Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-36288 | Medium | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop term… | |
| CVE-2026-11826 | Medium | 0.8% | 8.8 | OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/co… | |
| CVE-2026-15957 | Medium | 0.8% | 7.5 | Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and … | |
| CVE-2026-16756 | Medium | 0.8% | 7.5 | Missing connection and header-read timeouts and the absence of a concurrent-connection cap… | |
| CVE-2026-26035 | Medium | 0.8% | 9.8 | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.… | |
| CVE-2026-37237 | Medium | 0.8% | 7.5 | vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via m… | |
| CVE-2026-46603 | Medium | 0.8% | 7.5 | VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when p… | |
| CVE-2026-51788 | Medium | 0.8% | 7.5 | An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service… | |
| CVE-2026-53503 | Medium | 0.8% | 7.5 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's … | |
| CVE-2026-54159 | Medium | 0.8% | 10.0 | PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 u… | |
| CVE-2026-54417 | Medium | 0.8% | 7.5 | An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allo… | |
| CVE-2026-55108 | Medium | 0.8% | 8.5 | KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alp… | |
| CVE-2026-67861 | Medium | 0.8% | 7.5 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of ser… | |
| CVE-2026-70453 | Medium | 0.8% | 7.5 | rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() f… | |
| CVE-2026-75140 | Medium | 0.8% | 7.5 | jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumpti… | |
| CVE-2025-54603 | Medium | 0.7% | 9.0 | An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can res… | |
| CVE-2026-0551 | Medium | 0.7% | 8.8 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injecti… | |
| CVE-2026-17497 | Medium | 0.7% | 8.3 | NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bas… | |
| CVE-2026-74878 | Medium | 0.7% | 9.8 | openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force p… | |
| CVE-2026-76404 | Medium | 0.7% | 9.1 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role co… | |
| CVE-2026-93567 | Medium | 0.7% | 7.5 | A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/… | |
| CVE-2024-26828 | Medium | 0.7% | 9.4 | In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow i… | |
| CVE-2024-38605 | Medium | 0.7% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL … | |
| CVE-2026-12932 | Medium | 0.7% | 8.1 | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 an… | |
| CVE-2026-18961 | Medium | 0.7% | 8.1 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect p… | |
| CVE-2026-63359 | Medium | 0.7% | 9.8 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) application… | |
| CVE-2026-64320 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth o… | |
| CVE-2026-71248 | Medium | 0.7% | 9.8 | Inventory-Management-System-PHP's login.php constructs its authentication query via direct… | |
| CVE-2026-76658 | Medium | 0.7% | 10.0 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer th… | |
| CVE-2021-47274 | Medium | 0.7% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the … | |
| CVE-2026-17110 | Medium | 0.7% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitr… | |
| CVE-2026-26135 | Medium | 0.7% | 9.6 | Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows… | |
| CVE-2026-53994 | Medium | 0.7% | 7.5 | ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP … | |
| CVE-2026-56169 | Medium | 0.7% | 8.1 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate p… | |
| CVE-2026-68968 | Medium | 0.7% | 7.5 | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller… | |
| CVE-2026-86775 | Medium | 0.7% | 8.6 | knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Docu… | |
| CVE-2021-47515 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in … | |
| CVE-2024-26584 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net: tls: handle back… | |
| CVE-2026-16674 | Medium | 0.7% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitr… | |
| CVE-2026-16860 | Medium | 0.7% | 9.9 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitr… | |
| CVE-2026-18669 | Medium | 0.7% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a re… | |
| CVE-2026-44090 | Medium | 0.7% | 9.8 | Due to missing authentication, an unauthenticated remote attacker may access the MQTT brok… | |
| CVE-2026-44101 | Medium | 0.7% | 9.8 | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remot… | |
| CVE-2026-44631 | Medium | 0.7% | 9.8 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in th… | |
| CVE-2026-53405 | Medium | 0.7% | 9.8 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administra… | |
| CVE-2026-66756 | Medium | 0.7% | 9.8 | Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Ap… | |
| CVE-2026-75465 | Medium | 0.7% | 7.5 | The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Inco… | |
| CVE-2026-76657 | Medium | 0.7% | 10.0 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that cou… | |
| CVE-2026-7755 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to in… | |
| CVE-2019-25160 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-… |