Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-68763 | Medium | 0.7% | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in… | |
| CVE-2026-68981 | Medium | 0.7% | 7.5 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application RE… | |
| CVE-2026-71257 | Medium | 0.7% | 7.5 | Apache Wicket enforces the upload limits configured on a form or upload field while parsin… | |
| CVE-2026-71625 | Medium | 0.7% | 9.8 | An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges v… | |
| CVE-2026-7251 | Medium | 0.7% | 9.8 | Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a rem… | |
| CVE-2026-73483 | Medium | 0.7% | 8.8 | Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox e… | |
| CVE-2026-75005 | Medium | 0.7% | 7.5 | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small reques… | |
| CVE-2026-86542 | Medium | 0.7% | 9.1 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthe… | |
| CVE-2026-91752 | Medium | 0.7% | 7.5 | GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the p… | |
| CVE-2026-93687 | Medium | 0.7% | 7.5 | braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers … | |
| CVE-2024-26800 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-fr… | |
| CVE-2026-47867 | Medium | 0.7% | 8.7 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user … | |
| CVE-2026-47869 | Medium | 0.7% | 8.7 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authe… | |
| CVE-2026-5057 | Medium | 0.7% | 7.5 | ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulne… | |
| CVE-2026-82278 | Medium | 0.7% | 8.8 | BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_on… | |
| CVE-2021-47162 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tipc: skb_linearize t… | |
| CVE-2026-64530 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: H… | |
| CVE-2026-64535 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potent… | |
| CVE-2026-65637 | Medium | 0.7% | 9.8 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-202… | |
| CVE-2026-68136 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double … | |
| CVE-2026-70009 | Medium | 0.7% | 9.3 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Ar… | |
| CVE-2026-71300 | Medium | 0.7% | 9.8 | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. … | |
| CVE-2026-72065 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate t… | |
| CVE-2026-72069 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the i… | |
| CVE-2026-72191 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ntfs3: validate split… | |
| CVE-2026-72192 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ntfs3: bound to_move … | |
| CVE-2026-72466 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix bcall r… | |
| CVE-2026-74376 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: md/raid10: reset read… | |
| CVE-2026-74616 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones th… | |
| CVE-2026-78329 | Medium | 0.7% | 9.8 | Improper input validation vulnerability in Apache Camel Undertow component. This issue … | |
| CVE-2026-80609 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-boun… | |
| CVE-2026-89533 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix offset a… | |
| CVE-2026-89653 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ceph: reject export_t… | |
| CVE-2023-21805 | Medium | 0.7% | 7.8 | Windows MSHTML Platform Remote Code Execution Vulnerability | |
| CVE-2023-29539 | Medium | 0.7% | 8.8 | When handling the filename directive in the Content-Disposition header, the filename would… | |
| CVE-2024-44984 | Medium | 0.7% | 10.0 | In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix double D… | |
| CVE-2026-44209 | Medium | 0.7% | 7.5 | Banks generates meaningful LLM prompts using a template language that makes sense. Prior t… | |
| CVE-2026-63720 | Medium | 0.7% | 7.5 | datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability t… | |
| CVE-2026-67863 | Medium | 0.7% | 7.5 | In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callbac… | |
| CVE-2026-71469 | Medium | 0.7% | 7.5 | A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending… | |
| CVE-2026-85124 | Medium | 0.7% | 7.5 | @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for … | |
| CVE-2026-9190 | Medium | 0.7% | 9.1 | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Serve… | |
| CVE-2019-25765 | Medium | 0.7% | 7.5 | ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows… | |
| CVE-2021-46999 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update … | |
| CVE-2024-40937 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: gve: Clear napi->skb … | |
| CVE-2025-5331 | Medium | 0.7% | 7.3 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This … | |
| CVE-2026-10595 | Medium | 0.7% | 7.5 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in th… | |
| CVE-2026-23813 | Medium | 0.7% | 9.8 | A vulnerability has been identified in the web-based management interface of AOS-CX switch… | |
| CVE-2026-35561 | Medium | 0.7% | 7.4 | Insufficient authentication security controls in the browser-based authentication componen… | |
| CVE-2026-43807 | Medium | 0.7% | 9.8 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS … |