Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-58652 | Medium | 0.8% | 7.5 | luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a Lu… | |
| CVE-2026-65093 | Medium | 0.8% | 9.9 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbo… | |
| CVE-2026-68749 | Medium | 0.8% | 7.5 | Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html… | |
| CVE-2026-68750 | Medium | 0.8% | 7.5 | Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sa… | |
| CVE-2026-72592 | Medium | 0.8% | 9.8 | An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauth… | |
| CVE-2026-90779 | Medium | 0.8% | 7.5 | SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() wh… | |
| CVE-2024-21363 | Medium | 0.8% | 7.8 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
| CVE-2026-25755 | Medium | 0.8% | 8.1 | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the arg… | |
| CVE-2026-42001 | Medium | 0.8% | 7.5 | Insufficient Validation of Autoprimary SOA Queries | |
| CVE-2026-54333 | Medium | 0.8% | 9.8 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes… | |
| CVE-2026-54334 | Medium | 0.8% | 9.8 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes… | |
| CVE-2026-58264 | Medium | 0.8% | 9.8 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 u… | |
| CVE-2026-64769 | Medium | 0.8% | 9.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fi… | |
| CVE-2026-64770 | Medium | 0.8% | 9.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fi… | |
| CVE-2026-64774 | Medium | 0.8% | 9.8 | An integer overflow was addressed with improved input validation. This issue is fixed in i… | |
| CVE-2026-77550 | Medium | 0.8% | 10.0 | A malicious actor with access to the network could exploit an Improper Neutralization of C… | |
| CVE-2026-77649 | Medium | 0.8% | 9.8 | The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling… | |
| CVE-2026-77650 | Medium | 0.8% | 9.8 | The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when comp… | |
| CVE-2026-77651 | Medium | 0.8% | 9.8 | The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling … | |
| CVE-2026-84474 | Medium | 0.8% | 9.9 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The prov… | |
| CVE-2024-43465 | Medium | 0.8% | 7.8 | Microsoft Excel Elevation of Privilege Vulnerability | |
| CVE-2026-29870 | Medium | 0.8% | 7.6 | A directory traversal vulnerability in the agentic-context-engine project versions up to 0… | |
| CVE-2026-52134 | Medium | 0.8% | 9.8 | An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6… | |
| CVE-2026-63223 | Medium | 0.8% | 9.8 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in up… | |
| CVE-2026-68746 | Medium | 0.8% | 8.8 | Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an una… | |
| CVE-2024-41048 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: skmsg: Skip zero leng… | |
| CVE-2026-19286 | Medium | 0.8% | 9.8 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary c… | |
| CVE-2026-34406 | Medium | 0.8% | 8.8 | APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automa… | |
| CVE-2026-37004 | Medium | 0.8% | 9.8 | BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which all… | |
| CVE-2026-5947 | Medium | 0.8% | 7.5 | Undefined behavior may result due to a race condition leading to a use-after-free violatio… | |
| CVE-2026-65423 | Medium | 0.8% | 8.8 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 ma… | |
| CVE-2026-71559 | Medium | 0.8% | 7.5 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory al… | |
| CVE-2022-41051 | Medium | 0.8% | 7.8 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| CVE-2026-15667 | Medium | 0.8% | 7.5 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin fo… | |
| CVE-2026-42499 | Medium | 0.8% | 7.5 | Pathological inputs could cause DoS through consumePhrase when parsing an email address ac… | |
| CVE-2026-63508 | Medium | 0.8% | 10.0 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an… | |
| CVE-2026-64878 | Medium | 0.8% | 9.9 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command… | |
| CVE-2026-65667 | Medium | 0.8% | 10.0 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privil… | |
| CVE-2026-69502 | Medium | 0.8% | 10.0 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker t… | |
| CVE-2026-69555 | Medium | 0.8% | 10.0 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges… | |
| CVE-2026-70340 | Medium | 0.8% | 8.1 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privile… | |
| CVE-2026-72194 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add depth l… | |
| CVE-2026-73750 | Medium | 0.8% | 8.8 | Vulnerabilities exist in the authentication module that may improperly process malformed o… | |
| CVE-2026-64679 | Medium | 0.8% | 8.1 | Atlantis is a self-hosted golang application that listens for Terraform pull request event… | |
| CVE-2026-64824 | Medium | 0.8% | 8.4 | Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-… | |
| CVE-2026-63455 | Medium | 0.8% | 9.8 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator c… | |
| CVE-2026-63456 | Medium | 0.8% | 9.8 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator c… | |
| CVE-2026-65640 | Medium | 0.8% | 8.8 | WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript … | |
| CVE-2026-16840 | Medium | 0.8% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arb… | |
| CVE-2026-16917 | Medium | 0.8% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arb… |