE-2026-15979 | Medium | 1.2% | 8.1 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vu… | |
| CVE-2026-94184 | Medium | 1.2% | 8.1 | A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A … | |
| CVE-2026-71471 | Medium | 1.2% | 9.0 | A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the… | |
| CVE-2026-55799 | Medium | 1.2% | 9.8 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 … | |
| CVE-2026-82008 | Medium | 1.2% | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability tha… | |
| CVE-2020-3478 | Medium | 1.2% | 8.1 | A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) co… | |
| CVE-2026-34070 | Medium | 1.2% | 7.5 | LangChain is a framework for building agents and LLM-powered applications. Prior to versio… | |
| CVE-2026-3183 | Medium | 1.2% | 7.1 | Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Fact… | |
| CVE-2026-4224 | Medium | 1.2% | 7.5 | When an Expat parser with a registered ElementDeclHandler parses an inline document type d… | |
| CVE-2026-9614 | Medium | 1.2% | 8.8 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises… | |
| CVE-2026-34356 | Medium | 1.2% | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend serv… | |
| CVE-2000-0957 | Medium | 1.2% | 7.5 | The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly c… | |
| CVE-2026-3085 | Medium | 1.2% | 8.8 | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. Thi… | |
| CVE-2026-47294 | Medium | 1.2% | 8.0 | Improper neutralization of special elements used in an os command ('os command injection')… | |
| CVE-2026-82460 | Medium | 1.2% | 9.8 | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-o… | |
| CVE-2022-41061 | Medium | 1.2% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2023-21685 | Medium | 1.2% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-48358 | Medium | 1.2% | 9.1 | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability tha… | |
| CVE-2026-40478 | Medium | 1.2% | 9.0 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versi… | |
| CVE-2026-82533 | Medium | 1.2% | 9.6 | DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that… | |
| CVE-2017-11508 | Medium | 1.2% | 8.8 | SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that … | |
| CVE-2026-14484 | Medium | 1.2% | 9.1 | The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnera… | |
| CVE-2026-14544 | Medium | 1.2% | 9.8 | A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an… |