Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-16239 | Medium | 0.7% | 8.8 | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary … | |
| CVE-2026-44092 | Medium | 0.7% | 9.1 | An unauthenticated remote attacker can inject malicious input into the ModbusServer applic… | |
| CVE-2026-45631 | Medium | 0.7% | 10.0 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.… | |
| CVE-2026-63376 | Medium | 0.7% | 8.2 | toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in li… | |
| CVE-2026-71911 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan func… | |
| CVE-2026-71912 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest … | |
| CVE-2026-71934 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtra… | |
| CVE-2026-71935 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBack… | |
| CVE-2026-71936 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysrebo… | |
| CVE-2026-71937 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_sch… | |
| CVE-2026-71938 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_… | |
| CVE-2026-71939 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_gen… | |
| CVE-2026-71940 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_gen… | |
| CVE-2026-71941 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_lo… | |
| CVE-2026-71942 | Medium | 0.7% | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_ma… | |
| CVE-2026-71962 | Medium | 0.7% | 7.5 | Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the … | |
| CVE-2026-86678 | Medium | 0.7% | 8.8 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privile… | |
| CVE-2026-27690 | Medium | 0.7% | 9.1 | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attack… | |
| CVE-2026-50561 | Medium | 0.7% | 9.4 | Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent developme… | |
| CVE-2026-63041 | Medium | 0.7% | 8.8 | Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This … | |
| CVE-2026-68079 | Medium | 0.7% | 9.8 | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be re… | |
| CVE-2026-71289 | Medium | 0.7% | 9.8 | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's de… | |
| CVE-2026-84202 | Medium | 0.7% | 8.8 | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing a… | |
| CVE-2026-86683 | Medium | 0.7% | 8.1 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privile… | |
| CVE-2021-47478 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bou… | |
| CVE-2026-31847 | Medium | 0.7% | 8.8 | Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ fi… | |
| CVE-2026-40376 | Medium | 0.7% | 7.5 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate… | |
| CVE-2026-54593 | Medium | 0.7% | 8.1 | Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.… | |
| CVE-2026-59134 | Medium | 0.7% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to exe… | |
| CVE-2026-61363 | Medium | 0.7% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to exe… | |
| CVE-2026-68500 | Medium | 0.7% | 7.5 | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to… | |
| CVE-2026-9213 | Medium | 0.7% | 8.1 | A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability t… | |
| CVE-2026-93452 | Medium | 0.7% | 7.5 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(B… | |
| CVE-2024-56645 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_ses… | |
| CVE-2026-11325 | Medium | 0.7% | 8.8 | Description Cloudflare was recently notified by external researchers of vulnerabilities… | |
| CVE-2026-14974 | Medium | 0.7% | 8.1 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to… | |
| CVE-2026-41699 | Medium | 0.7% | 8.1 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing p… | |
| CVE-2026-43769 | Medium | 0.7% | 9.8 | An integer overflow was addressed with improved input validation. This issue is fixed in i… | |
| CVE-2026-52726 | Medium | 0.7% | 7.5 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in… | |
| CVE-2026-64194 | Medium | 0.7% | 7.5 | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression p… | |
| CVE-2026-64394 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: add a WRITE_DA… | |
| CVE-2026-68155 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monma… | |
| CVE-2026-84561 | Medium | 0.7% | 9.8 | A double free issue was addressed with improved memory management. This issue is fixed in … | |
| CVE-2026-93752 | Medium | 0.7% | 7.5 | CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setP… | |
| CVE-2023-52441 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bou… | |
| CVE-2024-26665 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of b… | |
| CVE-2024-47739 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: padata: use integer w… | |
| CVE-2026-32646 | Medium | 0.7% | 7.5 | A specific administrative endpoint is accessible without proper authentication, exposing d… | |
| CVE-2026-33414 | Medium | 0.7% | 7.8 | Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contai… | |
| CVE-2026-35082 | Medium | 0.7% | 8.8 | The ugw-logread method allows a remote attacker with user privileges to access arbitrary l… |