Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-56747 | Medium | 0.7% | 8.8 | Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl S… | |
| CVE-2026-82787 | Medium | 0.7% | 9.8 | Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this … | |
| CVE-2021-26860 | Medium | 0.7% | 7.8 | Windows App-V Overlay Filter Elevation of Privilege Vulnerability | |
| CVE-2025-15039 | Medium | 0.7% | 9.4 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce… | |
| CVE-2026-14476 | Medium | 0.7% | 8.0 | A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_componen… | |
| CVE-2026-69854 | Medium | 0.7% | 9.0 | Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate p… | |
| CVE-2026-76685 | Medium | 0.7% | 8.1 | A vulnerability exists in the proxy packet processing logic of the affected component wher… | |
| CVE-2026-77903 | Medium | 0.7% | 9.0 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker t… | |
| CVE-2022-48658 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: mm: slub: fix flush_c… | |
| CVE-2024-35797 | Medium | 0.7% | 7.1 | In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix tw… | |
| CVE-2026-13185 | Medium | 0.7% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based st… | |
| CVE-2026-13190 | Medium | 0.7% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in… | |
| CVE-2026-24782 | Medium | 0.7% | 7.6 | Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vu… | |
| CVE-2026-33001 | Medium | 0.7% | 8.8 | Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links d… | |
| CVE-2026-44574 | Medium | 0.7% | 8.1 | Next.js is a React framework for building full-stack web applications. From 15.4.0 to befo… | |
| CVE-2026-50559 | Medium | 0.7% | 7.5 | Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37… | |
| CVE-2026-55578 | Medium | 0.7% | 8.8 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to be… | |
| CVE-2024-57973 | Medium | 0.7% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent p… | |
| CVE-2026-13448 | Medium | 0.7% | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code … | |
| CVE-2026-1605 | Medium | 0.7% | 7.5 | In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a v… | |
| CVE-2026-28197 | Medium | 0.7% | 8.8 | An authenticated, low-privileged user with access to the NetBackup Flex OS management she… | |
| CVE-2026-41186 | Medium | 0.7% | 7.5 | When Calico's shared debug server is enabled (disabled by default), the Calico kube-contro… | |
| CVE-2026-54051 | Medium | 0.7% | 9.9 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the a… | |
| CVE-2026-78834 | Medium | 0.7% | 8.8 | A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authent… | |
| CVE-2026-79755 | Medium | 0.7% | 8.0 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to vers… | |
| CVE-2026-9139 | Medium | 0.7% | 9.8 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vuln… | |
| CVE-2026-93985 | Medium | 0.7% | 9.9 | OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in th… | |
| CVE-2021-47189 | Medium | 0.7% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory ord… | |
| CVE-2022-48789 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix possibl… | |
| CVE-2025-50324 | Medium | 0.7% | 8.8 | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute ar… | |
| CVE-2025-50330 | Medium | 0.7% | 8.8 | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to e… | |
| CVE-2026-13392 | Medium | 0.7% | 7.2 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custo… | |
| CVE-2026-13639 | Medium | 0.7% | 9.8 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM)… | |
| CVE-2026-14499 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execut… | |
| CVE-2026-18683 | Medium | 0.7% | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An… | |
| CVE-2026-19221 | Medium | 0.7% | 7.2 | The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide se… | |
| CVE-2026-3820 | Medium | 0.7% | 7.2 | There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. … | |
| CVE-2026-41870 | Medium | 0.7% | 8.8 | Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper… | |
| CVE-2026-44001 | Medium | 0.7% | 8.6 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerabil… | |
| CVE-2026-44004 | Medium | 0.7% | 7.5 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buf… | |
| CVE-2026-44444 | Medium | 0.7% | 9.1 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension bu… | |
| CVE-2026-49196 | Medium | 0.7% | 7.2 | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection … | |
| CVE-2026-50768 | Medium | 0.7% | 8.8 | File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 … | |
| CVE-2026-52630 | Medium | 0.7% | 9.8 | SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to … | |
| CVE-2026-55831 | Medium | 0.7% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-55833 | Medium | 0.7% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-56819 | Medium | 0.7% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-57089 | Medium | 0.7% | 7.5 | Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unaut… | |
| CVE-2026-59939 | Medium | 0.7% | 7.5 | httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 perf… | |
| CVE-2026-64775 | Medium | 0.7% | 9.8 | A memory initialization issue was addressed with improved memory handling. This issue is f… |