Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-61343 | Medium | 1.0% | 7.2 | LibreBooking's email template editor save action passes the submitted template name direct… | |
| CVE-2026-69100 | Medium | 1.0% | 8.8 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote … | |
| CVE-2026-80156 | Medium | 1.0% | 9.1 | Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and … | |
| CVE-2026-58023 | Medium | 1.0% | 9.1 | Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apa… | |
| CVE-2022-31339 | Medium | 1.0% | 7.2 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php. | |
| CVE-2023-5379 | Medium | 1.0% | 7.5 | A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size… | |
| CVE-2024-45496 | Medium | 1.0% | 9.9 | A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges … | |
| CVE-2026-14522 | Medium | 1.0% | 8.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 coul… | |
| CVE-2026-4107 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-34653 | Medium | 1.0% | 8.7 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-27577 | Medium | 1.0% | 9.9 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1… | |
| CVE-2026-76674 | Medium | 1.0% | 9.8 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking… | |
| CVE-2022-41088 | Medium | 1.0% | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | |
| CVE-2026-19264 | Medium | 1.0% | 9.8 | Postiz is an open-source social media scheduling tool. The route that serves locally store… | |
| CVE-2026-80351 | Medium | 1.0% | 9.8 | Improper neutralization of directives in dynamically evaluated code ('eval injection') vul… | |
| CVE-2026-44795 | Medium | 1.0% | 8.8 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, … | |
| CVE-2026-72551 | Medium | 1.0% | 8.8 | A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with… | |
| CVE-2026-72556 | Medium | 1.0% | 8.8 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user … | |
| CVE-2026-63732 | Medium | 1.0% | 9.9 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default … | |
| CVE-2026-89009 | Medium | 1.0% | 9.1 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an una… | |
| CVE-2023-2008 | Medium | 1.0% | 8.2 | A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This… | |
| CVE-2026-55005 | Medium | 1.0% | 8.8 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to e… | |
| CVE-2026-69256 | Medium | 1.0% | 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-91097 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-9863 | Medium | 1.0% | 7.5 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade a… | |
| CVE-2026-5204 | Medium | 1.0% | 8.8 | A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebType… | |
| CVE-2026-5349 | Medium | 1.0% | 8.8 | A vulnerability was identified in Trendnet TEW-657BRM 1.00.1. The affected element is the … | |
| CVE-2026-5350 | Medium | 1.0% | 8.8 | A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is… | |
| CVE-2026-5567 | Medium | 1.0% | 8.8 | A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdv… | |
| CVE-2026-5609 | Medium | 1.0% | 8.8 | A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the f… | |
| CVE-2026-63072 | Medium | 1.0% | 7.5 | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying… | |
| CVE-2026-70306 | Medium | 1.0% | 9.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Mi… | |
| CVE-2026-93839 | Medium | 1.0% | 9.8 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register… | |
| CVE-2026-33210 | Medium | 1.0% | 9.1 | Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2… | |
| CVE-2026-47299 | Medium | 1.0% | 7.2 | Improper neutralization of special elements used in a command ('command injection') in Azu… | |
| CVE-2026-59826 | Medium | 1.0% | 9.1 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 … | |
| CVE-2026-81349 | Medium | 1.0% | 7.2 | Improper neutralization of special elements used in an os command ('os command injection')… | |
| CVE-2026-31072 | Medium | 1.0% | 9.8 | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.… | |
| CVE-2026-46372 | Medium | 1.0% | 8.5 | SillyTavern is a locally installed user interface that allows users to interact with text … | |
| CVE-2026-78657 | Medium | 1.0% | 9.8 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary fi… | |
| CVE-2024-26621 | Medium | 1.0% | 8.2 | In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don'… | |
| CVE-2026-62144 | Medium | 1.0% | 9.1 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain… | |
| CVE-2026-91098 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-18352 | Medium | 1.0% | 7.5 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all v… | |
| CVE-2026-34711 | Medium | 1.0% | 7.5 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by … | |
| CVE-2026-48359 | Medium | 1.0% | 9.6 | Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Ref… | |
| CVE-2026-82310 | Medium | 1.0% | 7.2 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to th… | |
| CVE-2019-25758 | Medium | 1.0% | 8.8 | Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allo… | |
| CVE-2026-59692 | Medium | 1.0% | 7.5 | A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS … | |
| CVE-2026-62910 | Medium | 1.0% | 7.2 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Serv… |