Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-71801 | Medium | 0.8% | 9.8 | An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hard… | |
| CVE-2026-76003 | Medium | 0.8% | 9.9 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the fun… | |
| CVE-2026-76004 | Medium | 0.8% | 9.9 | A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. … | |
| CVE-2026-77022 | Medium | 0.8% | 9.9 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is … | |
| CVE-2026-77148 | Medium | 0.8% | 9.9 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C… | |
| CVE-2026-78050 | Medium | 0.8% | 9.9 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function… | |
| CVE-2026-78169 | Medium | 0.8% | 9.9 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts t… | |
| CVE-2026-78170 | Medium | 0.8% | 8.8 | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function str… | |
| CVE-2026-78478 | Medium | 0.8% | 8.1 | The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, … | |
| CVE-2026-78745 | Medium | 0.8% | 9.8 | An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker … | |
| CVE-2026-82967 | Medium | 0.8% | 9.8 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an… | |
| CVE-2026-85031 | Medium | 0.8% | 9.9 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown func… | |
| CVE-2026-8711 | Medium | 0.8% | 8.1 | NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with … | |
| CVE-2026-9389 | Medium | 0.8% | 8.8 | A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the functio… | |
| CVE-2026-9428 | Medium | 0.8% | 8.8 | A vulnerability has been found in Tenda F1202 1.2.0.20(408). Affected is the function from… | |
| CVE-2026-9429 | Medium | 0.8% | 8.8 | A vulnerability was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is … | |
| CVE-2026-9430 | Medium | 0.8% | 8.8 | A vulnerability was determined in Tenda F1202 1.2.0.20(408). Affected by this issue is the… | |
| CVE-2026-9431 | Medium | 0.8% | 8.8 | A vulnerability was identified in Tenda F1202 1.2.0.20(408). This affects the function fro… | |
| CVE-2026-9627 | Medium | 0.8% | 8.8 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts t… | |
| CVE-2026-9628 | Medium | 0.8% | 8.8 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unkn… | |
| CVE-2026-9631 | Medium | 0.8% | 8.8 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by th… | |
| CVE-2026-9632 | Medium | 0.8% | 8.8 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issu… | |
| CVE-2022-48790 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix a possible … | |
| CVE-2025-1247 | Medium | 0.8% | 8.3 | A flaw was found in Quarkus REST that allows request parameters to leak between concurrent… | |
| CVE-2026-18982 | Medium | 0.8% | 8.8 | A flaw was found in the RHOAI training-operator. This vulnerability allows a user with sta… | |
| CVE-2026-33756 | Medium | 0.8% | 7.5 | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.2… | |
| CVE-2026-33940 | Medium | 0.8% | 8.1 | Handlebars provides the power necessary to let users build semantic templates. In versions… | |
| CVE-2026-72130 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject sh… | |
| CVE-2026-78003 | Medium | 0.8% | 9.8 | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger… | |
| CVE-2026-87976 | Medium | 0.8% | 8.1 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing ex… | |
| CVE-2021-26890 | Medium | 0.8% | 7.8 | Application Virtualization Remote Code Execution Vulnerability | |
| CVE-2026-40036 | Medium | 0.8% | 7.5 | Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_comp… | |
| CVE-2026-48332 | Medium | 0.8% | 7.7 | ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could re… | |
| CVE-2026-49255 | Medium | 0.8% | 8.8 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. … | |
| CVE-2026-54332 | Medium | 0.8% | 7.5 | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the… | |
| CVE-2026-54345 | Medium | 0.8% | 7.5 | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the… | |
| CVE-2026-56160 | Medium | 0.8% | 9.1 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to e… | |
| CVE-2026-65605 | Medium | 0.8% | 9.6 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute Vie… | |
| CVE-2026-65606 | Medium | 0.8% | 9.6 | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protoc… | |
| CVE-2026-72593 | Medium | 0.8% | 9.8 | A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthent… | |
| CVE-2026-73046 | Medium | 0.8% | 9.8 | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAu… | |
| CVE-2026-73056 | Medium | 0.8% | 9.8 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentic… | |
| CVE-2026-73653 | Medium | 0.8% | 9.4 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-… | |
| CVE-2026-84645 | Medium | 0.8% | 8.8 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing … | |
| CVE-2024-39024 | Medium | 0.8% | 8.8 | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execu… | |
| CVE-2024-49996 | Medium | 0.8% | 9.4 | In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer over… | |
| CVE-2026-12151 | Medium | 0.8% | 7.5 | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count o… | |
| CVE-2026-28811 | Medium | 0.8% | 7.5 | Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are… | |
| CVE-2026-32444 | Medium | 0.8% | 9.9 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | |
| CVE-2026-59543 | Medium | 0.8% | 9.9 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. |