Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-75827 | Medium | 0.9% | 8.8 | Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic… | |
| CVE-2026-77909 | Medium | 0.9% | 7.7 | Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to … | |
| CVE-2026-78518 | Medium | 0.9% | 8.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute co… | |
| CVE-2026-85604 | Medium | 0.9% | 8.8 | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerab… | |
| CVE-2026-85887 | Medium | 0.9% | 7.7 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized… | |
| CVE-2021-26875 | Medium | 0.9% | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-26891 | Medium | 0.9% | 7.8 | Windows Container Execution Agent Elevation of Privilege Vulnerability | |
| CVE-2026-33815 | Medium | 0.9% | 9.8 | Memory-safety vulnerability in github.com/jackc/pgx/v5. | |
| CVE-2026-33816 | Medium | 0.9% | 9.8 | Memory-safety vulnerability in github.com/jackc/pgx/v5. | |
| CVE-2026-58474 | Medium | 0.9% | 8.8 | whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet comm… | |
| CVE-2026-71963 | Medium | 0.9% | 8.8 | Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execut… | |
| CVE-2020-1077 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Runtime improperly handles… | |
| CVE-2026-20931 | Medium | 0.9% | 8.0 | External control of file name or path in Windows Telephony Service allows an authorized at… | |
| CVE-2026-50894 | Medium | 0.9% | 9.8 | easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the… | |
| CVE-2026-62369 | Medium | 0.9% | 8.1 | KubeEdge is an open source system for extending native containerized application orchestra… | |
| CVE-2026-67678 | Medium | 0.9% | 9.8 | File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to … | |
| CVE-2026-67688 | Medium | 0.9% | 9.8 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerabil… | |
| CVE-2026-67858 | Medium | 0.9% | 7.5 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (L… | |
| CVE-2026-90778 | Medium | 0.9% | 7.5 | SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function whe… | |
| CVE-2026-90780 | Medium | 0.9% | 7.5 | SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function i… | |
| CVE-2022-41107 | Medium | 0.9% | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | |
| CVE-2024-21406 | Medium | 0.9% | 7.5 | Windows Printing Service Spoofing Vulnerability | |
| CVE-2026-34573 | Medium | 0.9% | 7.5 | Parse Server is an open source backend that can be deployed to any infrastructure that can… | |
| CVE-2026-44449 | Medium | 0.9% | 9.1 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPa… | |
| CVE-2026-64641 | Medium | 0.9% | 7.5 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 … | |
| CVE-2026-73667 | Medium | 0.9% | 8.8 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1… | |
| CVE-2026-86543 | Medium | 0.9% | 9.8 | knowns versions before 0.30.0 serve the management API without authentication on all netwo… | |
| CVE-2020-1121 | Medium | 0.9% | 7.0 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Cl… | |
| CVE-2020-1132 | Medium | 0.9% | 7.0 | An elevation of privilege vulnerability exists when Windows Error Reporting manager improp… | |
| CVE-2020-1138 | Medium | 0.9% | 7.0 | An elevation of privilege vulnerability exists when the Storage Service improperly handles… | |
| CVE-2024-43470 | Medium | 0.9% | 7.3 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | |
| CVE-2026-44420 | Medium | 0.9% | 8.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malici… | |
| CVE-2026-58231 | Medium | 0.9% | 10.0 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication cl… | |
| CVE-2026-81096 | Medium | 0.9% | 10.0 | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a serve… | |
| CVE-2026-86404 | Medium | 0.9% | 8.8 | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMess… | |
| CVE-2026-11841 | Medium | 0.9% | 9.4 | An attacker may perform unauthenticated read and write operations on sensitive filesystem … | |
| CVE-2026-16915 | Medium | 0.9% | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obta… | |
| CVE-2026-18554 | Medium | 0.9% | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obta… | |
| CVE-2026-19788 | Medium | 0.9% | 8.8 | A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the functio… | |
| CVE-2026-19789 | Medium | 0.9% | 8.8 | A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability … | |
| CVE-2026-19790 | Medium | 0.9% | 8.8 | A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function… | |
| CVE-2026-19791 | Medium | 0.9% | 8.8 | A weakness has been identified in Tenda G0 up to 20260625. The affected element is the fun… | |
| CVE-2026-19792 | Medium | 0.9% | 8.8 | A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function s… | |
| CVE-2026-19811 | Medium | 0.9% | 8.8 | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted… | |
| CVE-2026-19812 | Medium | 0.9% | 8.8 | A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the … | |
| CVE-2026-19813 | Medium | 0.9% | 8.8 | A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This … | |
| CVE-2026-19814 | Medium | 0.9% | 8.8 | A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the fun… | |
| CVE-2026-19815 | Medium | 0.9% | 8.8 | A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerabi… | |
| CVE-2026-19821 | Medium | 0.9% | 8.8 | A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability af… | |
| CVE-2026-19822 | Medium | 0.9% | 8.8 | A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue a… |