Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69625 | Medium | 0.8% | 8.0 | Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an a… | |
| CVE-2026-69643 | Medium | 0.8% | 8.0 | Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to eleva… | |
| CVE-2026-69681 | Medium | 0.8% | 8.0 | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized… | |
| CVE-2026-69689 | Medium | 0.8% | 8.0 | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges o… | |
| CVE-2026-69714 | Medium | 0.8% | 8.0 | Stack-based buffer overflow in Windows Device Association Service allows an authorized att… | |
| CVE-2026-69717 | Medium | 0.8% | 8.0 | Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to ele… | |
| CVE-2026-69727 | Medium | 0.8% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to e… | |
| CVE-2026-69762 | Medium | 0.8% | 8.0 | Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate pri… | |
| CVE-2026-69773 | Medium | 0.8% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to e… | |
| CVE-2026-69826 | Medium | 0.8% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to e… | |
| CVE-2026-69875 | Medium | 0.8% | 8.0 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privil… | |
| CVE-2026-86541 | Medium | 0.8% | 8.3 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeRepl… | |
| CVE-2026-65321 | Medium | 0.8% | 9.8 | PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticate… | |
| CVE-2026-71560 | Medium | 0.8% | 9.1 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects A… | |
| CVE-2026-79395 | Medium | 0.8% | 9.8 | An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verificat… | |
| CVE-2026-82617 | Medium | 0.8% | 9.8 | The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFac… | |
| CVE-2026-15996 | Medium | 0.8% | 7.5 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed … | |
| CVE-2026-43750 | Medium | 0.8% | 9.8 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macO… | |
| CVE-2026-4946 | Medium | 0.8% | 8.8 | Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in autom… | |
| CVE-2026-73108 | Medium | 0.8% | 7.5 | RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulne… | |
| CVE-2026-78239 | Medium | 0.8% | 9.8 | Xiiaozet LK100W exposes a critical management function that can be invoked without authen… | |
| CVE-2026-85442 | Medium | 0.8% | 7.5 | MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt… | |
| CVE-2026-19901 | Medium | 0.8% | 8.1 | A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unkn… | |
| CVE-2026-30278 | Medium | 0.8% | 9.8 | An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows … | |
| CVE-2026-46412 | Medium | 0.8% | 10.0 | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Serve… | |
| CVE-2026-6321 | Medium | 0.8% | 7.5 | fast-uri decoded percent-encoded path separators and dot segments before applying dot-segm… | |
| CVE-2026-72398 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: sctp: add INIT verifi… | |
| CVE-2026-90945 | Medium | 0.8% | 9.8 | Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cann… | |
| CVE-2026-9397 | Medium | 0.8% | 8.1 | A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected … | |
| CVE-2023-21822 | Medium | 0.8% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2026-24217 | Medium | 0.8% | 8.8 | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path tra… | |
| CVE-2026-44579 | Medium | 0.8% | 7.5 | Next.js is a React framework for building full-stack web applications. From to before 15.… | |
| CVE-2026-48834 | Medium | 0.8% | 7.5 | Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This … | |
| CVE-2026-66012 | Medium | 0.8% | 10.0 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kerne… | |
| CVE-2021-26901 | Medium | 0.8% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2026-41084 | Medium | 0.8% | 7.5 | A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dag… | |
| CVE-2026-67595 | Medium | 0.8% | 8.1 | VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload emb… | |
| CVE-2026-75482 | Medium | 0.8% | 7.5 | SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP ser… | |
| CVE-2024-38243 | Medium | 0.8% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2026-41862 | Medium | 0.8% | 8.8 | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) … | |
| CVE-2026-61701 | Medium | 0.8% | 8.8 | Laravel MagicLink creates links for authentication without a password or for accessing pri… | |
| CVE-2026-68096 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive … | |
| CVE-2026-89696 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEF… | |
| CVE-2023-3640 | Medium | 0.8% | 7.0 | A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area … | |
| CVE-2026-14946 | Medium | 0.8% | 7.2 | A high privileged remote attacker can upload a .php file and then request it directly from… | |
| CVE-2026-3418 | Medium | 0.8% | 9.1 | The System REST API accepts user-supplied file uploads without enforcing sufficient valida… | |
| CVE-2026-44573 | Medium | 0.8% | 7.5 | Next.js is a React framework for building full-stack web applications. From 12.2.0 to befo… | |
| CVE-2026-44575 | Medium | 0.8% | 7.5 | Next.js is a React framework for building full-stack web applications. From 15.2.0 to befo… | |
| CVE-2026-45109 | Medium | 0.8% | 7.5 | Next.js is a React framework for building full-stack web applications. From 15.2.0 to befo… | |
| CVE-2026-53176 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject logi… |