Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72936 | Medium | 0.7% | 8.1 | Use after free in Windows SMB Client allows an unauthorized attacker to execute code over … | |
| CVE-2026-72981 | Medium | 0.7% | 8.1 | Use after free in IP Helper allows an unauthorized attacker to execute code over a network… | |
| CVE-2026-72987 | Medium | 0.7% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a netwo… | |
| CVE-2026-75124 | Medium | 0.7% | 7.5 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-authentication memory … | |
| CVE-2026-77264 | Medium | 0.7% | 9.8 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code… | |
| CVE-2026-78002 | Medium | 0.7% | 7.5 | A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer … | |
| CVE-2026-78444 | Medium | 0.7% | 8.1 | Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker … | |
| CVE-2026-78449 | Medium | 0.7% | 8.1 | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized atta… | |
| CVE-2026-78450 | Medium | 0.7% | 8.1 | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized atta… | |
| CVE-2026-82526 | Medium | 0.7% | 9.8 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticat… | |
| CVE-2026-83997 | Medium | 0.7% | 8.1 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code … | |
| CVE-2026-85610 | Medium | 0.7% | 8.8 | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing auth… | |
| CVE-2026-86730 | Medium | 0.7% | 8.8 | Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout eleme… | |
| CVE-2026-9141 | Medium | 0.7% | 9.8 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vul… | |
| CVE-2023-29534 | Medium | 0.7% | 9.1 | Different techniques existed to obscure the fullscreen notification in Firefox and Focus f… | |
| CVE-2024-44986 | Medium | 0.7% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UA… | |
| CVE-2026-15271 | Medium | 0.7% | 7.5 | A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10,… | |
| CVE-2026-20479 | Medium | 0.7% | 7.5 | In Modem, there is a possible out of bounds read due to a missing bounds check. This could… | |
| CVE-2026-21548 | Medium | 0.7% | 7.5 | In nr modem, there is a possible improper input validation. This could lead to remote deni… | |
| CVE-2026-21549 | Medium | 0.7% | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial … | |
| CVE-2026-21550 | Medium | 0.7% | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial … | |
| CVE-2026-21551 | Medium | 0.7% | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial … | |
| CVE-2026-21552 | Medium | 0.7% | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial … | |
| CVE-2026-21553 | Medium | 0.7% | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial … | |
| CVE-2026-21554 | Medium | 0.7% | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial … | |
| CVE-2026-21555 | Medium | 0.7% | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial … | |
| CVE-2026-25048 | Medium | 0.7% | 7.5 | xgrammar is an open-source library for efficient, flexible, and portable structured genera… | |
| CVE-2026-29008 | Medium | 0.7% | 7.5 | U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state… | |
| CVE-2026-33236 | Medium | 0.7% | 8.1 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and t… | |
| CVE-2026-44017 | Medium | 0.7% | 7.5 | Docling simplifies document processing by parsing diverse formats and providing integratio… | |
| CVE-2026-54368 | Medium | 0.7% | 8.8 | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() a… | |
| CVE-2026-71207 | Medium | 0.7% | 9.8 | The Stock-Inventory-Management-System application's login.php assigns raw username/passwor… | |
| CVE-2026-81690 | Medium | 0.7% | 7.3 | openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify… | |
| CVE-2024-21489 | Medium | 0.7% | 8.2 | Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the … | |
| CVE-2025-31098 | Medium | 0.7% | 7.5 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote Fil… | |
| CVE-2025-50327 | Medium | 0.7% | 8.8 | An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escala… | |
| CVE-2025-70151 | Medium | 0.7% | 8.8 | code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve rem… | |
| CVE-2026-45742 | Medium | 0.7% | 7.5 | Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the n… | |
| CVE-2026-64142 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable … | |
| CVE-2026-72526 | Medium | 0.7% | 9.9 | A flaw was found in the multicloud-integrations component. The Application propagation con… | |
| CVE-2026-75021 | Medium | 0.7% | 8.1 | fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the exp… | |
| CVE-2026-75983 | Medium | 0.7% | 7.5 | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for Word… | |
| CVE-2026-81475 | Medium | 0.7% | 8.1 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authe… | |
| CVE-2026-85181 | Medium | 0.7% | 9.8 | CAT uses Java String.hashCode as the sole integrity check for session cookies without serv… | |
| CVE-2026-88273 | Medium | 0.7% | 7.2 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a s… | |
| CVE-2026-88274 | Medium | 0.7% | 7.2 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing she… | |
| CVE-2026-88275 | Medium | 0.7% | 7.2 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syn… | |
| CVE-2026-88276 | Medium | 0.7% | 7.2 | GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell… | |
| CVE-2026-32280 | Medium | 0.7% | 7.5 | During chain building, the amount of work that is done is not correctly limited when a lar… | |
| CVE-2026-45445 | Medium | 0.7% | 7.5 | Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher… |