Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-43692 | Medium | 0.7% | 8.8 | A validation issue was addressed with improved input sanitization. This issue is fixed in … | |
| CVE-2026-68157 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: libceph: guard missin… | |
| CVE-2024-38046 | Medium | 0.7% | 7.8 | PowerShell Elevation of Privilege Vulnerability | |
| CVE-2024-38247 | Medium | 0.7% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2026-20837 | Medium | 0.7% | 7.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute cod… | |
| CVE-2026-25879 | Medium | 0.7% | 9.8 | Langroid is a framework for building large-language-model-powered applications. Prior to v… | |
| CVE-2026-30117 | Medium | 0.7% | 9.8 | scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in t… | |
| CVE-2026-36433 | Medium | 0.7% | 9.8 | An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a phy… | |
| CVE-2026-44990 | Medium | 0.7% | 9.3 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provi… | |
| CVE-2026-61962 | Medium | 0.7% | 10.0 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | |
| CVE-2026-65701 | Medium | 0.7% | 9.1 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vuln… | |
| CVE-2026-66033 | Medium | 0.7% | 7.5 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer und… | |
| CVE-2026-75334 | Medium | 0.7% | 9.8 | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execu… | |
| CVE-2026-79574 | Medium | 0.7% | 9.8 | An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code … | |
| CVE-2026-82340 | Medium | 0.7% | 9.8 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserializatio… | |
| CVE-2026-85667 | Medium | 0.7% | 9.1 | xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook… | |
| CVE-2024-56644 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net/ipv6: release exp… | |
| CVE-2026-20340 | Medium | 0.7% | 8.8 | A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker… | |
| CVE-2026-28326 | Medium | 0.7% | 8.8 | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote … | |
| CVE-2026-56817 | Medium | 0.7% | 9.8 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-62911 | Medium | 0.7% | 8.0 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized … | |
| CVE-2026-64303 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: termi… | |
| CVE-2026-65591 | Medium | 0.7% | 8.8 | n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's compute… | |
| CVE-2026-68156 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth… | |
| CVE-2021-26870 | Medium | 0.7% | 7.8 | Windows Projected File System Elevation of Privilege Vulnerability | |
| CVE-2021-26872 | Medium | 0.7% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2021-26880 | Medium | 0.7% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2022-49194 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Use st… | |
| CVE-2022-49664 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: tipc: move bc link cr… | |
| CVE-2023-20083 | Medium | 0.7% | 8.6 | A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for… | |
| CVE-2023-38170 | Medium | 0.7% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2025-66455 | Medium | 0.7% | 9.8 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Start… | |
| CVE-2025-68206 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: ad… | |
| CVE-2025-68349 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS… | |
| CVE-2026-14494 | Medium | 0.7% | 9.8 | The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all ver… | |
| CVE-2026-5616 | Medium | 0.7% | 7.3 | A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element … | |
| CVE-2026-65595 | Medium | 0.7% | 8.8 | n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the … | |
| CVE-2026-71324 | Medium | 0.7% | 9.1 | Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, … | |
| CVE-2026-81202 | Medium | 0.7% | 7.3 | A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the func… | |
| CVE-2026-82428 | Medium | 0.7% | 8.8 | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under … | |
| CVE-2026-84423 | Medium | 0.7% | 7.3 | A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of… | |
| CVE-2026-85452 | Medium | 0.7% | 8.8 | MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp … | |
| CVE-2026-90524 | Medium | 0.7% | 7.3 | A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 2299… | |
| CVE-2026-90601 | Medium | 0.7% | 7.3 | A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function… | |
| CVE-2021-34514 | Medium | 0.7% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2022-49048 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix panic when … | |
| CVE-2026-18265 | Medium | 0.7% | 9.8 | OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulner… | |
| CVE-2026-47623 | Medium | 0.7% | 8.2 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserializa… | |
| CVE-2026-5676 | Medium | 0.7% | 7.3 | A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects t… | |
| CVE-2026-57817 | Medium | 0.7% | 8.1 | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` … |