Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-89260 | Medium | 0.7% | 7.5 | MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat… | |
| CVE-2026-89479 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing… | |
| CVE-2026-89555 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: mpls: reload header a… | |
| CVE-2026-89662 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent lock ow… | |
| CVE-2026-89669 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy… | |
| CVE-2026-93868 | Medium | 0.7% | 8.1 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in… | |
| CVE-2022-50666 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix QP dest… | |
| CVE-2024-42152 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible… | |
| CVE-2026-16268 | Medium | 0.7% | 8.2 | The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-pr… | |
| CVE-2026-18617 | Medium | 0.7% | 8.8 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exp… | |
| CVE-2026-44293 | Medium | 0.7% | 8.8 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 an… | |
| CVE-2026-54721 | Medium | 0.7% | 8.8 | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0… | |
| CVE-2026-90777 | Medium | 0.7% | 8.8 | ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weigh… | |
| CVE-2026-11974 | Medium | 0.7% | 8.6 | The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied … | |
| CVE-2026-13186 | Medium | 0.7% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in … | |
| CVE-2026-15025 | Medium | 0.7% | 7.5 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin f… | |
| CVE-2026-16616 | Medium | 0.7% | 8.6 | The Simple File List WordPress plugin through 6.3.11 does not validate the source path of … | |
| CVE-2026-40476 | Medium | 0.7% | 7.5 | graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the Overlappi… | |
| CVE-2026-40920 | Medium | 0.7% | 9.8 | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Us… | |
| CVE-2026-41364 | Medium | 0.7% | 8.1 | OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar up… | |
| CVE-2026-54225 | Medium | 0.7% | 7.5 | Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Pr… | |
| CVE-2026-57819 | Medium | 0.7% | 7.5 | Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via … | |
| CVE-2026-74396 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix UMR XL… | |
| CVE-2026-85666 | Medium | 0.7% | 7.5 | OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-… | |
| CVE-2024-20351 | Medium | 0.7% | 8.6 | A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of C… | |
| CVE-2024-40957 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: seg6: fix parameter p… | |
| CVE-2025-34468 | Medium | 0.7% | 9.8 | libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based… | |
| CVE-2026-20274 | Medium | 0.7% | 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco… | |
| CVE-2026-3087 | Medium | 0.7% | 7.5 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containi… | |
| CVE-2026-48749 | Medium | 0.7% | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a special… | |
| CVE-2026-48750 | Medium | 0.7% | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `reco… | |
| CVE-2026-48752 | Medium | 0.7% | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a special… | |
| CVE-2026-48753 | Medium | 0.7% | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 pr… | |
| CVE-2026-48755 | Medium | 0.7% | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper … | |
| CVE-2026-48769 | Medium | 0.7% | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitr… | |
| CVE-2026-58182 | Medium | 0.7% | 8.6 | The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and … | |
| CVE-2026-16985 | Medium | 0.7% | 8.8 | The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension o… | |
| CVE-2026-27648 | Medium | 0.7% | 8.8 | in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in… | |
| CVE-2026-55640 | Medium | 0.7% | 9.1 | Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nex… | |
| CVE-2026-57807 | Medium | 0.7% | 9.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Secur… | |
| CVE-2026-73634 | Medium | 0.7% | 7.5 | Uncontrolled resource consumption vulnerability in Apache Struts. An application that expo… | |
| CVE-2026-77018 | Medium | 0.7% | 8.8 | The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candi… | |
| CVE-2026-94493 | Medium | 0.7% | 10.0 | A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects … | |
| CVE-2025-71319 | Medium | 0.7% | 7.5 | image-size through 2.0.2 contains a denial of service vulnerability that allows remote att… | |
| CVE-2026-14456 | Medium | 0.7% | 7.5 | Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Init… | |
| CVE-2026-42354 | Medium | 0.7% | 9.1 | Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to befor… | |
| CVE-2026-61817 | Medium | 0.7% | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior … | |
| CVE-2026-61819 | Medium | 0.7% | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior … | |
| CVE-2026-61820 | Medium | 0.7% | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior … | |
| CVE-2026-64695 | Medium | 0.7% | 9.8 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 … |