Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-85440 | Medium | 1.0% | 9.8 | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in… | |
| CVE-2024-38220 | Medium | 1.0% | 9.0 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| CVE-2026-26740 | Medium | 1.0% | 8.2 | Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial… | |
| CVE-2026-65974 | Medium | 1.0% | 9.9 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and… | |
| CVE-2026-76841 | Medium | 1.0% | 8.8 | Xinference loads models with Hugging Face remote code execution unconditionally enabled, a… | |
| CVE-2026-42605 | Medium | 1.0% | 8.8 | AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6… | |
| CVE-2026-48315 | Medium | 1.0% | 9.3 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validati… | |
| CVE-2026-48334 | Medium | 1.0% | 9.3 | Illustrator is affected by an Improper Input Validation vulnerability that could result in… | |
| CVE-2026-77086 | Medium | 1.0% | 9.1 | SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uni… | |
| CVE-2024-7409 | Medium | 1.0% | 7.5 | A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (Do… | |
| CVE-2026-14498 | Medium | 1.0% | 8.8 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all vers… | |
| CVE-2026-32981 | Medium | 1.0% | 7.5 | A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray … | |
| CVE-2026-42908 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information … | |
| CVE-2026-45639 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information … | |
| CVE-2026-50463 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose informati… | |
| CVE-2026-50470 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker t… | |
| CVE-2026-62898 | Medium | 1.0% | 7.5 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information o… | |
| CVE-2026-69443 | Medium | 1.0% | 7.5 | Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Se… | |
| CVE-2026-69519 | Medium | 1.0% | 8.6 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disc… | |
| CVE-2026-70587 | Medium | 1.0% | 7.5 | Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attack… | |
| CVE-2026-71330 | Medium | 1.0% | 7.5 | Exposure of sensitive system information to an unauthorized control sphere in Windows Serv… | |
| CVE-2026-72932 | Medium | 1.0% | 7.5 | Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker … | |
| CVE-2026-72989 | Medium | 1.0% | 7.5 | Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker … | |
| CVE-2025-67447 | Medium | 1.0% | 9.8 | The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is… | |
| CVE-2026-20849 | Medium | 1.0% | 7.5 | Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authoriz… | |
| CVE-2026-28323 | Medium | 1.0% | 9.8 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerabi… | |
| CVE-2026-28356 | Medium | 1.0% | 7.5 | multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0… | |
| CVE-2026-94367 | Medium | 1.0% | 7.2 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command inject… | |
| CVE-2026-15965 | Medium | 1.0% | 8.8 | The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress … | |
| CVE-2026-18851 | Medium | 1.0% | 8.8 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2… | |
| CVE-2026-61524 | Medium | 1.0% | 7.2 | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the … | |
| CVE-2026-67192 | Medium | 1.0% | 8.1 | Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnera… | |
| CVE-2026-15969 | Medium | 1.0% | 9.8 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of Sa… | |
| CVE-2026-34648 | Medium | 1.0% | 7.5 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-49163 | Medium | 1.0% | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') in Applicat… | |
| CVE-2026-56196 | Medium | 1.0% | 8.8 | Relative path traversal in Windows Admin Center allows an authorized attacker to execute c… | |
| CVE-2026-59115 | Medium | 1.0% | 9.9 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized atta… | |
| CVE-2026-63509 | Medium | 1.0% | 9.9 | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privi… | |
| CVE-2026-67368 | Medium | 1.0% | 8.8 | Improper link resolution before file access ('link following') in SQL Server allows an aut… | |
| CVE-2026-18284 | Medium | 1.0% | 7.8 | Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerabil… | |
| CVE-2026-50628 | Medium | 1.0% | 9.8 | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound… | |
| CVE-2026-68839 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized… | |
| CVE-2026-69845 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execu… | |
| CVE-2026-14457 | Medium | 1.0% | 7.5 | Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) ena… | |
| CVE-2023-52434 | Medium | 1.0% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix pote… | |
| CVE-2026-76008 | Medium | 1.0% | 10.0 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_… | |
| CVE-2026-77946 | Medium | 1.0% | 10.0 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerab… | |
| CVE-2026-94003 | Medium | 1.0% | 10.0 | A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_cs… | |
| CVE-2021-38633 | Medium | 1.0% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2023-52798 | Medium | 1.0% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix dfs… |