Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-40165 | Medium | 0.7% | 8.7 | authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions … | |
| CVE-2026-73614 | Medium | 0.7% | 8.8 | Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters be… | |
| CVE-2026-74872 | Medium | 0.7% | 9.8 | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in… | |
| CVE-2026-74895 | Medium | 0.7% | 9.8 | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default pr… | |
| CVE-2026-81939 | Medium | 0.7% | 9.1 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file uplo… | |
| CVE-2026-89274 | Medium | 0.7% | 9.1 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in… | |
| CVE-2026-43112 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix ou… | |
| CVE-2026-44756 | Medium | 0.7% | 10.0 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing li… | |
| CVE-2026-65941 | Medium | 0.7% | 8.8 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with… | |
| CVE-2026-72107 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: dm era: fix out-of-bo… | |
| CVE-2026-72160 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject dinodes… | |
| CVE-2026-75915 | Medium | 0.7% | 7.5 | CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in… | |
| CVE-2026-89493 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate rl_us… | |
| CVE-2026-90823 | Medium | 0.7% | 9.8 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r… | |
| CVE-2022-49356 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Trap RDMA seg… | |
| CVE-2023-52628 | Medium | 0.7% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: … | |
| CVE-2026-24304 | Medium | 0.7% | 9.9 | Improper access control in Azure Resource Manager allows an authorized attacker to elevate… | |
| CVE-2026-44450 | Medium | 0.7% | 9.9 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation … | |
| CVE-2026-49366 | Medium | 0.7% | 7.8 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename com… | |
| CVE-2026-54617 | Medium | 0.7% | 9.8 | GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.… | |
| CVE-2026-55511 | Medium | 0.7% | 9.1 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with… | |
| CVE-2026-82404 | Medium | 0.7% | 8.3 | TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3… | |
| CVE-2021-41372 | Medium | 0.7% | 7.6 | A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists wh… | |
| CVE-2023-52454 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kern… | |
| CVE-2024-38570 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential g… | |
| CVE-2025-15627 | Medium | 0.7% | 7.5 | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on ha… | |
| CVE-2025-46418 | Medium | 0.7% | 7.6 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. | |
| CVE-2026-13181 | Medium | 0.7% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influen… | |
| CVE-2026-15019 | Medium | 0.7% | 7.5 | The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traver… | |
| CVE-2026-17624 | Medium | 0.7% | 8.5 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 t… | |
| CVE-2026-17633 | Medium | 0.7% | 8.5 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execu… | |
| CVE-2026-4327 | Medium | 0.7% | 8.8 | The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all vers… | |
| CVE-2026-76059 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source… | |
| CVE-2026-76861 | Medium | 0.7% | 8.8 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdum… | |
| CVE-2026-78212 | Medium | 0.7% | 7.5 | 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulner… | |
| CVE-2026-93468 | Medium | 0.7% | 7.5 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated … | |
| CVE-2026-35904 | Medium | 0.7% | 9.8 | Incorrect access control in the web management interface of T3 Technology CPE models T625P… | |
| CVE-2026-50759 | Medium | 0.7% | 7.5 | An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the… | |
| CVE-2026-63046 | Medium | 0.7% | 8.8 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnera… | |
| CVE-2026-6322 | Medium | 0.7% | 7.5 | fast-uri normalize() decoded percent-encoded authority delimiters inside the host componen… | |
| CVE-2026-73666 | Medium | 0.7% | 8.2 | OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the O… | |
| CVE-2026-91931 | Medium | 0.7% | 8.5 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node… | |
| CVE-2026-9330 | Medium | 0.7% | 8.5 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of use… | |
| CVE-2022-49075 | Medium | 0.7% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix qgroup res… | |
| CVE-2024-58349 | Medium | 0.7% | 9.8 | WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that all… | |
| CVE-2026-16230 | Medium | 0.7% | 9.8 | The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due … | |
| CVE-2026-34759 | Medium | 0.7% | 8.1 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.4… | |
| CVE-2026-35397 | Medium | 0.7% | 8.8 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier… | |
| CVE-2026-61550 | Medium | 0.7% | 9.8 | Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, c… | |
| CVE-2026-7284 | Medium | 0.7% | 9.8 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulne… |