Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-33843 | Medium | 0.9% | 9.1 | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directo… | |
| CVE-2026-42782 | Medium | 0.9% | 7.2 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administra… | |
| CVE-2026-58630 | Medium | 0.9% | 10.0 | Improper access control in Azure App Service allows an unauthorized attacker to elevate pr… | |
| CVE-2026-62916 | Medium | 0.9% | 9.1 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an u… | |
| CVE-2026-75977 | Medium | 0.9% | 8.8 | The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authenti… | |
| CVE-2025-11234 | Medium | 0.9% | 7.5 | A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to … | |
| CVE-2026-21273 | Medium | 0.9% | 8.7 | is affected by an Improper Input Validation vulnerability that could result in privilege e… | |
| CVE-2026-48414 | Medium | 0.9% | 7.7 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could… | |
| CVE-2026-74478 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-a… | |
| CVE-2021-38634 | Medium | 0.9% | 7.1 | Microsoft Windows Update Client Elevation of Privilege Vulnerability | |
| CVE-2021-47544 | Medium | 0.9% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix page frag co… | |
| CVE-2026-41109 | Medium | 0.9% | 8.8 | Improper neutralization of special elements in output used by a downstream component ('inj… | |
| CVE-2026-45503 | Medium | 0.9% | 8.1 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to discl… | |
| CVE-2026-47731 | Medium | 0.9% | 9.1 | The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Sp… | |
| CVE-2026-48561 | Medium | 0.9% | 9.6 | Improper neutralization of special elements used in a command ('command injection') in Cop… | |
| CVE-2026-49179 | Medium | 0.9% | 8.8 | Improper neutralization of special elements used in a command ('command injection') in Win… | |
| CVE-2026-55008 | Medium | 0.9% | 9.6 | Improper neutralization of input during web page generation ('cross-site scripting') in Mi… | |
| CVE-2026-57104 | Medium | 0.9% | 8.8 | Improper neutralization of input during web page generation ('cross-site scripting') in Az… | |
| CVE-2026-69320 | Medium | 0.9% | 8.8 | Improper neutralization of special elements used in an os command ('os command injection')… | |
| CVE-2026-70332 | Medium | 0.9% | 9.6 | Improper neutralization of input during web page generation ('cross-site scripting') in Mi… | |
| CVE-2026-78463 | Medium | 0.9% | 8.8 | Improper control of generation of code ('code injection') in Remote Desktop Client allows … | |
| CVE-2026-84190 | Medium | 0.9% | 7.2 | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the About… | |
| CVE-2026-1933 | Medium | 0.9% | 7.1 | A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured wit… | |
| CVE-2026-49827 | Medium | 0.9% | 9.8 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. … | |
| CVE-2026-66309 | Medium | 0.9% | 9.1 | Improper access control in Azure SQL Database allows an authorized attacker to elevate pri… | |
| CVE-2026-69641 | Medium | 0.9% | 9.1 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevat… | |
| CVE-2026-54410 | Medium | 0.9% | 8.6 | nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header f… | |
| CVE-2026-65083 | Medium | 0.9% | 9.9 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where… | |
| CVE-2026-67401 | Medium | 0.9% | 9.9 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution a… | |
| CVE-2026-72765 | Medium | 0.9% | 9.9 | n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression e… | |
| CVE-2024-44946 | Medium | 0.9% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_se… | |
| CVE-2026-16051 | Medium | 0.9% | 9.8 | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the pac… | |
| CVE-2026-16882 | Medium | 0.9% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arb… | |
| CVE-2026-16956 | Medium | 0.9% | 9.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary … | |
| CVE-2026-25470 | Medium | 0.9% | 10.0 | Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for W… | |
| CVE-2026-27544 | Medium | 0.9% | 10.0 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | |
| CVE-2026-48686 | Medium | 0.9% | 9.8 | FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the B… | |
| CVE-2026-62104 | Medium | 0.9% | 10.0 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | |
| CVE-2026-65553 | Medium | 0.9% | 10.0 | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件… | |
| CVE-2026-66613 | Medium | 0.9% | 9.8 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. | |
| CVE-2026-67593 | Medium | 0.9% | 9.1 | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deleti… | |
| CVE-2026-67926 | Medium | 0.9% | 9.8 | An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the f… | |
| CVE-2026-67965 | Medium | 0.9% | 9.8 | An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary cod… | |
| CVE-2026-73343 | Medium | 0.9% | 10.0 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | |
| CVE-2026-81204 | Medium | 0.9% | 9.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary c… | |
| CVE-2026-88404 | Medium | 0.9% | 9.8 | A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() fun… | |
| CVE-2026-88738 | Medium | 0.9% | 8.8 | Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in… | |
| CVE-2026-49759 | Medium | 0.9% | 8.2 | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthen… | |
| CVE-2026-69439 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to el… | |
| CVE-2026-69614 | Medium | 0.9% | 8.8 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to … |