Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-6664 | Medium | 0.7% | 7.5 | An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a b… | |
| CVE-2022-41092 | Medium | 0.7% | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2026-17182 | Medium | 0.7% | 9.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authenticat… | |
| CVE-2026-44891 | Medium | 0.7% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-45799 | Medium | 0.7% | 7.5 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3… | |
| CVE-2026-72970 | Medium | 0.7% | 8.3 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attac… | |
| CVE-2026-82000 | Medium | 0.7% | 9.6 | Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vul… | |
| CVE-2024-47696 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix WARNIN… | |
| CVE-2026-25776 | Medium | 0.7% | 9.8 | Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may … | |
| CVE-2026-47984 | Medium | 0.7% | 8.2 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result i… | |
| CVE-2026-64834 | Medium | 0.7% | 7.5 | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF … | |
| CVE-2026-72824 | Medium | 0.7% | 8.8 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap … | |
| CVE-2026-81098 | Medium | 0.7% | 9.1 | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a … | |
| CVE-2026-92229 | Medium | 0.7% | 9.1 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for Wor… | |
| CVE-2021-29993 | Medium | 0.7% | 8.1 | Firefox for Android allowed navigations through the `intent://` protocol, which could be u… | |
| CVE-2026-15734 | Medium | 0.7% | 9.8 | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and ear… | |
| CVE-2026-16770 | Medium | 0.7% | 9.8 | PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via me… | |
| CVE-2026-30631 | Medium | 0.7% | 9.8 | An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (… | |
| CVE-2026-52656 | Medium | 0.7% | 9.8 | An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based… | |
| CVE-2026-53545 | Medium | 0.7% | 9.8 | Termix is a web-based server management platform with SSH terminal, tunneling, and file ed… | |
| CVE-2026-53984 | Medium | 0.7% | 9.1 | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitra… | |
| CVE-2026-55546 | Medium | 0.7% | 9.8 | QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expr… | |
| CVE-2026-67873 | Medium | 0.7% | 9.8 | A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASD… | |
| CVE-2026-67960 | Medium | 0.7% | 9.8 | An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberC… | |
| CVE-2026-73211 | Medium | 0.7% | 9.8 | PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollow… | |
| CVE-2026-73649 | Medium | 0.7% | 9.8 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior t… | |
| CVE-2026-73849 | Medium | 0.7% | 9.8 | Emlog is an open source website building system. In 2.6.26 and earlier, install.php accept… | |
| CVE-2026-84372 | Medium | 0.7% | 9.8 | Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.… | |
| CVE-2026-93603 | Medium | 0.7% | 10.0 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver i… | |
| CVE-2026-93605 | Medium | 0.7% | 10.0 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGERO… | |
| CVE-2023-52741 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: cifs: Fix use-after-f… | |
| CVE-2026-14328 | Medium | 0.7% | 8.8 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for Wor… | |
| CVE-2026-16796 | Medium | 0.7% | 7.3 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bed… | |
| CVE-2026-34045 | Medium | 0.7% | 8.2 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1… | |
| CVE-2026-34645 | Medium | 0.7% | 7.5 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-34646 | Medium | 0.7% | 7.5 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-34877 | Medium | 0.7% | 9.8 | An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insu… | |
| CVE-2026-78030 | Medium | 0.7% | 9.8 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm… | |
| CVE-2026-93088 | Medium | 0.7% | 9.8 | SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code exe… | |
| CVE-2024-26877 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx - call… | |
| CVE-2024-42247 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips… | |
| CVE-2026-13383 | Medium | 0.7% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allo… | |
| CVE-2026-13384 | Medium | 0.7% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow… | |
| CVE-2026-15686 | Medium | 0.7% | 7.2 | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnera… | |
| CVE-2026-5584 | Medium | 0.7% | 7.3 | A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInt… | |
| CVE-2026-81236 | Medium | 0.7% | 8.6 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload… | |
| CVE-2026-81239 | Medium | 0.7% | 8.6 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload… | |
| CVE-2026-81240 | Medium | 0.7% | 8.6 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload… | |
| CVE-2024-26736 | Medium | 0.7% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer … | |
| CVE-2026-50112 | Medium | 0.7% | 8.8 | SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template … |