Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-21695 | Medium | 1.0% | 7.5 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulner… | |
| CVE-2026-27305 | Medium | 1.0% | 8.6 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of … | |
| CVE-2026-48310 | Medium | 1.0% | 8.6 | Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restrict… | |
| CVE-2026-54718 | Medium | 1.0% | 7.2 | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior … | |
| CVE-2026-7262 | Medium | 1.0% | 7.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* b… | |
| CVE-2026-18351 | Medium | 1.0% | 9.8 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Ar… | |
| CVE-2026-42587 | Medium | 1.0% | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Fina… | |
| CVE-2024-5974 | Medium | 1.0% | 7.2 | A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attack… | |
| CVE-2026-26147 | Medium | 1.0% | 7.7 | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclo… | |
| CVE-2026-11572 | Medium | 1.0% | 8.8 | Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to … | |
| CVE-2026-73240 | Medium | 1.0% | 9.8 | Specifically crafted inputs may lead to git argument injection in Apache Allura. This iss… | |
| CVE-2026-76943 | Medium | 1.0% | 9.8 | Xiiaozet LK100Wt contains an authentication weakness within an administrative service tha… | |
| CVE-2026-44495 | Medium | 1.0% | 7.0 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.… | |
| CVE-2026-8505 | Medium | 1.0% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentica… | |
| CVE-2026-59090 | Medium | 1.0% | 8.4 | A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer… | |
| CVE-2026-31020 | Medium | 1.0% | 9.8 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows … | |
| CVE-2026-55976 | Medium | 1.0% | 9.1 | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4… | |
| CVE-2026-74843 | Medium | 1.0% | 10.0 | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vu… | |
| CVE-2026-75031 | Medium | 1.0% | 9.8 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerabili… | |
| CVE-2026-75728 | Medium | 1.0% | 9.1 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2023-36895 | Medium | 1.0% | 7.8 | Microsoft Outlook Remote Code Execution Vulnerability | |
| CVE-2026-3945 | Medium | 1.0% | 7.5 | An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyprox… | |
| CVE-2026-48330 | Medium | 1.0% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2026-78461 | Medium | 1.0% | 7.4 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual S… | |
| CVE-2024-42467 | Medium | 1.0% | 10.0 | openHAB, a provider of open-source home automation software, has add-ons including the vis… | |
| CVE-2026-12872 | Medium | 1.0% | 9.8 | The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded f… | |
| CVE-2026-57124 | Medium | 1.0% | 9.8 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications… | |
| CVE-2026-91105 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2024-21536 | Medium | 1.0% | 7.5 | Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 ar… | |
| CVE-2026-19446 | Medium | 1.0% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can… | |
| CVE-2026-41449 | Medium | 1.0% | 7.8 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vu… | |
| CVE-2026-8461 | Medium | 1.0% | 8.8 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the M… | |
| CVE-2026-28703 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-28754 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-28756 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-34660 | Medium | 1.0% | 9.3 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Auth… | |
| CVE-2026-3879 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-3880 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-4108 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-41608 | Medium | 1.0% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache T… | |
| CVE-2026-43871 | Medium | 1.0% | 7.5 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Pyth… | |
| CVE-2026-45112 | Medium | 1.0% | 7.5 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java b… | |
| CVE-2026-45815 | Medium | 1.0% | 7.5 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple … | |
| CVE-2026-45816 | Medium | 1.0% | 7.5 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.… | |
| CVE-2026-48586 | Medium | 1.0% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache T… | |
| CVE-2026-49158 | Medium | 1.0% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache T… | |
| CVE-2026-55968 | Medium | 1.0% | 7.5 | Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling v… | |
| CVE-2026-55969 | Medium | 1.0% | 7.5 | Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Del… | |
| CVE-2026-58389 | Medium | 1.0% | 7.5 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust b… | |
| CVE-2026-61483 | Medium | 1.0% | 7.5 | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. Th… |