Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-54135 | Medium | 0.8% | 7.5 | AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. V… | |
| CVE-2026-6100 | Medium | 0.8% | 8.1 | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, a… | |
| CVE-2026-66270 | Medium | 0.8% | 7.2 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Uplo… | |
| CVE-2026-66271 | Medium | 0.8% | 7.2 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Uplo… | |
| CVE-2021-47168 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFS: fix an incorrect… | |
| CVE-2024-42232 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: libceph: fix race bet… | |
| CVE-2026-44486 | Medium | 0.8% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16… | |
| CVE-2026-44487 | Medium | 0.8% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16… | |
| CVE-2026-73683 | Medium | 0.8% | 8.1 | Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that… | |
| CVE-2026-78689 | Medium | 0.8% | 8.1 | Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace pre… | |
| CVE-2021-47328 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix conn… | |
| CVE-2023-36865 | Medium | 0.8% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2023-36866 | Medium | 0.8% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2024-27026 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix missing … | |
| CVE-2024-38238 | Medium | 0.8% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2026-15038 | Medium | 0.8% | 9.8 | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-con… | |
| CVE-2026-15314 | Medium | 0.8% | 7.5 | Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in th… | |
| CVE-2026-40961 | Medium | 0.8% | 7.2 | A bug in the login redirect route in Apache Airflow allowed authenticated users to craft U… | |
| CVE-2026-67856 | Medium | 0.8% | 7.5 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of ser… | |
| CVE-2026-67864 | Medium | 0.8% | 7.5 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of ser… | |
| CVE-2026-67865 | Medium | 0.8% | 7.5 | S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a re… | |
| CVE-2026-67872 | Medium | 0.8% | 7.5 | An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via… | |
| CVE-2026-7319 | Medium | 0.8% | 7.3 | A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the f… | |
| CVE-2026-75439 | Medium | 0.8% | 7.5 | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the … | |
| CVE-2026-87742 | Medium | 0.8% | 7.5 | A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker t… | |
| CVE-2026-93436 | Medium | 0.8% | 7.5 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference… | |
| CVE-2026-12943 | Medium | 0.8% | 9.8 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Mana… | |
| CVE-2026-24425 | Medium | 0.8% | 8.8 | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when … | |
| CVE-2026-34986 | Medium | 0.8% | 7.5 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of … | |
| CVE-2026-47281 | Medium | 0.8% | 9.6 | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate pri… | |
| CVE-2026-59113 | Medium | 0.8% | 8.8 | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute cod… | |
| CVE-2026-78254 | Medium | 0.8% | 7.4 | The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious s… | |
| CVE-2026-78462 | Medium | 0.8% | 8.8 | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthori… | |
| CVE-2026-91863 | Medium | 0.8% | 7.5 | A specially crafted WS-Policy document with deeply nested policy elements can bypass Neeth… | |
| CVE-2024-13784 | Medium | 0.8% | 9.8 | The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vuln… | |
| CVE-2024-40980 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: drop_monitor: replace… | |
| CVE-2024-46737 | Medium | 0.8% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix kernel… | |
| CVE-2024-8676 | Medium | 0.8% | 7.4 | A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive… | |
| CVE-2025-24259 | Medium | 0.8% | 9.8 | This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS… | |
| CVE-2026-14490 | Medium | 0.8% | 7.5 | The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulne… | |
| CVE-2026-17630 | Medium | 0.8% | 7.2 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary c… | |
| CVE-2026-33939 | Medium | 0.8% | 7.5 | Handlebars provides the power necessary to let users build semantic templates. In versions… | |
| CVE-2026-39892 | Medium | 0.8% | 9.8 | cryptography is a package designed to expose cryptographic primitives and recipes to Pytho… | |
| CVE-2026-40092 | Medium | 0.8% | 7.5 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In ver… | |
| CVE-2026-54297 | Medium | 0.8% | 7.5 | Faraday is an HTTP client library abstraction layer that provides a common interface over … | |
| CVE-2026-54612 | Medium | 0.8% | 8.8 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecom… | |
| CVE-2026-7637 | Medium | 0.8% | 9.8 | The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, an… | |
| CVE-2024-38119 | Medium | 0.8% | 7.5 | Windows Network Address Translation (NAT) Remote Code Execution Vulnerability | |
| CVE-2026-20848 | Medium | 0.8% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition'… | |
| CVE-2026-20934 | Medium | 0.8% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race condition'… |