Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-41451 | Medium | 1.2% | 7.8 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vu… | |
| CVE-2026-56703 | Medium | 1.2% | 7.2 | Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handli… | |
| CVE-2026-5211 | Medium | 1.2% | 8.8 | A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW,… | |
| CVE-2026-5213 | Medium | 1.2% | 8.8 | A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, D… | |
| CVE-2026-63639 | Medium | 1.2% | 8.8 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1… | |
| CVE-2022-1011 | Medium | 1.2% | 7.8 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user tr… | |
| CVE-2026-8992 | Medium | 1.2% | 8.8 | An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.… | |
| CVE-2026-91771 | Medium | 1.2% | 8.8 | Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses… | |
| CVE-2026-27302 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2026-48286 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Inco… | |
| CVE-2026-48303 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Inco… | |
| CVE-2026-48449 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2026-71398 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2026-75723 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2026-75745 | Medium | 1.2% | 10.0 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability… | |
| CVE-2026-85437 | Medium | 1.2% | 9.8 | MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function … | |
| CVE-2021-26431 | Medium | 1.2% | 7.8 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | |
| CVE-2026-31843 | Medium | 1.2% | 9.8 | The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the … | |
| CVE-2026-47391 | Medium | 1.2% | 9.8 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party … | |
| CVE-2026-67587 | Medium | 1.2% | 8.8 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running i… | |
| CVE-2026-5212 | Medium | 1.2% | 8.8 | A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, D… | |
| CVE-2024-38263 | Medium | 1.2% | 7.5 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | |
| CVE-2022-41118 | Medium | 1.2% | 7.5 | Windows Scripting Languages Remote Code Execution Vulnerability | |
| CVE-2026-63073 | Medium | 1.2% | 9.8 | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distin… | |
| CVE-2026-84675 | Medium | 1.2% | 7.4 | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows atta… | |
| CVE-2021-26862 | Medium | 1.2% | 7.0 | Windows Installer Elevation of Privilege Vulnerability | |
| CVE-2024-21389 | Medium | 1.2% | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2024-21393 | Medium | 1.2% | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2024-21396 | Medium | 1.2% | 7.6 | Dynamics 365 Sales Spoofing Vulnerability | |
| CVE-2024-6592 | Medium | 1.2% | 9.1 | An incorrect authorization vulnerability in the protocol communication between the WatchGu… | |
| CVE-2026-8260 | Medium | 1.2% | 8.8 | A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the fu… | |
| CVE-2026-1460 | Medium | 1.2% | 7.2 | A post-authentication command injection vulnerability in the “DomainName” parameter of the… | |
| CVE-2026-54569 | Medium | 1.2% | 9.8 | SENAITE.CORE is the core framework for the SENAITE laboratory information management syste… | |
| CVE-2026-44724 | Medium | 1.2% | 7.8 | systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.… | |
| CVE-2019-12627 | Medium | 1.2% | 7.5 | A vulnerability in the application policy configuration of the Cisco Firepower Threat Defe… | |
| CVE-2022-41120 | Medium | 1.2% | 7.8 | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | |
| CVE-2026-16585 | Medium | 1.2% | 7.2 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for W… | |
| CVE-2026-42578 | Medium | 1.2% | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Fina… | |
| CVE-2026-51934 | Medium | 1.2% | 9.8 | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.… | |
| CVE-2026-17524 | Medium | 1.2% | 7.5 | Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the… | |
| CVE-2026-48746 | Medium | 1.2% | 9.1 | vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until… | |
| CVE-2023-21686 | Medium | 1.2% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-1526 | Medium | 1.2% | 7.5 | The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memo… | |
| CVE-2026-35002 | Medium | 1.2% | 9.8 | Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the mod… | |
| CVE-2026-45117 | Medium | 1.1% | 9.8 | MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer modul… | |
| CVE-2026-51785 | Medium | 1.1% | 9.8 | An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute ar… | |
| CVE-2026-72571 | Medium | 1.1% | 7.5 | A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an una… | |
| CVE-2026-72572 | Medium | 1.1% | 7.5 | A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated re… | |
| CVE-2023-21808 | Medium | 1.1% | 7.8 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2026-15244 | Medium | 1.1% | 7.2 | The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against … |