Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-65907 | Medium | 0.7% | 9.1 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possi… | |
| CVE-2026-71231 | Medium | 0.7% | 9.8 | IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT… | |
| CVE-2026-71278 | Medium | 0.7% | 9.8 | rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/contro… | |
| CVE-2026-73552 | Medium | 0.7% | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Pri… | |
| CVE-2026-73751 | Medium | 0.7% | 8.8 | An authenticated user with low-privileged access could submit crafted input through the we… | |
| CVE-2026-73753 | Medium | 0.7% | 8.8 | Exploitation through affected command-line operations could allow an authenticated low-pri… | |
| CVE-2026-74851 | Medium | 0.7% | 7.2 | The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback ag… | |
| CVE-2026-81934 | Medium | 0.7% | 7.1 | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, w… | |
| CVE-2026-82642 | Medium | 0.7% | 8.8 | Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB… | |
| CVE-2026-84609 | Medium | 0.7% | 9.8 | A permissions issue was addressed with improved path validation. This issue is fixed in iO… | |
| CVE-2026-87021 | Medium | 0.7% | 7.2 | Tanium addressed an unauthorized code execution vulnerability in Comply. | |
| CVE-2023-52775 | Medium | 0.7% | 8.2 | In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid data c… | |
| CVE-2024-50276 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net: vertexcom: mse10… | |
| CVE-2025-20127 | Medium | 0.7% | 7.7 | A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firew… | |
| CVE-2026-0611 | Medium | 0.7% | 9.8 | Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain … | |
| CVE-2026-10196 | Medium | 0.7% | 9.8 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin … | |
| CVE-2026-18420 | Medium | 0.7% | 8.8 | Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Da… | |
| CVE-2026-34742 | Medium | 0.7% | 8.1 | The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context… | |
| CVE-2026-52199 | Medium | 0.7% | 9.1 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execut… | |
| CVE-2026-53383 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VAL… | |
| CVE-2026-54414 | Medium | 0.7% | 9.8 | FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoin… | |
| CVE-2026-58151 | Medium | 0.7% | 7.5 | Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 fr… | |
| CVE-2026-58161 | Medium | 0.7% | 7.5 | Apache Traffic Server can crash from null dereferences and dangling references in TLS and … | |
| CVE-2026-58164 | Medium | 0.7% | 7.5 | Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap con… | |
| CVE-2026-58175 | Medium | 0.7% | 7.5 | Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects A… | |
| CVE-2026-58178 | Medium | 0.7% | 7.5 | The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controll… | |
| CVE-2026-58180 | Medium | 0.7% | 7.5 | The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled inpu… | |
| CVE-2026-58181 | Medium | 0.7% | 7.5 | The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash o… | |
| CVE-2026-59568 | Medium | 0.7% | 9.1 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote cod… | |
| CVE-2026-63125 | Medium | 0.7% | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unpriv… | |
| CVE-2026-64958 | Medium | 0.7% | 7.5 | An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial o… | |
| CVE-2026-65324 | Medium | 0.7% | 7.5 | Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 res… | |
| CVE-2026-66145 | Medium | 0.7% | 9.1 | An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build … | |
| CVE-2026-68481 | Medium | 0.7% | 7.5 | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt su… | |
| CVE-2026-69253 | Medium | 0.7% | 8.8 | Flowise is a drag-and-drop user interface for building customized large language model (LL… | |
| CVE-2026-86083 | Medium | 0.7% | 8.8 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2,… | |
| CVE-2026-93575 | Medium | 0.7% | 7.5 | A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit th… | |
| CVE-2025-67030 | Medium | 0.7% | 8.8 | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Ex… | |
| CVE-2026-16142 | Medium | 0.7% | 9.8 | The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up t… | |
| CVE-2026-16723 | Medium | 0.7% | 9.0 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This… | |
| CVE-2026-31409 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->bi… | |
| CVE-2026-50685 | Medium | 0.7% | 7.5 | Double free in Windows DHCP Server allows an authorized attacker to execute code over a ne… | |
| CVE-2026-62787 | Medium | 0.7% | 7.5 | Use after free in Windows DNS allows an authorized attacker to execute code over a network… | |
| CVE-2026-62813 | Medium | 0.7% | 7.5 | Use after free in Active Directory Domain Services allows an authorized attacker to execut… | |
| CVE-2026-67379 | Medium | 0.7% | 8.5 | Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code ov… | |
| CVE-2026-69429 | Medium | 0.7% | 7.5 | Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execu… | |
| CVE-2026-69514 | Medium | 0.7% | 7.5 | Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacke… | |
| CVE-2026-69539 | Medium | 0.7% | 7.5 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute… | |
| CVE-2026-69599 | Medium | 0.7% | 7.5 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute… | |
| CVE-2026-69852 | Medium | 0.7% | 7.5 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker … |