Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-2229 | Medium | 0.9% | 7.5 | ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to impro… | |
| CVE-2026-48399 | Medium | 0.9% | 7.5 | Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulner… | |
| CVE-2026-58612 | Medium | 0.9% | 7.4 | Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized att… | |
| CVE-2026-8619 | Medium | 0.9% | 7.5 | An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2… | |
| CVE-2026-93993 | Medium | 0.9% | 8.8 | Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree … | |
| CVE-2021-26898 | Medium | 0.9% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2026-29181 | Medium | 0.9% | 7.5 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-v… | |
| CVE-2026-80229 | Medium | 0.9% | 7.5 | When performing transfers via libcurl’s multi interface, pooled TLS connections can outliv… | |
| CVE-2024-41081 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ila: block BH in ila_… | |
| CVE-2026-66373 | Medium | 0.9% | 7.5 | Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTOR… | |
| CVE-2024-42145 | Medium | 0.9% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: IB/core: Implement a … | |
| CVE-2026-56623 | Medium | 0.9% | 7.1 | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Ja… | |
| CVE-2020-1088 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER h… | |
| CVE-2024-42285 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix a use-… | |
| CVE-2026-0603 | Medium | 0.9% | 8.3 | A flaw was found in Hibernate. A remote attacker with low privileges could exploit a secon… | |
| CVE-2026-27891 | Medium | 0.9% | 7.2 | FacturaScripts is an open source accounting and invoicing software. Versions 2026 and belo… | |
| CVE-2026-35174 | Medium | 0.9% | 9.1 | Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vul… | |
| CVE-2026-54399 | Medium | 0.9% | 7.5 | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache H… | |
| CVE-2026-54428 | Medium | 0.9% | 7.5 | Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache… | |
| CVE-2026-63454 | Medium | 0.9% | 7.2 | An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of… | |
| CVE-2026-73765 | Medium | 0.9% | 7.2 | Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful … | |
| CVE-2026-75963 | Medium | 0.9% | 7.5 | The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all ver… | |
| CVE-2026-84086 | Medium | 0.9% | 7.2 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute a… | |
| CVE-2026-4885 | Medium | 0.9% | 9.8 | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file … | |
| CVE-2026-49832 | Medium | 0.9% | 8.0 | DSpace open source software is a repository application which provides durable access to d… | |
| CVE-2026-6960 | Medium | 0.9% | 9.8 | The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to m… | |
| CVE-2026-85216 | Medium | 0.9% | 9.8 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication… | |
| CVE-2024-21538 | Medium | 0.9% | 7.5 | Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerab… | |
| CVE-2026-15459 | Medium | 0.9% | 8.1 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all … | |
| CVE-2026-19136 | Medium | 0.9% | 7.8 | A potential command injection vulnerability was reported in the Tianxi AI Agent PC Applica… | |
| CVE-2026-33814 | Medium | 0.9% | 7.5 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing C… | |
| CVE-2026-39820 | Medium | 0.9% | 7.5 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to tr… | |
| CVE-2026-40192 | Medium | 0.9% | 7.5 | Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amoun… | |
| CVE-2026-40400 | Medium | 0.9% | 8.0 | Relative path traversal in Windows PowerShell allows an authorized attacker to execute cod… | |
| CVE-2021-1640 | Medium | 0.9% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2022-49407 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: dlm: fix plock invali… | |
| CVE-2025-23368 | Medium | 0.9% | 8.1 | A flaw was found in Wildfly Elytron integration. The component does not implement sufficie… | |
| CVE-2026-69807 | Medium | 0.9% | 8.0 | Improper limitation of a pathname to a restricted directory ('path traversal') in Windows … | |
| CVE-2026-7307 | Medium | 0.9% | 7.5 | A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially craf… | |
| CVE-2026-84484 | Medium | 0.9% | 7.5 | ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdn… | |
| CVE-2026-8809 | Medium | 0.9% | 9.8 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escal… | |
| CVE-2026-93491 | Medium | 0.9% | 7.5 | A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploi… | |
| CVE-2026-38165 | Medium | 0.9% | 9.8 | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine conf… | |
| CVE-2026-47930 | Medium | 0.9% | 8.1 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validati… | |
| CVE-2026-58195 | Medium | 0.9% | 8.8 | Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP serv… | |
| CVE-2026-65687 | Medium | 0.9% | 9.8 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validat… | |
| CVE-2026-65688 | Medium | 0.9% | 9.8 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validat… | |
| CVE-2026-65689 | Medium | 0.9% | 9.8 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validat… | |
| CVE-2026-78847 | Medium | 0.9% | 9.8 | An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in l… | |
| CVE-2026-90413 | Medium | 0.9% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject logi… |