Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-80235 | Medium | 0.9% | 9.8 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerabilit… | |
| CVE-2026-93952 | Medium | 0.9% | 10.0 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a rem… | |
| CVE-2019-11284 | Medium | 0.9% | 8.6 | Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, includi… | |
| CVE-2024-38541 | Medium | 0.9% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: of: module: add buffe… | |
| CVE-2026-18951 | Medium | 0.9% | 8.8 | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. Th… | |
| CVE-2026-42533 | Medium | 0.9% | 8.1 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex… | |
| CVE-2026-15964 | Medium | 0.9% | 9.8 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via… | |
| CVE-2026-32820 | Medium | 0.9% | 7.5 | dataCycle is a data management system for centrally storing, managing, searching, finding,… | |
| CVE-2026-42154 | Medium | 0.9% | 7.5 | Prometheus is an open-source monitoring system and time series database. Prior to versions… | |
| CVE-2026-78501 | Medium | 0.9% | 7.4 | Improper neutralization of special elements used in a command ('command injection') in Mic… | |
| CVE-2023-52654 | Medium | 0.9% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: dis… | |
| CVE-2026-48252 | Medium | 0.9% | 8.6 | Adobe Experience Manager is affected by a Missing Authentication for Critical Function vul… | |
| CVE-2026-4926 | Medium | 0.9% | 7.5 | Impact: A bad regular expression is generated any time you have multiple sequential optio… | |
| CVE-2026-34282 | Medium | 0.9% | 7.5 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edi… | |
| CVE-2026-42425 | Medium | 0.9% | 7.2 | OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticat… | |
| CVE-2026-48345 | Medium | 0.9% | 8.2 | Animate is affected by an Improper Neutralization of Special Elements used in an OS Comman… | |
| CVE-2026-49845 | Medium | 0.9% | 9.8 | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before… | |
| CVE-2024-43476 | Medium | 0.9% | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2026-17086 | Medium | 0.9% | 8.8 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress… | |
| CVE-2026-30650 | Medium | 0.9% | 8.8 | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/ev… | |
| CVE-2026-44513 | Medium | 0.9% | 8.8 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remo… | |
| CVE-2020-3167 | Medium | 0.9% | 7.8 | A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could all… | |
| CVE-2026-24254 | Medium | 0.9% | 9.8 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where… | |
| CVE-2026-25747 | Medium | 0.9% | 8.8 | Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Ca… | |
| CVE-2026-37006 | Medium | 0.9% | 9.8 | A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an u… | |
| CVE-2026-52608 | Medium | 0.9% | 9.8 | An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthentica… | |
| CVE-2026-56741 | Medium | 0.9% | 7.5 | JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, t… | |
| CVE-2026-62182 | Medium | 0.9% | 8.8 | KubeEdge is an open source system for extending native containerized application orchestra… | |
| CVE-2026-62371 | Medium | 0.9% | 8.8 | KubeEdge is an open source system for extending native containerized application orchestra… | |
| CVE-2026-68300 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify au… | |
| CVE-2026-88885 | Medium | 0.9% | 7.0 | Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager wh… | |
| CVE-2026-88888 | Medium | 0.9% | 7.0 | Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when… | |
| CVE-2026-28367 | Medium | 0.9% | 8.7 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending … | |
| CVE-2026-30632 | Medium | 0.9% | 7.5 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name valu… | |
| CVE-2026-30633 | Medium | 0.9% | 7.5 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to th… | |
| CVE-2026-48842 | Medium | 0.9% | 8.1 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL in… | |
| CVE-2026-56684 | Medium | 0.9% | 7.5 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1… | |
| CVE-2021-36081 | Medium | 0.9% | 7.8 | Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk … | |
| CVE-2023-21564 | Medium | 0.9% | 7.1 | Azure DevOps Server Cross-Site Scripting Vulnerability | |
| CVE-2026-15014 | Medium | 0.9% | 9.8 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery p… | |
| CVE-2026-5604 | Medium | 0.9% | 8.8 | A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the fun… | |
| CVE-2026-5605 | Medium | 0.9% | 8.8 | A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExt… | |
| CVE-2026-74239 | Medium | 0.9% | 7.2 | XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importe… | |
| CVE-2026-75854 | Medium | 0.9% | 9.8 | ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redi… | |
| CVE-2026-28368 | Medium | 0.9% | 8.7 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct spe… | |
| CVE-2026-28369 | Medium | 0.9% | 8.7 | A flaw was found in Undertow. When Undertow receives an HTTP request where the first heade… | |
| CVE-2026-33845 | Medium | 0.9% | 7.5 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and no… | |
| CVE-2026-82244 | Medium | 0.9% | 9.1 | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin ha… | |
| CVE-2024-1139 | Medium | 0.9% | 7.7 | A credentials leak vulnerability was found in the cluster monitoring operator in OCP. Thi… | |
| CVE-2024-42286 | Medium | 0.9% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: valida… |