Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-3141 | Medium | 0.9% | 9.1 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion du… | |
| CVE-2026-34649 | Medium | 0.9% | 7.5 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-34650 | Medium | 0.9% | 7.5 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-34651 | Medium | 0.9% | 7.5 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-34652 | Medium | 0.9% | 7.5 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-34665 | Medium | 0.9% | 7.5 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by … | |
| CVE-2026-34713 | Medium | 0.9% | 7.5 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by … | |
| CVE-2026-48438 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could… | |
| CVE-2026-48439 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability … | |
| CVE-2026-71360 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability … | |
| CVE-2026-71442 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerabi… | |
| CVE-2026-72819 | Medium | 0.9% | 8.8 | Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects … | |
| CVE-2026-75632 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability … | |
| CVE-2026-32186 | Medium | 0.9% | 10.0 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to el… | |
| CVE-2026-32213 | Medium | 0.9% | 10.0 | Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate priv… | |
| CVE-2026-33105 | Medium | 0.9% | 10.0 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attack… | |
| CVE-2026-33107 | Medium | 0.9% | 10.0 | Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to … | |
| CVE-2026-47280 | Medium | 0.9% | 10.0 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to… | |
| CVE-2026-56162 | Medium | 0.9% | 10.0 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate p… | |
| CVE-2026-56163 | Medium | 0.9% | 10.0 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows … | |
| CVE-2026-56191 | Medium | 0.9% | 10.0 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to pe… | |
| CVE-2026-57106 | Medium | 0.9% | 10.0 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elev… | |
| CVE-2026-61552 | Medium | 0.9% | 7.2 | Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, t… | |
| CVE-2026-65690 | Medium | 0.9% | 8.8 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validat… | |
| CVE-2026-65801 | Medium | 0.9% | 10.0 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized att… | |
| CVE-2026-66803 | Medium | 0.9% | 10.0 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code… | |
| CVE-2026-73025 | Medium | 0.9% | 9.8 | Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security … | |
| CVE-2026-57127 | Medium | 0.9% | 9.8 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuth… | |
| CVE-2026-59942 | Medium | 0.9% | 7.5 | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a De… | |
| CVE-2026-72695 | Medium | 0.9% | 8.1 | Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile… | |
| CVE-2024-30073 | Medium | 0.9% | 7.8 | Windows Security Zone Mapping Security Feature Bypass Vulnerability | |
| CVE-2026-25559 | Medium | 0.9% | 8.8 | OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist … | |
| CVE-2026-57863 | Medium | 0.9% | 8.8 | Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update AP… | |
| CVE-2026-81849 | Medium | 0.9% | 8.8 | Improper limitation of a pathname to a restricted directory in the aws:downloadContent plu… | |
| CVE-2026-86492 | Medium | 0.9% | 8.5 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft … | |
| CVE-2026-3655 | Medium | 0.9% | 9.8 | The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to au… | |
| CVE-2026-49361 | Medium | 0.9% | 7.5 | Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with… | |
| CVE-2026-80231 | Medium | 0.9% | 7.5 | A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given ho… | |
| CVE-2019-12699 | Medium | 0.9% | 7.8 | Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defe… | |
| CVE-2021-26425 | Medium | 0.9% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2026-33891 | Medium | 0.9% | 7.5 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in… | |
| CVE-2026-34078 | Medium | 0.9% | 10.0 | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the… | |
| CVE-2026-48259 | Medium | 0.9% | 9.6 | Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability… | |
| CVE-2026-72713 | Medium | 0.9% | 7.5 | XAgent contains a path traversal vulnerability in the workspace file endpoint that allows … | |
| CVE-2026-76009 | Medium | 0.9% | 8.1 | The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authent… | |
| CVE-2026-85606 | Medium | 0.9% | 7.5 | firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the fir… | |
| CVE-2026-53633 | Medium | 0.9% | 9.8 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-be… | |
| CVE-2026-5497 | Medium | 0.9% | 7.5 | vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (… | |
| CVE-2026-84383 | Medium | 0.9% | 9.8 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a cr… | |
| CVE-2026-56705 | Medium | 0.9% | 9.8 | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN stri… |