Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-68782 | Medium | 1.0% | 9.9 | Improper neutralization of special elements used in an sql command ('sql injection') in Az… | |
| CVE-2026-68789 | Medium | 1.0% | 9.9 | Improper neutralization of special elements used in an sql command ('sql injection') in Az… | |
| CVE-2026-69716 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in Mi… | |
| CVE-2026-77908 | Medium | 1.0% | 8.8 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows… | |
| CVE-2026-85885 | Medium | 1.0% | 9.9 | Improper neutralization of special elements used in a command ('command injection') in M36… | |
| CVE-2026-46625 | Medium | 1.0% | 7.5 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version … | |
| CVE-2020-1079 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists when the Windows fails to properly handle o… | |
| CVE-2023-35371 | Medium | 1.0% | 7.8 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2023-35372 | Medium | 1.0% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2023-36896 | Medium | 1.0% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2026-10973 | Medium | 1.0% | 7.4 | Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacke… | |
| CVE-2026-5707 | Medium | 1.0% | 8.8 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Res… | |
| CVE-2026-5709 | Medium | 1.0% | 8.8 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) vers… | |
| CVE-2026-75110 | Medium | 1.0% | 9.8 | MemOS is a memory operating system for LLMs and AI agents. In deployments where authentica… | |
| CVE-2026-75429 | Medium | 1.0% | 9.8 | PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulne… | |
| CVE-2026-81537 | Medium | 1.0% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to… | |
| CVE-2026-86124 | Medium | 1.0% | 9.8 | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP serve… | |
| CVE-2026-86538 | Medium | 1.0% | 7.5 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/temp… | |
| CVE-2026-93031 | Medium | 1.0% | 8.8 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins… | |
| CVE-2026-91003 | Medium | 1.0% | 9.1 | A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_a… | |
| CVE-2026-18358 | Medium | 1.0% | 7.5 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the … | |
| CVE-2026-9231 | Medium | 1.0% | 7.5 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress i… | |
| CVE-2020-1109 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists when the Windows Update Stack fails to prop… | |
| CVE-2026-36467 | Medium | 1.0% | 7.2 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.… | |
| CVE-2026-75496 | Medium | 1.0% | 7.2 | Webkul QloApps does not perform proper validation on uploaded file extensions or MIME type… | |
| CVE-2026-92980 | Medium | 1.0% | 7.2 | HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that all… | |
| CVE-2026-91099 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-55971 | Medium | 1.0% | 9.8 | Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affect… | |
| CVE-2020-1082 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER h… | |
| CVE-2026-24719 | Medium | 1.0% | 7.2 | A command injection vulnerability has been reported to affect several QNAP operating syste… | |
| CVE-2026-47298 | Medium | 1.0% | 8.0 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to exe… | |
| CVE-2026-72538 | Medium | 1.0% | 8.8 | An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticate… | |
| CVE-2026-76187 | Medium | 1.0% | 9.8 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-cred… | |
| CVE-2026-82311 | Medium | 1.0% | 9.8 | Apache Airflow FAB provider: resetting a user's password does not delete that user's exist… | |
| CVE-2024-35857 | Medium | 1.0% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: icmp: prevent possibl… | |
| CVE-2026-7762 | Medium | 1.0% | 9.8 | A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in … | |
| CVE-2026-7763 | Medium | 1.0% | 9.8 | A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Mo… | |
| CVE-2026-29785 | Medium | 1.0% | 7.5 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging sy… | |
| CVE-2026-40412 | Medium | 1.0% | 10.0 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthor… | |
| CVE-2026-42990 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to ex… | |
| CVE-2026-44815 | Medium | 1.0% | 9.8 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to exec… | |
| CVE-2026-45657 | Medium | 1.0% | 9.8 | Use after free in Windows Kernel allows an unauthorized attacker to execute code over a ne… | |
| CVE-2026-47291 | Medium | 1.0% | 9.8 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to exec… | |
| CVE-2026-47643 | Medium | 1.0% | 9.8 | External control of file name or path in Azure Stack Edge allows an unauthorized attacker … | |
| CVE-2026-48397 | Medium | 1.0% | 8.6 | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that co… | |
| CVE-2026-49172 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execu… | |
| CVE-2026-50447 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to e… | |
| CVE-2026-50518 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execu… | |
| CVE-2026-55010 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized at… | |
| CVE-2026-56159 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execu… |