Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-26954 | Medium | 0.7% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-o… | |
| CVE-2025-12195 | Medium | 0.7% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authen… | |
| CVE-2026-12000 | Medium | 0.7% | 7.5 | The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information … | |
| CVE-2026-17087 | Medium | 0.7% | 7.5 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress i… | |
| CVE-2026-32829 | Medium | 0.7% | 7.5 | lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.… | |
| CVE-2026-47296 | Medium | 0.7% | 7.5 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… | |
| CVE-2026-69254 | Medium | 0.7% | 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2024-35971 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Handle s… | |
| CVE-2026-28812 | Medium | 0.7% | 9.8 | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may a… | |
| CVE-2026-34884 | Medium | 0.7% | 9.8 | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache … | |
| CVE-2026-58595 | Medium | 0.7% | 8.1 | Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows … | |
| CVE-2026-62183 | Medium | 0.7% | 9.8 | Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user… | |
| CVE-2026-70570 | Medium | 0.7% | 7.5 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker … | |
| CVE-2026-76682 | Medium | 0.7% | 8.2 | A vulnerability in the network security monitoring component of intrusion detection system… | |
| CVE-2026-77109 | Medium | 0.7% | 8.6 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result i… | |
| CVE-2026-86669 | Medium | 0.7% | 7.3 | A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the funct… | |
| CVE-2026-86830 | Medium | 0.7% | 7.2 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM … | |
| CVE-2026-92399 | Medium | 0.7% | 7.3 | A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handl… | |
| CVE-2026-93962 | Medium | 0.7% | 8.3 | A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacte… | |
| CVE-2024-26882 | Medium | 0.7% | 7.3 | In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make … | |
| CVE-2026-14450 | Medium | 0.7% | 9.9 | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to … | |
| CVE-2026-15001 | Medium | 0.7% | 8.8 | The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege… | |
| CVE-2026-18191 | Medium | 0.7% | 9.8 | VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unaut… | |
| CVE-2026-19883 | Medium | 0.7% | 8.8 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modifica… | |
| CVE-2026-52746 | Medium | 0.7% | 7.5 | JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious n… | |
| CVE-2026-56161 | Medium | 0.7% | 9.6 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose info… | |
| CVE-2026-62896 | Medium | 0.7% | 9.6 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privil… | |
| CVE-2026-66792 | Medium | 0.7% | 9.9 | A flaw was found in the multicloud-operators-subscription component. This vulnerability al… | |
| CVE-2026-75596 | Medium | 0.7% | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fin… | |
| CVE-2026-77084 | Medium | 0.7% | 8.8 | n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerabili… | |
| CVE-2026-85607 | Medium | 0.7% | 8.8 | Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC proced… | |
| CVE-2026-8761 | Medium | 0.7% | 8.8 | The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to… | |
| CVE-2024-42256 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-r… | |
| CVE-2025-37879 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper … | |
| CVE-2026-15990 | Medium | 0.7% | 7.5 | The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all ver… | |
| CVE-2026-54670 | Medium | 0.7% | 9.1 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution reque… | |
| CVE-2026-63490 | Medium | 0.7% | 7.5 | Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.… | |
| CVE-2022-49280 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent underfl… | |
| CVE-2023-54219 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: Revert "IB/isert: Fix… | |
| CVE-2024-26881 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel… | |
| CVE-2026-10270 | Medium | 0.7% | 8.8 | A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the func… | |
| CVE-2026-5172 | Medium | 0.7% | 7.3 | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger … | |
| CVE-2026-53510 | Medium | 0.7% | 8.1 | Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpo… | |
| CVE-2026-55642 | Medium | 0.7% | 9.8 | dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middl… | |
| CVE-2026-5588 | Medium | 0.7% | 7.5 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Cas… | |
| CVE-2026-5684 | Medium | 0.7% | 8.0 | A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the f… | |
| CVE-2026-85661 | Medium | 0.7% | 9.8 | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PA… | |
| CVE-2024-35880 | Medium | 0.7% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: hold i… | |
| CVE-2024-35884 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: udp: do not accept no… | |
| CVE-2026-16210 | Medium | 0.7% | 7.3 | A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function sel… |