Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-65548 | Medium | 0.8% | 9.9 | Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | |
| CVE-2026-66747 | Medium | 0.8% | 9.8 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in… | |
| CVE-2026-72567 | Medium | 0.8% | 9.8 | An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f3… | |
| CVE-2026-73992 | Medium | 0.8% | 9.9 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | |
| CVE-2026-87701 | Medium | 0.8% | 9.6 | Improper neutralization of special elements in output used by a downstream component ('inj… | |
| CVE-2026-9558 | Medium | 0.8% | 9.9 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The… | |
| CVE-2024-38183 | Medium | 0.8% | 9.8 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker t… | |
| CVE-2024-38587 | Medium | 0.8% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: speakup: Fix sizeof()… | |
| CVE-2026-21279 | Medium | 0.8% | 8.2 | is affected by an Improper Input Validation vulnerability that could result in a Security … | |
| CVE-2026-60112 | Medium | 0.8% | 9.8 | AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerab… | |
| CVE-2026-62391 | Medium | 0.8% | 8.1 | The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyu… | |
| CVE-2026-70461 | Medium | 0.8% | 8.2 | rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows rem… | |
| CVE-2024-44998 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: preven… | |
| CVE-2026-72899 | Medium | 0.8% | 10.0 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared … | |
| CVE-2026-14270 | Medium | 0.8% | 8.8 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plu… | |
| CVE-2026-27282 | Medium | 0.8% | 7.5 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validati… | |
| CVE-2026-28302 | Medium | 0.8% | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability … | |
| CVE-2026-28304 | Medium | 0.8% | 9.1 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploite… | |
| CVE-2026-28305 | Medium | 0.8% | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability … | |
| CVE-2026-28308 | Medium | 0.8% | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability … | |
| CVE-2026-32590 | Medium | 0.8% | 7.1 | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. Th… | |
| CVE-2026-72781 | Medium | 0.8% | 8.8 | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a rem… | |
| CVE-2026-80237 | Medium | 0.8% | 8.8 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerabilit… | |
| CVE-2018-25365 | Medium | 0.8% | 7.5 | PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated a… | |
| CVE-2018-25374 | Medium | 0.8% | 7.5 | Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability… | |
| CVE-2024-50033 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: slip: make slhc_remem… | |
| CVE-2026-26899 | Medium | 0.8% | 8.8 | An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The … | |
| CVE-2026-48381 | Medium | 0.8% | 9.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2026-54680 | Medium | 0.8% | 9.9 | Logging operator automates the deployment and configuration of Kubernetes logging pipeline… | |
| CVE-2026-59878 | Medium | 0.8% | 7.5 | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache A… | |
| CVE-2026-67611 | Medium | 0.8% | 8.1 | OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attacker… | |
| CVE-2026-72738 | Medium | 0.8% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backu… | |
| CVE-2026-72740 | Medium | 0.8% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/… | |
| CVE-2023-21817 | Medium | 0.8% | 7.8 | Windows Kerberos Elevation of Privilege Vulnerability | |
| CVE-2026-49289 | Medium | 0.8% | 7.5 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.… | |
| CVE-2026-54156 | Medium | 0.8% | 7.5 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the p… | |
| CVE-2026-54767 | Medium | 0.8% | 9.1 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema… | |
| CVE-2026-55559 | Medium | 0.8% | 9.8 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateAr… | |
| CVE-2026-66729 | Medium | 0.8% | 7.5 | facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart … | |
| CVE-2026-66730 | Medium | 0.8% | 7.5 | facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart b… | |
| CVE-2026-66731 | Medium | 0.8% | 7.5 | facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 ch… | |
| CVE-2026-67432 | Medium | 0.8% | 7.5 | MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prio… | |
| CVE-2026-70355 | Medium | 0.8% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Mi… | |
| CVE-2026-70464 | Medium | 0.8% | 7.5 | rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows una… | |
| CVE-2026-80131 | Medium | 0.8% | 7.4 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions … | |
| CVE-2026-82520 | Medium | 0.8% | 7.5 | parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read … | |
| CVE-2021-47013 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fi… | |
| CVE-2021-47506 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix use-after-f… | |
| CVE-2026-44492 | Medium | 0.8% | 8.6 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16… | |
| CVE-2026-51366 | Medium | 0.8% | 9.9 | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote a… |