Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-16236 | Medium | 1.2% | 8.8 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in ve… | |
| CVE-2026-33871 | Medium | 1.2% | 7.5 | Netty is an asynchronous, event-driven network application framework. In versions prior to… | |
| CVE-2026-57099 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorize… | |
| CVE-2026-69329 | Medium | 1.2% | 7.5 | Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a n… | |
| CVE-2026-69378 | Medium | 1.2% | 7.5 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to den… | |
| CVE-2026-69809 | Medium | 1.2% | 7.5 | Missing release of memory after effective lifetime in Active Directory Domain Services all… | |
| CVE-2026-72923 | Medium | 1.2% | 7.5 | In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.… | |
| CVE-2026-84837 | Medium | 1.2% | 7.8 | A flaw was found in rpm. An attacker can exploit a command injection vulnerability by infl… | |
| CVE-2026-92937 | Medium | 1.2% | 10.0 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host … | |
| CVE-2021-1493 | Medium | 1.2% | 8.5 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) S… | |
| CVE-2026-16098 | Medium | 1.2% | 9.8 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in a… | |
| CVE-2026-80138 | Medium | 1.2% | 9.8 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath pa… | |
| CVE-2026-12701 | Medium | 1.2% | 9.0 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function… | |
| CVE-2026-20921 | Medium | 1.2% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition'… | |
| CVE-2026-67195 | Medium | 1.2% | 8.8 | Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticat… | |
| CVE-2026-16144 | Medium | 1.2% | 8.1 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable t… | |
| CVE-2026-65660 | Medium | 1.2% | 8.8 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint a… | |
| CVE-2026-61523 | Medium | 1.2% | 7.2 | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets ed… | |
| CVE-2026-72748 | Medium | 1.2% | 9.1 | AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoder… | |
| CVE-2026-86792 | Medium | 1.2% | 8.8 | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path stri… | |
| CVE-2021-1422 | Medium | 1.2% | 7.7 | A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (… | |
| CVE-2023-21797 | Medium | 1.2% | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | |
| CVE-2023-21798 | Medium | 1.2% | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | |
| CVE-2023-21799 | Medium | 1.2% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2024-20673 | Medium | 1.2% | 7.8 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2026-40030 | Medium | 1.2% | 7.8 | parseusbs before 1.9 contains an OS command injection vulnerability where the volume listi… | |
| CVE-2026-58400 | Medium | 1.2% | 9.1 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to ver… | |
| CVE-2026-7855 | Medium | 1.2% | 8.8 | A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the f… | |
| CVE-2026-40032 | Medium | 1.2% | 7.8 | UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerab… | |
| CVE-2026-42785 | Medium | 1.2% | 7.2 | OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated adm… | |
| CVE-2026-14903 | Medium | 1.2% | 7.7 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated … | |
| CVE-2026-23816 | Medium | 1.2% | 7.2 | A vulnerability in the command line interface of AOS-CX Switches could allow an authentica… | |
| CVE-2026-52720 | Medium | 1.2% | 8.8 | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The… | |
| CVE-2026-6857 | Medium | 1.2% | 7.5 | A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization i… | |
| CVE-2000-0949 | Medium | 1.2% | 7.2 | Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user… | |
| CVE-2021-47308 | Medium | 1.2% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix arra… | |
| CVE-2026-12476 | Medium | 1.2% | 7.2 | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in … | |
| CVE-2022-4995 | Medium | 1.2% | 9.8 | Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability t… | |
| CVE-2026-41604 | Medium | 1.2% | 8.2 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: befo… | |
| CVE-2026-75744 | Medium | 1.2% | 8.1 | Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vuln… | |
| CVE-2026-3104 | Medium | 1.2% | 7.5 | A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by… | |
| CVE-2026-33096 | Medium | 1.2% | 7.5 | Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service ove… | |
| CVE-2026-40378 | Medium | 1.2% | 7.5 | Memory allocation with excessive size value in Windows Local Security Authority Subsystem … | |
| CVE-2026-47302 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthorized attack… | |
| CVE-2026-49160 | Medium | 1.2% | 7.5 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny servic… | |
| CVE-2026-49787 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in Windows HTTP.sys allows an unautho… | |
| CVE-2026-49788 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized atta… | |
| CVE-2026-50304 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized… | |
| CVE-2026-50355 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized… | |
| CVE-2026-50368 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized… |