Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-48207 | Medium | 0.8% | 9.8 | Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could b… | |
| CVE-2026-55196 | Medium | 0.8% | 9.1 | Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey re… | |
| CVE-2026-70336 | Medium | 0.8% | 8.8 | Improper control of generation of code ('code injection') in Visual Studio Code allows an … | |
| CVE-2026-7522 | Medium | 0.8% | 8.8 | The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File I… | |
| CVE-2026-54658 | Medium | 0.8% | 9.8 | Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in … | |
| CVE-2026-62895 | Medium | 0.8% | 8.8 | Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized … | |
| CVE-2026-68160 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth ou… | |
| CVE-2026-73749 | Medium | 0.8% | 9.8 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processin… | |
| CVE-2026-93922 | Medium | 0.8% | 8.8 | SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog wi… | |
| CVE-2024-38544 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix seg fau… | |
| CVE-2026-69865 | Medium | 0.8% | 10.0 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an… | |
| CVE-2026-83711 | Medium | 0.8% | 10.0 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C a… | |
| CVE-2026-83944 | Medium | 0.8% | 10.0 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate pri… | |
| CVE-2026-12996 | Medium | 0.8% | 8.1 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remot… | |
| CVE-2026-70477 | Medium | 0.8% | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-74232 | Medium | 0.8% | 9.8 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 … | |
| CVE-2026-88795 | Medium | 0.8% | 9.0 | The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API a… | |
| CVE-2025-63823 | Medium | 0.8% | 9.8 | My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authenticatio… | |
| CVE-2026-39387 | Medium | 0.8% | 7.2 | BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs,… | |
| CVE-2026-42298 | Medium | 0.8% | 10.0 | Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vul… | |
| CVE-2026-45697 | Medium | 0.8% | 9.8 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticat… | |
| CVE-2026-72764 | Medium | 0.8% | 8.8 | n8n's JavaScript task runner shared a single module cache across all users' Code-node exec… | |
| CVE-2021-33751 | Medium | 0.8% | 7.0 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2026-11756 | Medium | 0.8% | 10.0 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPE… | |
| CVE-2026-17061 | Medium | 0.8% | 10.0 | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from … | |
| CVE-2026-39890 | Medium | 0.8% | 9.8 | PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromF… | |
| CVE-2026-59940 | Medium | 0.8% | 9.8 | Seroval facilitates JS value stringification, including complex structures beyond JSON.str… | |
| CVE-2026-65883 | Medium | 0.8% | 9.8 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less… | |
| CVE-2026-7858 | Medium | 0.8% | 9.8 | A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic R… | |
| CVE-2026-20919 | Medium | 0.8% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition'… | |
| CVE-2026-20926 | Medium | 0.8% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition'… | |
| CVE-2026-64837 | Medium | 0.8% | 8.8 | ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/prope… | |
| CVE-2026-72875 | Medium | 0.8% | 8.8 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.… | |
| CVE-2026-72902 | Medium | 0.8% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy a… | |
| CVE-2026-76186 | Medium | 0.8% | 9.1 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user'… | |
| CVE-2022-50717 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds… | |
| CVE-2024-43847 | Medium | 0.8% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix inv… | |
| CVE-2026-19508 | Medium | 0.8% | 9.8 | Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebU… | |
| CVE-2026-66793 | Medium | 0.8% | 8.8 | A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced C… | |
| CVE-2026-72508 | Medium | 0.8% | 9.9 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cl… | |
| CVE-2026-43869 | Medium | 0.8% | 7.3 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. Thi… | |
| CVE-2026-45644 | Medium | 0.8% | 8.0 | Improper neutralization of input during web page generation ('cross-site scripting') in Mi… | |
| CVE-2026-49298 | Medium | 0.8% | 8.8 | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to auth… | |
| CVE-2026-73841 | Medium | 0.8% | 8.8 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 an… | |
| CVE-2026-88899 | Medium | 0.8% | 9.8 | knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request h… | |
| CVE-2022-50668 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix deadlock du… | |
| CVE-2026-19750 | Medium | 0.8% | 8.1 | A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by t… | |
| CVE-2026-25588 | Medium | 0.8% | 8.8 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of Redis… | |
| CVE-2026-25589 | Medium | 0.8% | 8.8 | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBl… | |
| CVE-2026-49190 | Medium | 0.8% | 8.8 | The system fails to evaluate instructional permissions over multiple internal operation co… |