Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-66909 | Medium | 1.1% | 9.8 | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using na… | |
| CVE-2026-68771 | Medium | 1.1% | 9.8 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDatase… | |
| CVE-2021-26866 | Medium | 1.1% | 7.1 | Windows Update Service Elevation of Privilege Vulnerability | |
| CVE-2020-5403 | Medium | 1.1% | 7.5 | Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException tha… | |
| CVE-2026-5485 | Medium | 1.1% | 7.8 | OS command injection in the browser-based authentication component in Amazon Athena ODBC d… | |
| CVE-2021-36963 | Medium | 1.1% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2026-34619 | Medium | 1.1% | 7.7 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of … | |
| CVE-2026-89040 | Medium | 1.1% | 9.8 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to… | |
| CVE-2026-90823 | Medium | 1.1% | 9.8 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r… | |
| CVE-2026-8778 | Medium | 1.1% | 9.8 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. p… | |
| CVE-2026-87796 | Medium | 1.1% | 9.8 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File … | |
| CVE-2024-21395 | Medium | 1.1% | 8.2 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2026-41450 | Medium | 1.1% | 7.8 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vu… | |
| CVE-2020-1070 | Medium | 1.1% | 7.8 | An elevation of privilege vulnerability exists when the Windows Print Spooler service impr… | |
| CVE-2021-26873 | Medium | 1.1% | 7.0 | Windows User Profile Service Elevation of Privilege Vulnerability | |
| CVE-2026-4809 | Medium | 1.1% | 9.8 | plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type whe… | |
| CVE-2026-8631 | Medium | 1.1% | 9.8 | A potential security vulnerability has been identified in the HP Linux Imaging and Printin… | |
| CVE-2026-16606 | Medium | 1.1% | 9.8 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openF… | |
| CVE-2026-3828 | Medium | 1.1% | 7.2 | Some Hikvision switch products (discontinued since December 2023) are vulnerable to authen… | |
| CVE-2026-47297 | Medium | 1.1% | 8.1 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute… | |
| CVE-2026-52098 | Medium | 1.1% | 9.8 | An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/… | |
| CVE-2026-53421 | Medium | 1.1% | 9.8 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administ… | |
| CVE-2026-27446 | Medium | 1.1% | 9.8 | Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Ap… | |
| CVE-2026-66748 | Medium | 1.1% | 8.8 | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution … | |
| CVE-2026-74997 | Medium | 1.1% | 8.8 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the mar… | |
| CVE-2022-41057 | Medium | 1.1% | 7.8 | Windows HTTP.sys Elevation of Privilege Vulnerability | |
| CVE-2026-20856 | Medium | 1.1% | 8.1 | Improper input validation in Windows Server Update Service allows an unauthorized attacker… | |
| CVE-2026-33278 | Medium | 1.1% | 9.8 | NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DN… | |
| CVE-2026-86165 | Medium | 1.1% | 9.8 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function… | |
| CVE-2024-21537 | Medium | 1.1% | 8.8 | Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary … | |
| CVE-2026-52610 | Medium | 1.1% | 9.1 | An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows… | |
| CVE-2020-3973 | Medium | 1.1% | 8.8 | The VeloCloud Orchestrator does not apply correct input validation which allows for blind … | |
| CVE-2025-2609 | Medium | 1.1% | 8.2 | Improper neutralization of input during web page generation vulnerability in MagnusSolutio… | |
| CVE-2026-42009 | Medium | 1.1% | 7.5 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Trans… | |
| CVE-2026-48413 | Medium | 1.1% | 8.7 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could… | |
| CVE-2026-79641 | Medium | 1.1% | 7.5 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions … | |
| CVE-2026-19091 | Medium | 1.1% | 8.1 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin f… | |
| CVE-2026-43003 | Medium | 1.1% | 8.0 | An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Pyth… | |
| CVE-2026-73679 | Medium | 1.1% | 7.2 | ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag… | |
| CVE-2026-76979 | Medium | 1.1% | 7.7 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vul… | |
| CVE-2026-48316 | Medium | 1.1% | 10.0 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validati… | |
| CVE-2023-50781 | Medium | 1.1% | 7.5 | A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured m… | |
| CVE-2026-86297 | Medium | 1.1% | 8.1 | A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the funct… | |
| CVE-2020-15874 | Medium | 1.1% | 8.8 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal priv… | |
| CVE-2026-33846 | Medium | 1.1% | 7.5 | A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logi… | |
| CVE-2026-48163 | Medium | 1.1% | 8.0 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to befo… | |
| CVE-2024-43467 | Medium | 1.1% | 7.5 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | |
| CVE-2026-72710 | Medium | 1.1% | 9.8 | SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action tha… | |
| CVE-2026-75411 | Medium | 1.1% | 9.8 | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the … | |
| CVE-2022-41039 | Medium | 1.1% | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |