Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69843 | Medium | 0.9% | 10.0 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to e… | |
| CVE-2026-70352 | Medium | 0.9% | 10.0 | Missing authentication for critical function in Azure AI Language allows an unauthorized a… | |
| CVE-2026-85889 | Medium | 0.9% | 10.0 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized at… | |
| CVE-2026-16843 | Medium | 0.9% | 7.2 | Some Hikvision Networking Products are vulnerable to authenticated command execution due t… | |
| CVE-2026-21837 | Medium | 0.9% | 8.8 | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital… | |
| CVE-2026-32286 | Medium | 0.9% | 7.5 | The DataRow.Decode function fails to properly validate field lengths. A malicious or compr… | |
| CVE-2023-20006 | Medium | 0.9% | 8.6 | A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive… | |
| CVE-2026-34647 | Medium | 0.9% | 7.4 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-35031 | Medium | 0.9% | 9.9 | Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a v… | |
| CVE-2026-44604 | Medium | 0.9% | 7.0 | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. Wh… | |
| CVE-2026-56748 | Medium | 0.9% | 8.8 | Improper validation of symbolic links in the Pack Git import feature in Cribl Stream befor… | |
| CVE-2026-5857 | Medium | 0.9% | 8.1 | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_l… | |
| CVE-2026-7246 | Medium | 0.9% | 7.2 | This CVE record was assigned not following CNA/CVE rules and is not considered a valid vul… | |
| CVE-2026-16242 | Medium | 0.9% | 9.4 | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes.… | |
| CVE-2026-25535 | Medium | 0.9% | 7.5 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the fir… | |
| CVE-2026-65693 | Medium | 0.9% | 7.2 | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that… | |
| CVE-2026-67340 | Medium | 0.9% | 7.2 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in… | |
| CVE-2026-71284 | Medium | 0.9% | 7.2 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/bac… | |
| CVE-2026-72649 | Medium | 0.9% | 8.8 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning componen… | |
| CVE-2026-76424 | Medium | 0.9% | 7.2 | A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker… | |
| CVE-2026-93450 | Medium | 0.9% | 7.5 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered… | |
| CVE-2026-17481 | Medium | 0.9% | 8.8 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arb… | |
| CVE-2026-45798 | Medium | 0.9% | 7.5 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-41283 | Medium | 0.9% | 9.9 | OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is ex… | |
| CVE-2023-3390 | Medium | 0.9% | 7.8 | A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/… | |
| CVE-2026-69098 | Medium | 0.9% | 9.8 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_co… | |
| CVE-2026-93467 | Medium | 0.9% | 9.8 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthentica… | |
| CVE-2026-33120 | Medium | 0.9% | 8.8 | Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code … | |
| CVE-2026-41523 | Medium | 0.9% | 7.5 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0,… | |
| CVE-2026-45648 | Medium | 0.9% | 8.8 | Stack-based buffer overflow in Active Directory Domain Services allows an authorized attac… | |
| CVE-2026-49178 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attack… | |
| CVE-2026-50666 | Medium | 0.9% | 8.8 | Use after free in Windows Remote Access Connection Manager allows an authorized attacker t… | |
| CVE-2026-55002 | Medium | 0.9% | 8.8 | External control of file name or path in SQL Server allows an authorized attacker to eleva… | |
| CVE-2026-56194 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to… | |
| CVE-2026-56642 | Medium | 0.9% | 8.8 | Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attack… | |
| CVE-2026-56647 | Medium | 0.9% | 8.8 | Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an a… | |
| CVE-2026-57092 | Medium | 0.9% | 9.9 | Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges ove… | |
| CVE-2026-58626 | Medium | 0.9% | 8.8 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute… | |
| CVE-2026-59133 | Medium | 0.9% | 8.8 | Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack a… | |
| CVE-2026-62784 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an… | |
| CVE-2026-62790 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute … | |
| CVE-2026-62800 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute … | |
| CVE-2026-62818 | Medium | 0.9% | 8.8 | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attac… | |
| CVE-2026-62913 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to e… | |
| CVE-2026-67373 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-67380 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-67381 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileg… | |
| CVE-2026-67384 | Medium | 0.9% | 8.8 | Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code… | |
| CVE-2026-67385 | Medium | 0.9% | 8.8 | Use after free in SQL Server allows an authorized attacker to execute code over a network. | |
| CVE-2026-67388 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… |