Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-64772 | Medium | 0.8% | 9.8 | An out-of-bounds write issue was addressed with improved input validation. This issue is f… | |
| CVE-2026-70455 | Medium | 0.8% | 7.5 | rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote s… | |
| CVE-2026-3014 | Medium | 0.8% | 9.1 | Milestone has released a new version of XProtect® (and several cumulative patch updates) w… | |
| CVE-2026-64606 | Medium | 0.8% | 9.8 | Deserialization of untrusted data vulnerability that may allow class-registration checks t… | |
| CVE-2026-66138 | Medium | 0.8% | 7.2 | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager ro… | |
| CVE-2026-82717 | Medium | 0.8% | 9.8 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can pr… | |
| CVE-2019-12674 | Medium | 0.8% | 8.2 | Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (… | |
| CVE-2024-10963 | Medium | 0.8% | 7.4 | A flaw was found in pam_access, where certain rules in its configuration file are mistaken… | |
| CVE-2026-49980 | Medium | 0.8% | 9.8 | Rclone is a command-line program to sync files and directories to and from different cloud… | |
| CVE-2026-54182 | Medium | 0.8% | 8.1 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a coll… | |
| CVE-2026-6020 | Medium | 0.8% | 7.2 | The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the … | |
| CVE-2026-69223 | Medium | 0.8% | 9.1 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue… | |
| CVE-2026-71187 | Medium | 0.8% | 9.8 | The Ebyte device relies on client side authentication logic that can be reproduced by una… | |
| CVE-2026-71237 | Medium | 0.8% | 9.8 | Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password di… | |
| CVE-2026-73699 | Medium | 0.8% | 7.2 | FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenti… | |
| CVE-2026-9051 | Medium | 0.8% | 9.1 | There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard … | |
| CVE-2026-48827 | Medium | 0.8% | 7.1 | Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation … | |
| CVE-2026-55209 | Medium | 0.8% | 9.8 | resdata is software for reading and writing result files from the Eclipse reservoir simula… | |
| CVE-2026-64767 | Medium | 0.8% | 9.8 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macO… | |
| CVE-2026-13308 | Medium | 0.8% | 8.1 | Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnera… | |
| CVE-2026-47393 | Medium | 0.8% | 9.8 | PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents th… | |
| CVE-2026-59178 | Medium | 0.8% | 9.8 | ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. … | |
| CVE-2026-72920 | Medium | 0.8% | 9.8 | SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedI… | |
| CVE-2026-81735 | Medium | 0.8% | 10.0 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen addr… | |
| CVE-2026-82277 | Medium | 0.8% | 9.8 | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollou… | |
| CVE-2026-35430 | Medium | 0.8% | 8.8 | Authorization bypass through user-controlled key in Azure Privileged Identity Management (… | |
| CVE-2026-40371 | Medium | 0.8% | 8.8 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-… | |
| CVE-2026-42764 | Medium | 0.8% | 7.5 | Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL po… | |
| CVE-2026-45504 | Medium | 0.8% | 8.8 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attac… | |
| CVE-2026-47300 | Medium | 0.8% | 8.8 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized … | |
| CVE-2026-47301 | Medium | 0.8% | 8.8 | Improper access control in Microsoft Configuration Manager allows an authorized attacker t… | |
| CVE-2026-50360 | Medium | 0.8% | 8.8 | Incorrect implementation of authentication algorithm in Windows SMB Server allows an autho… | |
| CVE-2026-50444 | Medium | 0.8% | 8.8 | Missing authentication for critical function in Windows Server Update Service allows an au… | |
| CVE-2026-54121 | Medium | 0.8% | 8.8 | Improper authorization in Active Directory Certificate Services (AD CS) allows an authoriz… | |
| CVE-2026-57969 | Medium | 0.8% | 8.8 | Missing authentication for critical function in Azure CycleCloud allows an authorized atta… | |
| CVE-2026-62830 | Medium | 0.8% | 9.9 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileg… | |
| CVE-2026-62872 | Medium | 0.8% | 8.8 | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privile… | |
| CVE-2026-63075 | Medium | 0.8% | 7.5 | Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-e… | |
| CVE-2026-65668 | Medium | 0.8% | 8.8 | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to e… | |
| CVE-2026-66814 | Medium | 0.8% | 8.8 | Insufficient granularity of access control in SQL Server allows an authorized attacker to … | |
| CVE-2026-66818 | Medium | 0.8% | 8.8 | Improper privilege management in SQL Server allows an authorized attacker to elevate privi… | |
| CVE-2026-69268 | Medium | 0.8% | 8.8 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to ex… | |
| CVE-2026-69273 | Medium | 0.8% | 8.8 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to ex… | |
| CVE-2026-69282 | Medium | 0.8% | 8.8 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to ex… | |
| CVE-2026-69465 | Medium | 0.8% | 8.8 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to exec… | |
| CVE-2026-69676 | Medium | 0.8% | 8.8 | Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker … | |
| CVE-2026-69724 | Medium | 0.8% | 8.8 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to exec… | |
| CVE-2026-69851 | Medium | 0.8% | 9.9 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker… | |
| CVE-2026-70326 | Medium | 0.8% | 8.8 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized att… | |
| CVE-2026-73028 | Medium | 0.8% | 8.8 | Improper access control in SQL Server allows an authorized attacker to elevate privileges … |