Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-73807 | Medium | 0.8% | 9.8 | The mySCADA myPRO Manager command API does not properly enforce authentication for privile… | |
| CVE-2026-77480 | Medium | 0.8% | 8.8 | Insufficient granularity of access control in SQL Server allows an authorized attacker to … | |
| CVE-2026-77483 | Medium | 0.8% | 8.8 | Weak authentication in SQL Server allows an authorized attacker to elevate privileges over… | |
| CVE-2026-77487 | Medium | 0.8% | 8.8 | Improper access control in SQL Server allows an authorized attacker to elevate privileges … | |
| CVE-2026-83941 | Medium | 0.8% | 9.9 | Missing authorization in Entra ID allows an authorized attacker to elevate privileges over… | |
| CVE-2026-94109 | Medium | 0.8% | 8.0 | openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injectio… | |
| CVE-2021-47245 | Medium | 0.8% | 8.2 | In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: … | |
| CVE-2026-46703 | Medium | 0.8% | 9.6 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Box… | |
| CVE-2026-64609 | Medium | 0.8% | 9.1 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserial… | |
| CVE-2026-81757 | Medium | 0.8% | 7.2 | Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | |
| CVE-2025-15514 | Medium | 0.8% | 7.5 | Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulner… | |
| CVE-2026-50627 | Medium | 0.8% | 9.1 | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) cla… | |
| CVE-2026-66040 | Medium | 0.8% | 8.8 | FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnera… | |
| CVE-2026-66906 | Medium | 0.8% | 9.1 | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. Thi… | |
| CVE-2026-82887 | Medium | 0.8% | 8.8 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute a… | |
| CVE-2023-21806 | Medium | 0.8% | 8.2 | Power BI Report Server Spoofing Vulnerability | |
| CVE-2024-47659 | Medium | 0.8% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: smack: tcp: ipv4, fix… | |
| CVE-2025-22039 | Medium | 0.8% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow i… | |
| CVE-2025-59321 | Medium | 0.8% | 9.8 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy t… | |
| CVE-2026-42944 | Medium | 0.8% | 7.5 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that resu… | |
| CVE-2026-48062 | Medium | 0.8% | 9.8 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validatio… | |
| CVE-2026-54627 | Medium | 0.8% | 9.8 | SAIL is a cross-platform library for loading and saving images with support for animation,… | |
| CVE-2026-55585 | Medium | 0.8% | 8.8 | QWED is open-source AI verification infrastructure for deterministic verification of LLM o… | |
| CVE-2026-65905 | Medium | 0.8% | 9.8 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authentica… | |
| CVE-2026-82447 | Medium | 0.8% | 8.8 | Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that rend… | |
| CVE-2026-86679 | Medium | 0.8% | 7.1 | ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a … | |
| CVE-2026-94184 | Medium | 0.8% | 8.1 | A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A … | |
| CVE-2022-49321 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: xprtrdma: treat all c… | |
| CVE-2023-20244 | Medium | 0.8% | 8.6 | A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) … | |
| CVE-2026-41446 | Medium | 0.8% | 9.8 | Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclose… | |
| CVE-2026-47430 | Medium | 0.8% | 7.5 | ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field … | |
| CVE-2026-51974 | Medium | 0.8% | 8.8 | An eval() injection vulnerability in the get_list function in modules/meta_parser.py in ll… | |
| CVE-2026-66257 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resou… | |
| CVE-2026-66273 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage type size/count handling to cause excessive a… | |
| CVE-2026-66274 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError po… | |
| CVE-2026-67465 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resou… | |
| CVE-2026-67551 | Medium | 0.8% | 7.5 | pre-authentication attacker could leverage type size/count handling to cause excessive all… | |
| CVE-2026-67552 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError po… | |
| CVE-2026-67588 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resou… | |
| CVE-2026-67589 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage type size/count handling to cause excessive a… | |
| CVE-2026-67590 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError po… | |
| CVE-2026-68060 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage type size/count handling to cause excessive a… | |
| CVE-2026-68073 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError po… | |
| CVE-2026-68074 | Medium | 0.8% | 7.5 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resou… | |
| CVE-2026-75161 | Medium | 0.8% | 8.8 | An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway… | |
| CVE-2026-76221 | Medium | 0.8% | 8.8 | GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name … | |
| CVE-2026-81554 | Medium | 0.8% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to… | |
| CVE-2026-82092 | Medium | 0.8% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to… | |
| CVE-2022-29582 | Medium | 0.8% | 7.0 | In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condit… | |
| CVE-2024-41007 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many r… |