Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2020-1187 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository Service i… | |
| CVE-2020-1188 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository Service i… | |
| CVE-2020-1189 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository Service i… | |
| CVE-2020-1190 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository Service i… | |
| CVE-2025-49794 | Medium | 0.8% | 9.1 | A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath … | |
| CVE-2026-71467 | Medium | 0.8% | 7.5 | A flaw was found in search-v2-api. The authentication middleware in the affected component… | |
| CVE-2026-0288 | Medium | 0.8% | 7.5 | Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) compon… | |
| CVE-2026-18268 | Medium | 0.8% | 7.0 | Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability.… | |
| CVE-2026-57308 | Medium | 0.8% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulne… | |
| CVE-2022-49330 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix tcp_mtup_pro… | |
| CVE-2026-13714 | Medium | 0.8% | 9.8 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not v… | |
| CVE-2026-14812 | Medium | 0.8% | 10.0 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that c… | |
| CVE-2026-15039 | Medium | 0.8% | 9.8 | The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files i… | |
| CVE-2026-16250 | Medium | 0.8% | 9.8 | The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that… | |
| CVE-2026-16618 | Medium | 0.8% | 9.8 | The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files,… | |
| CVE-2026-19089 | Medium | 0.8% | 9.8 | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate u… | |
| CVE-2026-44108 | Medium | 0.8% | 9.8 | Due to a flaw in the execution order of scripts during shutdown, the firewall is terminate… | |
| CVE-2026-50516 | Medium | 0.8% | 9.4 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows … | |
| CVE-2026-67271 | Medium | 0.8% | 9.8 | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unaut… | |
| CVE-2026-73717 | Medium | 0.8% | 7.5 | A command injection vulnerability exists in the web-based management interface of HPE Netw… | |
| CVE-2026-15722 | Medium | 0.8% | 7.5 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruve… | |
| CVE-2026-22807 | Medium | 0.8% | 8.8 | vLLM is an inference and serving engine for large language models (LLMs). Starting in vers… | |
| CVE-2026-64827 | Medium | 0.8% | 9.8 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions,… | |
| CVE-2024-49569 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: unquiesce … | |
| CVE-2026-30286 | Medium | 0.8% | 9.8 | An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 … | |
| CVE-2026-48285 | Medium | 0.8% | 8.6 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forg… | |
| CVE-2026-7374 | Medium | 0.8% | 9.9 | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authen… | |
| CVE-2026-76851 | Medium | 0.8% | 8.8 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Ser… | |
| CVE-2026-77774 | Medium | 0.8% | 8.6 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result i… | |
| CVE-2024-27398 | Medium | 0.8% | 8.0 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-af… | |
| CVE-2026-16138 | Medium | 0.8% | 8.0 | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserial… | |
| CVE-2026-76190 | Medium | 0.8% | 8.6 | ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluate… | |
| CVE-2026-86462 | Medium | 0.8% | 9.1 | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH … | |
| CVE-2026-18618 | Medium | 0.8% | 7.5 | A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdat… | |
| CVE-2026-18941 | Medium | 0.8% | 7.7 | A flaw was found in Feast and feast-operator. The default configuration for both the Feast… | |
| CVE-2026-41292 | Medium | 0.8% | 7.5 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of se… | |
| CVE-2026-43037 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb… | |
| CVE-2026-72914 | Medium | 0.8% | 7.5 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.2… | |
| CVE-2026-73512 | Medium | 0.8% | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Pri… | |
| CVE-2026-73547 | Medium | 0.8% | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Pri… | |
| CVE-2026-80590 | Medium | 0.8% | 8.6 | In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GS… | |
| CVE-2022-41078 | Medium | 0.8% | 8.0 | Microsoft Exchange Server Spoofing Vulnerability | |
| CVE-2022-41079 | Medium | 0.8% | 8.0 | Microsoft Exchange Server Spoofing Vulnerability | |
| CVE-2026-41098 | Medium | 0.8% | 8.4 | Improper neutralization of input during web page generation ('cross-site scripting') in Az… | |
| CVE-2026-61514 | Medium | 0.8% | 9.8 | Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulne… | |
| CVE-2026-69793 | Medium | 0.8% | 7.5 | Improper validation of consistency within input in Windows TCP/IP allows an unauthorized a… | |
| CVE-2026-70552 | Medium | 0.8% | 9.8 | MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX … | |
| CVE-2026-82452 | Medium | 0.8% | 9.8 | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability … | |
| CVE-2026-82923 | Medium | 0.8% | 9.8 | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authoris… | |
| CVE-2026-45541 | Medium | 0.8% | 7.5 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6… |