Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-67638 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-67639 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-67642 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-68775 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-68786 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-69355 | Medium | 0.9% | 8.8 | External control of file name or path in Microsoft Exchange Server allows an authorized at… | |
| CVE-2026-69464 | Medium | 0.9% | 8.8 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized … | |
| CVE-2026-69485 | Medium | 0.9% | 8.8 | Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to ex… | |
| CVE-2026-69522 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute cod… | |
| CVE-2026-69547 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute… | |
| CVE-2026-69551 | Medium | 0.9% | 8.8 | Use after free in Windows DNS allows an authorized attacker to execute code over a network… | |
| CVE-2026-69628 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code … | |
| CVE-2026-69712 | Medium | 0.9% | 8.8 | Use after free in Windows Key Distribution Center allows an authorized attacker to execute… | |
| CVE-2026-69729 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker t… | |
| CVE-2026-71336 | Medium | 0.9% | 8.8 | Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacke… | |
| CVE-2026-71352 | Medium | 0.9% | 8.8 | Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows … | |
| CVE-2026-72959 | Medium | 0.9% | 8.8 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker … | |
| CVE-2026-73012 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows Management Services allows an authorized attacker to… | |
| CVE-2026-75816 | Medium | 0.9% | 9.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypa… | |
| CVE-2026-77481 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-78456 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code ove… | |
| CVE-2026-80096 | Medium | 0.9% | 8.8 | Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to ele… | |
| CVE-2026-14526 | Medium | 0.9% | 9.8 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization byp… | |
| CVE-2026-71472 | Medium | 0.9% | 9.1 | A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attack… | |
| CVE-2026-87935 | Medium | 0.9% | 8.1 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all vers… | |
| CVE-2021-36967 | Medium | 0.9% | 8.0 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | |
| CVE-2026-16466 | Medium | 0.9% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticat… | |
| CVE-2026-76220 | Medium | 0.9% | 8.8 | GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_opt… | |
| CVE-2026-87909 | Medium | 0.9% | 7.5 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all… | |
| CVE-2026-5815 | Medium | 0.9% | 8.8 | A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function he… | |
| CVE-2026-68770 | Medium | 0.9% | 9.8 | sentence-transformers contains a security control bypass vulnerability that allows attacke… | |
| CVE-2026-82592 | Medium | 0.9% | 9.9 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725… | |
| CVE-2026-82593 | Medium | 0.9% | 9.9 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of th… | |
| CVE-2026-90680 | Medium | 0.9% | 9.9 | A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted ele… | |
| CVE-2026-90692 | Medium | 0.9% | 9.9 | A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynami… | |
| CVE-2026-90693 | Medium | 0.9% | 9.9 | A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings … | |
| CVE-2025-3511 | Medium | 0.9% | 7.5 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Co… | |
| CVE-2026-18907 | Medium | 0.9% | 7.5 | Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows … | |
| CVE-2026-34607 | Medium | 0.9% | 7.2 | Emlog is an open source website building system. In versions 2.6.2 and prior, a path trave… | |
| CVE-2026-58567 | Medium | 0.9% | 8.8 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with… | |
| CVE-2026-58571 | Medium | 0.9% | 8.8 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with… | |
| CVE-2026-79682 | Medium | 0.9% | 8.8 | Dell PowerStore contains a Command Injection vulnerability. An authenticated user with lim… | |
| CVE-2024-36929 | Medium | 0.9% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb… | |
| CVE-2026-40938 | Medium | 0.9% | 7.5 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines.… | |
| CVE-2026-4703 | Medium | 0.9% | 9.8 | The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to … | |
| CVE-2026-57123 | Medium | 0.9% | 9.8 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.r… | |
| CVE-2026-81891 | Medium | 0.9% | 8.1 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Pr… | |
| CVE-2020-6830 | Medium | 0.9% | 7.5 | For native-to-JS bridging, the app requires a unique token to be passed that ensures non-a… | |
| CVE-2021-33767 | Medium | 0.9% | 8.2 | Open Enclave SDK Elevation of Privilege Vulnerability | |
| CVE-2026-44417 | Medium | 0.9% | 7.5 | The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was no… |