Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-55200 | Medium | 0.8% | 8.1 | libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerabil… | |
| CVE-2026-76218 | Medium | 0.8% | 7.5 | GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that f… | |
| CVE-2022-41063 | Medium | 0.8% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2022-41119 | Medium | 0.8% | 7.8 | Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-12397 | Medium | 0.8% | 7.4 | A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-deli… | |
| CVE-2026-16634 | Medium | 0.8% | 9.8 | TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tom… | |
| CVE-2026-47073 | Medium | 0.8% | 7.5 | Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allo… | |
| CVE-2026-71217 | Medium | 0.8% | 7.5 | A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending cr… | |
| CVE-2026-7598 | Medium | 0.8% | 7.3 | A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element i… | |
| CVE-2026-92596 | Medium | 0.8% | 7.5 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressp… | |
| CVE-2026-9698 | Medium | 0.8% | 9.8 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages… | |
| CVE-2026-4326 | Medium | 0.8% | 8.8 | The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorizatio… | |
| CVE-2026-52999 | Medium | 0.8% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_… | |
| CVE-2026-64577 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_d… | |
| CVE-2024-38558 | Medium | 0.8% | 10.0 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix… | |
| CVE-2026-14474 | Medium | 0.8% | 8.8 | A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is no… | |
| CVE-2026-14958 | Medium | 0.8% | 9.1 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to … | |
| CVE-2026-50481 | Medium | 0.8% | 9.9 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authoriz… | |
| CVE-2026-66709 | Medium | 0.8% | 9.1 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | |
| CVE-2026-84738 | Medium | 0.8% | 9.1 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files upload… | |
| CVE-2026-15802 | Medium | 0.8% | 8.1 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to ins… | |
| CVE-2026-39399 | Medium | 0.8% | 9.6 | NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exis… | |
| CVE-2026-47102 | Medium | 0.8% | 8.8 | LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update … | |
| CVE-2026-49362 | Medium | 0.8% | 7.5 | An unauthenticated remote attacker can create arbitrary durable queues via the CORE protoc… | |
| CVE-2026-69259 | Medium | 0.8% | 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2022-49561 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack:… | |
| CVE-2026-26212 | Medium | 0.8% | 7.2 | Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file up… | |
| CVE-2026-40895 | Medium | 0.8% | 7.5 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modu… | |
| CVE-2026-43803 | Medium | 0.8% | 9.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fi… | |
| CVE-2026-43810 | Medium | 0.8% | 9.8 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 … | |
| CVE-2026-46735 | Medium | 0.8% | 7.8 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper… | |
| CVE-2026-47612 | Medium | 0.8% | 7.5 | NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an a… | |
| CVE-2026-48328 | Medium | 0.8% | 7.7 | ColdFusion is affected by an Improper Input Validation vulnerability that could result in … | |
| CVE-2026-48863 | Medium | 0.8% | 7.5 | A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP… | |
| CVE-2026-53836 | Medium | 0.8% | 8.8 | OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded… | |
| CVE-2026-67859 | Medium | 0.8% | 7.5 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a deni… | |
| CVE-2026-67866 | Medium | 0.8% | 7.5 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a … | |
| CVE-2026-67867 | Medium | 0.8% | 7.5 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a … | |
| CVE-2026-67869 | Medium | 0.8% | 7.5 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a deni… | |
| CVE-2026-67871 | Medium | 0.8% | 7.5 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a … | |
| CVE-2026-73514 | Medium | 0.8% | 8.8 | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, con… | |
| CVE-2026-75438 | Medium | 0.8% | 7.5 | Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial… | |
| CVE-2026-75998 | Medium | 0.8% | 7.5 | ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbi… | |
| CVE-2026-77108 | Medium | 0.8% | 7.5 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result i… | |
| CVE-2026-80233 | Medium | 0.8% | 7.2 | CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitr… | |
| CVE-2026-90932 | Medium | 0.8% | 7.2 | LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the c… | |
| CVE-2026-92970 | Medium | 0.8% | 8.8 | HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload … | |
| CVE-2021-33034 | Medium | 0.8% | 7.8 | In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when des… | |
| CVE-2023-3617 | Medium | 0.8% | 7.3 | A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been cl… | |
| CVE-2026-32225 | Medium | 0.8% | 8.8 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a … |