Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-7465 | Medium | 1.0% | 8.8 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress i… | |
| CVE-2026-82010 | Medium | 1.0% | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2026-14913 | Medium | 1.0% | 8.8 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vul… | |
| CVE-2026-47698 | Medium | 1.0% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup… | |
| CVE-2026-56671 | Medium | 1.0% | 7.5 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Pr… | |
| CVE-2026-63913 | Medium | 1.0% | 8.2 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack:… | |
| CVE-2026-14512 | Medium | 1.0% | 9.8 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authenticat… | |
| CVE-2026-44168 | Medium | 1.0% | 8.0 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to befo… | |
| CVE-2020-3317 | Medium | 1.0% | 7.5 | A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) So… | |
| CVE-2023-21778 | Medium | 1.0% | 8.0 | Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | |
| CVE-2026-26278 | Medium | 1.0% | 7.5 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS… | |
| CVE-2026-53977 | Medium | 1.0% | 7.5 | OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthentic… | |
| CVE-2026-42039 | Medium | 1.0% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31… | |
| CVE-2026-44496 | Medium | 1.0% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.… | |
| CVE-2026-48553 | Medium | 1.0% | 7.5 | Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated re… | |
| CVE-2026-48554 | Medium | 1.0% | 7.5 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated re… | |
| CVE-2026-54629 | Medium | 1.0% | 7.5 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server ex… | |
| CVE-2021-26899 | Medium | 1.0% | 7.8 | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
| CVE-2021-27364 | Medium | 1.0% | 7.1 | An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_is… | |
| CVE-2026-42264 | Medium | 1.0% | 7.4 | Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to be… | |
| CVE-2026-91103 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-4598 | Medium | 1.0% | 7.5 | Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bn… | |
| CVE-2026-67614 | Medium | 1.0% | 9.8 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal … | |
| CVE-2026-91101 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-91104 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-91106 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-13423 | Medium | 1.0% | 9.8 | The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce ver… | |
| CVE-2026-18391 | Medium | 1.0% | 9.8 | The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input b… | |
| CVE-2026-19952 | Medium | 1.0% | 7.5 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file dele… | |
| CVE-2026-67191 | Medium | 1.0% | 9.8 | Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerab… | |
| CVE-2026-82954 | Medium | 1.0% | 9.9 | A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writ… | |
| CVE-2022-32981 | Medium | 1.0% | 7.8 | An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. Th… | |
| CVE-2026-75149 | Medium | 1.0% | 8.8 | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuratio… | |
| CVE-2026-83497 | Medium | 1.0% | 8.8 | Unrestricted deserialization of untrusted data in the cursor pagination component in the O… | |
| CVE-2017-20237 | Medium | 1.0% | 9.8 | Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentic… | |
| CVE-2026-18649 | Medium | 1.0% | 7.5 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265de… | |
| CVE-2026-48386 | Medium | 1.0% | 7.5 | ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability… | |
| CVE-2026-23600 | Medium | 1.0% | 9.8 | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APL… | |
| CVE-2026-43642 | Medium | 1.0% | 8.1 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection v… | |
| CVE-2026-5598 | Medium | 1.0% | 7.5 | Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on al… | |
| CVE-2024-27388 | Medium | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some meml… | |
| CVE-2026-47871 | Medium | 1.0% | 8.8 | VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path … | |
| CVE-2026-50027 | Medium | 1.0% | 9.8 | mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all H… | |
| CVE-2026-76578 | Medium | 1.0% | 9.8 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authenticatio… | |
| CVE-2017-20284 | Medium | 1.0% | 7.5 | Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-do… | |
| CVE-2026-11430 | Medium | 1.0% | 7.3 | Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token… | |
| CVE-2026-40411 | Medium | 1.0% | 9.9 | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker t… | |
| CVE-2026-54120 | Medium | 1.0% | 9.9 | Improper input validation in Microsoft Surface allows an authorized attacker to execute co… | |
| CVE-2026-65811 | Medium | 1.0% | 8.8 | Improper input validation in Power BI allows an authorized attacker to execute code over a… | |
| CVE-2024-36912 | Medium | 1.0% | 9.6 | In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: T… |