Browse vulnerabilities
379,235 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-40983 | Medium | 0.8% | 7.5 | In Micrometer, it is possible for a user to provide specially crafted gRPC requests that m… | |
| CVE-2026-42561 | Medium | 0.8% | 7.5 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multi… | |
| CVE-2026-44250 | Medium | 0.8% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-44890 | Medium | 0.8% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-46340 | Medium | 0.8% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-48006 | Medium | 0.8% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-50011 | Medium | 0.8% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-70416 | Medium | 0.8% | 10.0 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data … | |
| CVE-2026-70563 | Medium | 0.8% | 8.1 | Improper link resolution before file access ('link following') in Windows Shell allows an … | |
| CVE-2026-81657 | Medium | 0.8% | 9.8 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute… | |
| CVE-2024-7341 | Medium | 0.8% | 7.1 | A session fixation issue was discovered in the SAML adapters provided by Keycloak. The ses… | |
| CVE-2026-18901 | Medium | 0.8% | 7.2 | A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function … | |
| CVE-2026-71979 | Medium | 0.8% | 7.5 | INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commi… | |
| CVE-2026-8855 | Medium | 0.8% | 8.1 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service … | |
| CVE-2026-18453 | Medium | 0.8% | 7.5 | A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged result… | |
| CVE-2026-33466 | Medium | 0.8% | 8.1 | Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead … | |
| CVE-2026-42579 | Medium | 0.8% | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Fina… | |
| CVE-2026-61410 | Medium | 0.8% | 9.4 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions … | |
| CVE-2026-63093 | Medium | 0.8% | 8.8 | Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows rem… | |
| CVE-2026-64771 | Medium | 0.8% | 9.8 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS … | |
| CVE-2026-74909 | Medium | 0.8% | 8.1 | Keycloak provides a policy enforcer to protect applications by matching incoming web reque… | |
| CVE-2021-26878 | Medium | 0.8% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2024-26924 | Medium | 0.8% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pi… | |
| CVE-2026-67594 | Medium | 0.8% | 9.8 | Spikster through commit e1cdf8c contains a missing authentication vulnerability that allow… | |
| CVE-2026-84787 | Medium | 0.8% | 8.1 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vul… | |
| CVE-2026-28474 | Medium | 0.8% | 9.8 | OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on th… | |
| CVE-2026-33630 | Medium | 0.8% | 7.5 | c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free… | |
| CVE-2026-52986 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntra… | |
| CVE-2026-84694 | Medium | 0.8% | 8.8 | Coolify before 4.2.0 fails to properly escape environment variable key names in Docker com… | |
| CVE-2026-15303 | Medium | 0.8% | 9.8 | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versio… | |
| CVE-2026-16060 | Medium | 0.8% | 9.8 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not… | |
| CVE-2026-27889 | Medium | 0.8% | 7.5 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging sy… | |
| CVE-2026-33218 | Medium | 0.8% | 7.5 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging sy… | |
| CVE-2026-40682 | Medium | 0.8% | 9.1 | XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryE… | |
| CVE-2026-75627 | Medium | 0.8% | 9.8 | Bastillion fails to properly validate request URI paths in its controller dispatcher, allo… | |
| CVE-2026-33938 | Medium | 0.8% | 8.1 | Handlebars provides the power necessary to let users build semantic templates. In versions… | |
| CVE-2026-86300 | Medium | 0.8% | 7.3 | A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHa… | |
| CVE-2026-86810 | Medium | 0.8% | 7.3 | A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is th… | |
| CVE-2026-16287 | Medium | 0.8% | 7.8 | Improper neutralization of special elements used in an OS command ('OS command injection')… | |
| CVE-2026-77111 | Medium | 0.8% | 8.7 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result i… | |
| CVE-2026-8301 | Medium | 0.8% | 7.8 | Improper neutralization of special elements used in an OS command ('OS command injection')… | |
| CVE-2026-84374 | Medium | 0.8% | 7.5 | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until… | |
| CVE-2026-47303 | Medium | 0.8% | 8.8 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attac… | |
| CVE-2026-73787 | Medium | 0.8% | 7.2 | A vulnerability in the CPPM web interface could allow an authenticated remote attacker to … | |
| CVE-2026-76714 | Medium | 0.8% | 7.2 | Vulnerabilities in the Analytics and Location Engine web interface allows remote authentic… | |
| CVE-2026-82680 | Medium | 0.8% | 8.8 | A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function o… | |
| CVE-2026-9135 | Medium | 0.8% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918… | |
| CVE-2026-92944 | Medium | 0.8% | 9.8 | vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 wh… | |
| CVE-2026-33324 | Medium | 0.8% | 8.8 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In ver… | |
| CVE-2026-34172 | Medium | 0.8% | 8.8 | Giskard is an open-source Python library for testing and evaluating agentic systems. Prior… |