Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-20094 | Medium | 1.1% | 8.8 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenti… | |
| CVE-2024-21394 | Medium | 1.1% | 7.6 | Dynamics 365 Field Service Spoofing Vulnerability | |
| CVE-2026-16445 | Medium | 1.1% | 7.5 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vul… | |
| CVE-2026-50632 | Medium | 1.1% | 8.1 | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configurati… | |
| CVE-2026-63767 | Medium | 1.1% | 9.8 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle d… | |
| CVE-2026-86121 | Medium | 1.1% | 9.8 | Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME env… | |
| CVE-2023-34062 | Medium | 1.1% | 7.5 | In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1… | |
| CVE-2026-66050 | Medium | 1.1% | 7.5 | NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file t… | |
| CVE-2006-3096 | Medium | 1.1% | 7.5 | Multiple SQL injection vulnerabilities in iPostMX 2005 2.0 and earlier allow remote attack… | |
| CVE-2023-21705 | Medium | 1.1% | 8.8 | Microsoft SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-8134 | Medium | 1.1% | 7.2 | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerF… | |
| CVE-2025-23172 | Medium | 1.1% | 7.2 | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending no… | |
| CVE-2026-52680 | Medium | 1.1% | 9.8 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart file… | |
| CVE-2026-33701 | Medium | 1.1% | 9.8 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrum… | |
| CVE-2026-41252 | Medium | 1.1% | 9.8 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds chec… | |
| CVE-2026-80104 | Medium | 1.1% | 9.8 | DB-GPT builds the destination path for an uploaded skill from the multipart filename witho… | |
| CVE-2026-56186 | Medium | 1.1% | 8.1 | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose informati… | |
| CVE-2026-67367 | Medium | 1.1% | 8.6 | A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), … | |
| CVE-2026-92969 | Medium | 1.1% | 8.1 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerabl… | |
| CVE-2026-85684 | Medium | 1.1% | 9.1 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload… | |
| CVE-2026-3083 | Medium | 1.1% | 8.8 | GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulne… | |
| CVE-2026-50223 | Medium | 1.1% | 8.8 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz al… | |
| CVE-2026-86438 | Medium | 1.1% | 7.2 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule … | |
| CVE-2026-20854 | Medium | 1.1% | 7.5 | Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an aut… | |
| CVE-2026-20922 | Medium | 1.1% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code l… | |
| CVE-2026-39276 | Medium | 1.1% | 7.2 | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowi… | |
| CVE-2026-69111 | Medium | 1.1% | 7.5 | Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerabilit… | |
| CVE-2026-73601 | Medium | 1.1% | 8.8 | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom … | |
| CVE-2026-16099 | Medium | 1.1% | 8.8 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletio… | |
| CVE-2026-48318 | Medium | 1.1% | 9.9 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory (… | |
| CVE-2026-71513 | Medium | 1.1% | 8.8 | NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler th… | |
| CVE-2026-72579 | Medium | 1.1% | 7.5 | An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjac… | |
| CVE-2026-18588 | Medium | 1.1% | 9.8 | A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the func… | |
| CVE-2026-18589 | Medium | 1.1% | 9.8 | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function … | |
| CVE-2026-5680 | Medium | 1.1% | 7.5 | A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sendin… | |
| CVE-2026-75784 | Medium | 1.1% | 10.0 | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is t… | |
| CVE-2026-79911 | Medium | 1.1% | 10.0 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The a… | |
| CVE-2026-82542 | Medium | 1.1% | 10.0 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the func… | |
| CVE-2026-85109 | Medium | 1.1% | 9.8 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function fo… | |
| CVE-2026-93740 | Medium | 1.1% | 10.0 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the func… | |
| CVE-2026-93741 | Medium | 1.1% | 10.0 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by thi… | |
| CVE-2023-21717 | Medium | 1.1% | 8.8 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| CVE-2025-37778 | Medium | 1.1% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix dangling p… | |
| CVE-2026-15307 | Medium | 1.1% | 8.8 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatia… | |
| CVE-2026-15358 | Medium | 1.1% | 7.5 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671… | |
| CVE-2026-1771 | Medium | 1.1% | 7.2 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil… | |
| CVE-2026-35091 | Medium | 1.1% | 8.2 | A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return… | |
| CVE-2026-77110 | Medium | 1.1% | 7.6 | Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directo… | |
| CVE-2026-41939 | Medium | 1.1% | 9.8 | Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bun… | |
| CVE-2025-43433 | Medium | 1.1% | 8.8 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1,… |