Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-2240 | Medium | 1.0% | 7.5 | A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-me… | |
| CVE-2026-48356 | Medium | 1.0% | 9.3 | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerabi… | |
| CVE-2026-67615 | Medium | 1.0% | 8.8 | openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability … | |
| CVE-2024-41040 | Medium | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix UAF wh… | |
| CVE-2026-5830 | Medium | 1.0% | 8.8 | A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGe… | |
| CVE-2026-80442 | Medium | 1.0% | 9.9 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection v… | |
| CVE-2026-84838 | Medium | 1.0% | 7.8 | A flaw was found in rpmuncompress. This command injection vulnerability allows a local att… | |
| CVE-2025-37899 | Medium | 1.0% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-… | |
| CVE-2026-18428 | Medium | 1.0% | 8.8 | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL p… | |
| CVE-2026-32211 | Medium | 1.0% | 9.1 | Missing authentication for critical function in Azure MCP Server allows an unauthorized at… | |
| CVE-2026-48579 | Medium | 1.0% | 9.1 | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to dis… | |
| CVE-2026-82450 | Medium | 1.0% | 8.8 | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZI… | |
| CVE-2026-14890 | Medium | 1.0% | 9.1 | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a rou… | |
| CVE-2026-39849 | Medium | 1.0% | 8.8 | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker bloc… | |
| CVE-2021-2316 | Medium | 1.0% | 8.1 | Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: F… | |
| CVE-2026-69276 | Medium | 1.0% | 9.8 | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows a… | |
| CVE-2026-69408 | Medium | 1.0% | 9.8 | Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorize… | |
| CVE-2026-69431 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute cod… | |
| CVE-2026-69493 | Medium | 1.0% | 9.8 | Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to exe… | |
| CVE-2026-69819 | Medium | 1.0% | 9.8 | Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a … | |
| CVE-2026-69824 | Medium | 1.0% | 9.8 | Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized at… | |
| CVE-2026-18613 | Medium | 1.0% | 9.8 | A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the fu… | |
| CVE-2026-34838 | Medium | 1.0% | 9.9 | Group-Office is an enterprise customer relationship management and groupware tool. Prior t… | |
| CVE-2026-68791 | Medium | 1.0% | 8.6 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to discl… | |
| CVE-2026-85917 | Medium | 1.0% | 7.5 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to … | |
| CVE-2026-32725 | Medium | 1.0% | 8.3 | SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior t… | |
| CVE-2026-37007 | Medium | 1.0% | 9.8 | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to… | |
| CVE-2026-5570 | Medium | 1.0% | 7.3 | A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affect… | |
| CVE-2026-58016 | Medium | 1.0% | 7.5 | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml()… | |
| CVE-2026-49849 | Medium | 1.0% | 9.1 | xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerabili… | |
| CVE-2022-37315 | Medium | 1.0% | 7.5 | graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definitio… | |
| CVE-2026-32141 | Medium | 1.0% | 7.5 | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recur… | |
| CVE-2026-47992 | Medium | 1.0% | 7.2 | Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQ… | |
| CVE-2026-75746 | Medium | 1.0% | 9.1 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Co… | |
| CVE-2026-82009 | Medium | 1.0% | 9.1 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2025-5459 | Medium | 1.0% | 8.8 | A user with specific node group editing permissions and a specially crafted class paramete… | |
| CVE-2026-43501 | Medium | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve ma… | |
| CVE-2026-71558 | Medium | 1.0% | 9.8 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects … | |
| CVE-2026-65098 | Medium | 1.0% | 8.1 | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, w… | |
| CVE-2026-85102 | Medium | 1.0% | 9.8 | Improper certificate trust validation during VPN negotiation in Check Point Quantum Securi… | |
| CVE-2026-18245 | Medium | 1.0% | 9.0 | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 … | |
| CVE-2026-45162 | Medium | 1.0% | 8.0 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) an… | |
| CVE-2026-47295 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… | |
| CVE-2026-56197 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in a command ('command injection') in Win… | |
| CVE-2026-5685 | Medium | 1.0% | 8.8 | A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromA… | |
| CVE-2026-5686 | Medium | 1.0% | 8.8 | A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects… | |
| CVE-2026-5687 | Medium | 1.0% | 8.8 | A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function… | |
| CVE-2026-66819 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… | |
| CVE-2026-66820 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… | |
| CVE-2026-67370 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… |