Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-62906 | Medium | 0.9% | 7.4 | Improper neutralization of special elements in data query logic in Microsoft Discovery Stu… | |
| CVE-2026-80379 | Medium | 0.9% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to… | |
| CVE-2026-80425 | Medium | 0.9% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to… | |
| CVE-2026-85694 | Medium | 0.9% | 8.1 | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtract… | |
| CVE-2026-13339 | Medium | 0.9% | 7.5 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all vers… | |
| CVE-2026-3843 | Medium | 0.9% | 9.8 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL … | |
| CVE-2026-52778 | Medium | 0.9% | 9.8 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulne… | |
| CVE-2026-61551 | Medium | 0.9% | 8.6 | Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing… | |
| CVE-2026-67920 | Medium | 0.9% | 8.8 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.hal… | |
| CVE-2026-74845 | Medium | 0.9% | 8.8 | Official Document Management System developed by 2100 Technology has an Arbitrary File Upl… | |
| CVE-2026-77929 | Medium | 0.9% | 8.8 | ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authentic… | |
| CVE-2021-34510 | Medium | 0.9% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2026-61548 | Medium | 0.9% | 8.1 | Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optiona… | |
| CVE-2026-62827 | Medium | 0.9% | 8.8 | Improper authentication in Microsoft Office SharePoint allows an authorized attacker to el… | |
| CVE-2026-64921 | Medium | 0.9% | 8.8 | Missing authentication for critical function in Microsoft Office SharePoint allows an auth… | |
| CVE-2026-70324 | Medium | 0.9% | 8.8 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized att… | |
| CVE-2025-4330 | Medium | 0.9% | 7.5 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the … | |
| CVE-2026-14323 | Medium | 0.9% | 7.5 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulner… | |
| CVE-2026-50663 | Medium | 0.9% | 8.8 | Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthoriz… | |
| CVE-2026-65768 | Medium | 0.9% | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsof… | |
| CVE-2026-69400 | Medium | 0.9% | 9.6 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Lo… | |
| CVE-2026-70337 | Medium | 0.9% | 8.8 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to ex… | |
| CVE-2026-76801 | Medium | 0.9% | 8.8 | The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment… | |
| CVE-2026-86169 | Medium | 0.9% | 8.8 | Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patc… | |
| CVE-2020-1021 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER h… | |
| CVE-2026-21229 | Medium | 0.9% | 8.0 | Improper input validation in Power BI allows an authorized attacker to execute code over a… | |
| CVE-2026-23815 | Medium | 0.9% | 7.2 | A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticat… | |
| CVE-2026-46384 | Medium | 0.9% | 7.5 | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read … | |
| CVE-2024-43463 | Medium | 0.9% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2026-13368 | Medium | 0.9% | 8.1 | WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability… | |
| CVE-2026-14448 | Medium | 0.9% | 7.2 | An high privileged remote attacker can exploit an authenticated OS command injection vulne… | |
| CVE-2026-73040 | Medium | 0.9% | 8.8 | Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list c… | |
| CVE-2026-75122 | Medium | 0.9% | 7.2 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command … | |
| CVE-2026-16139 | Medium | 0.9% | 7.2 | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authent… | |
| CVE-2026-66256 | Medium | 0.9% | 7.2 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache … | |
| CVE-2022-48788 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix possib… | |
| CVE-2024-8751 | Medium | 0.9% | 7.5 | A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP addre… | |
| CVE-2026-1360 | Medium | 0.9% | 7.5 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in … | |
| CVE-2026-70200 | Medium | 0.9% | 10.0 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Lo… | |
| CVE-2026-44494 | Medium | 0.9% | 8.7 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.1… | |
| CVE-2026-68823 | Medium | 0.9% | 9.1 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized att… | |
| CVE-2023-29491 | Medium | 0.9% | 7.8 | ncurses before 6.4 20230408, when used by a setuid application, allows local users to trig… | |
| CVE-2026-23855 | Medium | 0.9% | 7.2 | Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and … | |
| CVE-2026-29074 | Medium | 0.9% | 7.5 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optim… | |
| CVE-2026-30922 | Medium | 0.9% | 7.5 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vuln… | |
| CVE-2026-44488 | Medium | 0.9% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 thr… | |
| CVE-2026-48779 | Medium | 0.9% | 7.5 | ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up t… | |
| CVE-2026-50682 | Medium | 0.9% | 7.1 | Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny servi… | |
| CVE-2026-77068 | Medium | 0.9% | 8.8 | n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability i… | |
| CVE-2026-91001 | Medium | 0.9% | 9.9 | A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddn… |