Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-53705 | Medium | 0.7% | 7.6 | A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing… | |
| CVE-2026-5569 | Medium | 0.7% | 7.3 | A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an … | |
| CVE-2026-5573 | Medium | 0.7% | 7.3 | A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impac… | |
| CVE-2026-58186 | Medium | 0.7% | 7.5 | The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, … | |
| CVE-2026-64612 | Medium | 0.7% | 7.5 | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function create… | |
| CVE-2026-69380 | Medium | 0.7% | 8.1 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevat… | |
| CVE-2026-8457 | Medium | 0.7% | 9.8 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass… | |
| CVE-2026-85663 | Medium | 0.7% | 9.8 | Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary … | |
| CVE-2026-92971 | Medium | 0.7% | 7.5 | InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistS… | |
| CVE-2022-48686 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF whe… | |
| CVE-2026-46266 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets usi… | |
| CVE-2026-63765 | Medium | 0.7% | 8.2 | Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploa… | |
| CVE-2026-64393 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info w… | |
| CVE-2026-68457 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener cre… | |
| CVE-2021-44733 | Medium | 0.7% | 7.0 | A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel … | |
| CVE-2023-29536 | Medium | 0.7% | 8.8 | An attacker could cause the memory manager to incorrectly free a pointer that addresses at… | |
| CVE-2023-29550 | Medium | 0.7% | 8.8 | Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed… | |
| CVE-2025-68700 | Medium | 0.7% | 8.8 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior t… | |
| CVE-2026-22016 | Medium | 0.7% | 7.5 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edi… | |
| CVE-2026-40542 | Medium | 0.7% | 7.3 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cau… | |
| CVE-2026-45777 | Medium | 0.7% | 9.8 | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in versi… | |
| CVE-2026-51346 | Medium | 0.7% | 9.1 | SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a … | |
| CVE-2026-64257 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject o… | |
| CVE-2026-66902 | Medium | 0.7% | 9.8 | Google::Auth versions before 0.06 for Perl run a command named in an external_account cred… | |
| CVE-2026-67289 | Medium | 0.7% | 9.8 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control cha… | |
| CVE-2026-68343 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate… | |
| CVE-2026-72098 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer… | |
| CVE-2026-73639 | Medium | 0.7% | 9.1 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row … | |
| CVE-2026-74476 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: veth: convert frag_li… | |
| CVE-2026-75143 | Medium | 0.7% | 9.8 | FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (… | |
| CVE-2026-80617 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_… | |
| CVE-2026-89036 | Medium | 0.7% | 8.8 | Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticat… | |
| CVE-2026-89634 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix ALIG… | |
| CVE-2026-33211 | Medium | 0.7% | 9.6 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines.… | |
| CVE-2026-50369 | Medium | 0.7% | 8.8 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate… | |
| CVE-2026-53790 | Medium | 0.7% | 8.1 | rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that a… | |
| CVE-2026-64397 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUER… | |
| CVE-2026-68302 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb head… | |
| CVE-2026-7383 | Medium | 0.7% | 8.1 | Issue summary: A signed integer overflow when sizing the destination buffer for Unicode ou… | |
| CVE-2026-74608 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-… | |
| CVE-2026-74743 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit need… | |
| CVE-2026-74744 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit neede… | |
| CVE-2026-80589 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: block: stop the timeo… | |
| CVE-2026-89636 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: clear ce… | |
| CVE-2021-26426 | Medium | 0.7% | 7.0 | Windows User Account Profile Picture Elevation of Privilege Vulnerability | |
| CVE-2026-18608 | Medium | 0.7% | 8.7 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole… | |
| CVE-2026-33079 | Medium | 0.7% | 7.5 | In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial … | |
| CVE-2026-35425 | Medium | 0.7% | 8.0 | Improper access control in Azure API Management (APIM) allows an authorized attacker to ex… | |
| CVE-2026-42245 | Medium | 0.7% | 7.5 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby.… | |
| CVE-2026-45768 | Medium | 0.7% | 7.5 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network … |