Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-26880 | Medium | 0.7% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: dm: call the resume m… | |
| CVE-2026-28299 | Medium | 0.7% | 8.2 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, whi… | |
| CVE-2026-3245 | Medium | 0.7% | 7.5 | A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead t… | |
| CVE-2026-54653 | Medium | 0.7% | 8.8 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec… | |
| CVE-2026-61466 | Medium | 0.7% | 9.1 | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server acce… | |
| CVE-2026-75031 | Medium | 0.7% | 9.8 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerabili… | |
| CVE-2026-86437 | Medium | 0.7% | 7.2 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpo… | |
| CVE-2026-13439 | Medium | 0.7% | 9.8 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated… | |
| CVE-2026-42535 | Medium | 0.7% | 9.1 | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content a… | |
| CVE-2026-71320 | Medium | 0.7% | 8.1 | Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and … | |
| CVE-2026-81944 | Medium | 0.7% | 7.5 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412… | |
| CVE-2026-93872 | Medium | 0.7% | 7.5 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_clas… | |
| CVE-2026-11420 | Medium | 0.7% | 9.8 | Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Ent… | |
| CVE-2026-53791 | Medium | 0.7% | 9.1 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauth… | |
| CVE-2026-54635 | Medium | 0.7% | 7.5 | pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access … | |
| CVE-2026-61516 | Medium | 0.7% | 9.8 | Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerab… | |
| CVE-2026-1829 | Medium | 0.7% | 8.8 | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code … | |
| CVE-2026-55685 | Medium | 0.7% | 7.5 | React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoin… | |
| CVE-2021-47259 | Medium | 0.7% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: NFS: Fix use-after-fr… | |
| CVE-2025-5635 | Medium | 0.7% | 7.3 | A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerabi… | |
| CVE-2026-42974 | Medium | 0.7% | 8.1 | Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attac… | |
| CVE-2026-42981 | Medium | 0.7% | 8.1 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthoriz… | |
| CVE-2026-42987 | Medium | 0.7% | 8.1 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute c… | |
| CVE-2026-45584 | Medium | 0.7% | 8.1 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execut… | |
| CVE-2026-45599 | Medium | 0.7% | 8.1 | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to ex… | |
| CVE-2026-45635 | Medium | 0.7% | 8.1 | Access of resource using incompatible type ('type confusion') in Universal Plug and Play (… | |
| CVE-2026-50686 | Medium | 0.7% | 8.1 | Access of resource using incompatible type ('type confusion') in Windows OLE allows an una… | |
| CVE-2026-53985 | Medium | 0.7% | 7.5 | Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability … | |
| CVE-2026-5490 | Medium | 0.7% | 8.8 | DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remo… | |
| CVE-2026-62781 | Medium | 0.7% | 8.1 | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code … | |
| CVE-2026-62792 | Medium | 0.7% | 8.1 | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute c… | |
| CVE-2026-62819 | Medium | 0.7% | 8.1 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker … | |
| CVE-2026-62889 | Medium | 0.7% | 8.1 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized atta… | |
| CVE-2026-65679 | Medium | 0.7% | 8.1 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker… | |
| CVE-2026-65789 | Medium | 0.7% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a netwo… | |
| CVE-2026-65796 | Medium | 0.7% | 8.1 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker… | |
| CVE-2026-67378 | Medium | 0.7% | 9.0 | Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute cod… | |
| CVE-2026-67636 | Medium | 0.7% | 9.0 | Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a ne… | |
| CVE-2026-69510 | Medium | 0.7% | 8.1 | Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to exec… | |
| CVE-2026-69620 | Medium | 0.7% | 8.1 | Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to exec… | |
| CVE-2026-69732 | Medium | 0.7% | 8.1 | Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an una… | |
| CVE-2026-69786 | Medium | 0.7% | 8.1 | Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to exec… | |
| CVE-2026-69813 | Medium | 0.7% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a netwo… | |
| CVE-2026-69858 | Medium | 0.7% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a netwo… | |
| CVE-2026-69989 | Medium | 0.7% | 8.1 | Use after free in DNS Server allows an unauthorized attacker to execute code over a networ… | |
| CVE-2026-70342 | Medium | 0.7% | 8.1 | Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized att… | |
| CVE-2026-71331 | Medium | 0.7% | 8.1 | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauth… | |
| CVE-2026-71470 | Medium | 0.7% | 9.1 | A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, s… | |
| CVE-2026-72868 | Medium | 0.7% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokp… | |
| CVE-2026-72876 | Medium | 0.7% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.get… |