Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-26434 | Medium | 0.9% | 7.8 | Visual Studio Elevation of Privilege Vulnerability | |
| CVE-2026-45505 | Medium | 0.9% | 8.8 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulne… | |
| CVE-2026-47392 | Medium | 0.9% | 9.9 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, correspondi… | |
| CVE-2026-56740 | Medium | 0.9% | 7.5 | JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, t… | |
| CVE-2026-15709 | Medium | 0.9% | 7.5 | A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate e… | |
| CVE-2026-35178 | Medium | 0.9% | 9.8 | Workbench is a suite of tools for administrators and developers to interact with Salesforc… | |
| CVE-2025-41265 | Medium | 0.9% | 7.2 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41266 | Medium | 0.9% | 7.2 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41267 | Medium | 0.9% | 7.2 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2025-41279 | Medium | 0.9% | 7.2 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used… | |
| CVE-2026-27459 | Medium | 0.9% | 9.8 | pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and p… | |
| CVE-2026-3505 | Medium | 0.9% | 7.5 | Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vu… | |
| CVE-2026-4111 | Medium | 0.9% | 7.5 | A flaw was identified in the RAR5 archive decompression logic of the libarchive library, s… | |
| CVE-2026-41673 | Medium | 0.9% | 7.5 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XML… | |
| CVE-2026-44178 | Medium | 0.9% | 8.8 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer o… | |
| CVE-2026-44432 | Medium | 0.9% | 7.5 | urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could de… | |
| CVE-2026-44893 | Medium | 0.9% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-46385 | Medium | 0.9% | 7.5 | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders … | |
| CVE-2026-48059 | Medium | 0.9% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-48068 | Medium | 0.9% | 7.5 | @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C+… | |
| CVE-2026-65669 | Medium | 0.9% | 9.6 | Improper neutralization of special elements in output used by a downstream component ('inj… | |
| CVE-2026-8177 | Medium | 0.9% | 7.5 | XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing X… | |
| CVE-2026-9662 | Medium | 0.9% | 8.1 | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusio… | |
| CVE-2024-40983 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tipc: force a dst ref… | |
| CVE-2026-40688 | Medium | 0.9% | 7.2 | An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 th… | |
| CVE-2000-0998 | Medium | 0.9% | 7.2 | Format string vulnerability in top program allows local attackers to gain root privileges … | |
| CVE-2024-43479 | Medium | 0.9% | 8.5 | Microsoft Power Automate Desktop Remote Code Execution Vulnerability | |
| CVE-2026-22029 | Medium | 0.9% | 8.0 | React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react… | |
| CVE-2026-5367 | Medium | 0.9% | 8.6 | A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCP… | |
| CVE-2026-72767 | Medium | 0.9% | 8.8 | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code exe… | |
| CVE-2026-73550 | Medium | 0.9% | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Pri… | |
| CVE-2026-85169 | Medium | 0.9% | 8.8 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in t… | |
| CVE-2026-85438 | Medium | 0.9% | 9.8 | MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() … | |
| CVE-2026-90558 | Medium | 0.9% | 9.8 | sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute forma… | |
| CVE-2026-33811 | Medium | 0.9% | 7.5 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a… | |
| CVE-2026-35171 | Medium | 0.9% | 9.8 | Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the log… | |
| CVE-2026-4602 | Medium | 0.9% | 7.5 | Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion bet… | |
| CVE-2026-55952 | Medium | 0.9% | 7.5 | The Erlang/OTP ssl application does not validate that the PSK identity list and binder lis… | |
| CVE-2026-73418 | Medium | 0.9% | 7.5 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth … | |
| CVE-2024-44985 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possibl… | |
| CVE-2026-38615 | Medium | 0.9% | 9.8 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. | |
| CVE-2026-56211 | Medium | 0.9% | 7.1 | A remote code execution vulnerability was found in libaom, the reference AV1 codec impleme… | |
| CVE-2026-75414 | Medium | 0.9% | 9.8 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without fil… | |
| CVE-2026-91995 | Medium | 0.9% | 9.1 | pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password… | |
| CVE-2026-51368 | Medium | 0.9% | 9.8 | An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExp… | |
| CVE-2026-65643 | Medium | 0.9% | 8.8 | Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execu… | |
| CVE-2026-73268 | Medium | 0.9% | 9.9 | A flaw was found in the cluster-curator-controller component of multicluster engine (MCE).… | |
| CVE-2022-49058 | Medium | 0.9% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: cifs: potential buffe… | |
| CVE-2023-27170 | Medium | 0.9% | 7.5 | Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via m… | |
| CVE-2024-38245 | Medium | 0.9% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability |