Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-23823 | Medium | 1.0% | 7.2 | A vulnerability in the command line interface of Access Points running AOS-10 could allow … | |
| CVE-2026-63520 | Medium | 1.0% | 8.1 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker t… | |
| CVE-2026-5550 | Medium | 1.0% | 8.8 | A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the fun… | |
| CVE-2022-50671 | Medium | 1.0% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix "kernel… | |
| CVE-2022-50676 | Medium | 1.0% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: rds: don't hold … | |
| CVE-2026-15011 | Medium | 1.0% | 9.8 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code I… | |
| CVE-2026-44189 | Medium | 1.0% | 7.8 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookR… | |
| CVE-2026-55159 | Medium | 1.0% | 8.8 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that … | |
| CVE-2026-72867 | Medium | 1.0% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, … | |
| CVE-2026-72901 | Medium | 1.0% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy a… | |
| CVE-2026-90817 | Medium | 1.0% | 9.8 | An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough… | |
| CVE-2026-44673 | Medium | 1.0% | 7.5 | libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in… | |
| CVE-2026-58115 | Medium | 1.0% | 10.0 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All … | |
| CVE-2026-7863 | Medium | 1.0% | 8.4 | Improper neutralization of special elements used in an OS command ('OS command injection')… | |
| CVE-2026-9277 | Medium | 1.0% | 8.1 | shell-quote's `quote()` function did not validate object-token inputs against the operator… | |
| CVE-2024-35248 | Medium | 1.0% | 7.3 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| CVE-2026-6147 | Medium | 1.0% | 8.8 | The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to miss… | |
| CVE-2026-94104 | Medium | 1.0% | 8.8 | NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager… | |
| CVE-2020-3549 | Medium | 1.0% | 8.1 | A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) S… | |
| CVE-2026-3805 | Medium | 1.0% | 7.5 | When doing a second SMB request to the same host again, curl would wrongly use a data poin… | |
| CVE-2026-82003 | Medium | 1.0% | 8.5 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability tha… | |
| CVE-2023-6291 | Medium | 1.0% | 7.1 | A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a … | |
| CVE-2024-38249 | Medium | 1.0% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2026-84218 | Medium | 0.9% | 8.1 | A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of… | |
| CVE-2026-29167 | Medium | 0.9% | 9.8 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configur… | |
| CVE-2026-42359 | Medium | 0.9% | 8.8 | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an… | |
| CVE-2026-47938 | Medium | 0.9% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Serve… | |
| CVE-2026-48331 | Medium | 0.9% | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerabi… | |
| CVE-2026-48333 | Medium | 0.9% | 9.8 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2026-5260 | Medium | 0.9% | 8.2 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster … | |
| CVE-2020-1068 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in Windows Media Service that allows file c… | |
| CVE-2020-1081 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Printer Service improperly… | |
| CVE-2020-1110 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Update Stack fails to prop… | |
| CVE-2020-1111 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Cl… | |
| CVE-2020-1114 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly h… | |
| CVE-2020-1137 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in the way the Windows Push Notification Se… | |
| CVE-2020-1140 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in … | |
| CVE-2020-1142 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in the way that the Windows Graphics Device… | |
| CVE-2020-1154 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Common Log File System (CL… | |
| CVE-2020-1165 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Cl… | |
| CVE-2020-1166 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Cl… | |
| CVE-2025-2610 | Medium | 0.9% | 7.6 | Improper neutralization of input during web page generation vulnerability in MagnusSolutio… | |
| CVE-2026-40477 | Medium | 0.9% | 9.0 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versi… | |
| CVE-2026-42010 | Medium | 0.9% | 7.1 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-S… | |
| CVE-2026-56718 | Medium | 0.9% | 7.5 | AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnera… | |
| CVE-2026-12940 | Medium | 0.9% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execu… | |
| CVE-2026-28387 | Medium | 0.9% | 8.1 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server auth… | |
| CVE-2026-8633 | Medium | 0.9% | 9.8 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IB… | |
| CVE-2026-16469 | Medium | 0.9% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated … | |
| CVE-2026-48317 | Medium | 0.9% | 9.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dy… |