Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-58374 | Medium | 0.7% | 7.5 | Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree … | |
| CVE-2026-15711 | Medium | 0.7% | 7.5 | A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library… | |
| CVE-2026-41871 | Medium | 0.7% | 9.8 | Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsa… | |
| CVE-2026-44901 | Medium | 0.7% | 8.4 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-5708 | Medium | 0.7% | 8.8 | Unsanitized control of user-modifiable attributes in the session creation component in AWS… | |
| CVE-2026-66046 | Medium | 0.7% | 7.5 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorit… | |
| CVE-2026-68159 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{te… | |
| CVE-2021-47131 | Medium | 0.7% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix use-afte… | |
| CVE-2026-27243 | Medium | 0.7% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Sc… | |
| CVE-2026-27245 | Medium | 0.7% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Sc… | |
| CVE-2026-27246 | Medium | 0.7% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Sc… | |
| CVE-2026-34691 | Medium | 0.7% | 9.3 | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by … | |
| CVE-2026-45721 | Medium | 0.7% | 9.0 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is a… | |
| CVE-2026-75166 | Medium | 0.7% | 8.8 | Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allow… | |
| CVE-2026-76200 | Medium | 0.7% | 9.3 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could… | |
| CVE-2026-76201 | Medium | 0.7% | 9.3 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could… | |
| CVE-2026-79393 | Medium | 0.7% | 7.5 | A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation func… | |
| CVE-2021-47001 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix cwnd up… | |
| CVE-2023-29541 | Medium | 0.7% | 8.8 | Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which … | |
| CVE-2026-16137 | Medium | 0.7% | 7.2 | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone … | |
| CVE-2026-31842 | Medium | 0.7% | 7.5 | Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a … | |
| CVE-2026-72602 | Medium | 0.7% | 7.5 | A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows … | |
| CVE-2026-8135 | Medium | 0.7% | 7.2 | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deser… | |
| CVE-2026-14266 | Medium | 0.7% | 7.8 | 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. Thi… | |
| CVE-2026-50076 | Medium | 0.7% | 9.1 | Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-cor… | |
| CVE-2026-50340 | Medium | 0.7% | 8.5 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges over… | |
| CVE-2026-50500 | Medium | 0.7% | 7.5 | Use after free in Windows Netlogon allows an authorized attacker to elevate privileges ove… | |
| CVE-2026-50505 | Medium | 0.7% | 7.5 | Use after free in Windows Message Queuing allows an authorized attacker to execute code ov… | |
| CVE-2026-62317 | Medium | 0.7% | 7.5 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0… | |
| CVE-2026-69419 | Medium | 0.7% | 8.5 | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attac… | |
| CVE-2026-71321 | Medium | 0.7% | 7.5 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and … | |
| CVE-2026-72818 | Medium | 0.7% | 7.5 | The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_… | |
| CVE-2026-72830 | Medium | 0.7% | 8.8 | Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigControl… | |
| CVE-2026-83599 | Medium | 0.7% | 7.5 | Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated W… | |
| CVE-2026-85449 | Medium | 0.7% | 7.5 | MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities… | |
| CVE-2025-37871 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nfsd: decrease sc_cou… | |
| CVE-2026-61609 | Medium | 0.7% | 7.5 | Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, … | |
| CVE-2021-46955 | Medium | 0.7% | 8.2 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stac… | |
| CVE-2023-21718 | Medium | 0.7% | 7.8 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| CVE-2024-50095 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Improve han… | |
| CVE-2026-29009 | Medium | 0.7% | 8.2 | U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply()… | |
| CVE-2026-37106 | Medium | 0.7% | 9.8 | An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an ac… | |
| CVE-2026-42294 | Medium | 0.7% | 7.5 | Argo Workflows is an open source container-native workflow engine for orchestrating parall… | |
| CVE-2026-50645 | Medium | 0.7% | 7.5 | There is no restriction on the amount of attachment headers that a message can contain whe… | |
| CVE-2026-59173 | Medium | 0.7% | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affe… | |
| CVE-2026-65927 | Medium | 0.7% | 7.5 | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valv… | |
| CVE-2026-66142 | Medium | 0.7% | 7.5 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack poli… | |
| CVE-2026-66144 | Medium | 0.7% | 7.5 | Although remote policy references are not retrieved during policy normalization, if they a… | |
| CVE-2026-67211 | Medium | 0.7% | 7.5 | OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializ… | |
| CVE-2026-67592 | Medium | 0.7% | 7.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery,… |