Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-70341 | Medium | 0.7% | 8.5 | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute… | |
| CVE-2026-70636 | Medium | 0.7% | 7.5 | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthen… | |
| CVE-2026-72928 | Medium | 0.7% | 7.5 | Use after free in Windows DNS allows an authorized attacker to execute code over a network… | |
| CVE-2026-72943 | Medium | 0.7% | 7.5 | Use after free in Windows Deployment Services allows an authorized attacker to execute cod… | |
| CVE-2026-72954 | Medium | 0.7% | 7.5 | Use after free in Windows Deployment Services allows an authorized attacker to execute cod… | |
| CVE-2026-75110 | Medium | 0.7% | 9.8 | MemOS is a memory operating system for LLMs and AI agents. In deployments where authentica… | |
| CVE-2026-75852 | Medium | 0.7% | 9.8 | ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in th… | |
| CVE-2026-81180 | Medium | 0.7% | 8.8 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authentica… | |
| CVE-2024-35861 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix pote… | |
| CVE-2024-35862 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix pote… | |
| CVE-2024-35863 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix pote… | |
| CVE-2024-35864 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix pote… | |
| CVE-2026-10591 | Medium | 0.7% | 8.8 | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before … | |
| CVE-2026-14669 | Medium | 0.7% | 8.8 | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the time… | |
| CVE-2026-27137 | Medium | 0.7% | 7.5 | When verifying a certificate chain which contains a certificate containing multiple email … | |
| CVE-2026-44172 | Medium | 0.7% | 9.1 | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8… | |
| CVE-2026-54890 | Medium | 0.7% | 7.5 | Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts module… | |
| CVE-2026-62309 | Medium | 0.7% | 7.5 | CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can … | |
| CVE-2026-73031 | Medium | 0.7% | 8.7 | telegram-search contains a stored cross-site scripting vulnerability that allows remote at… | |
| CVE-2026-73486 | Medium | 0.7% | 8.8 | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's custo… | |
| CVE-2026-89049 | Medium | 0.7% | 9.9 | A server-side request forgery issue due to improper validation of equivalent address repre… | |
| CVE-2023-52513 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix connect… | |
| CVE-2024-20330 | Medium | 0.7% | 8.6 | A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower… | |
| CVE-2026-27143 | Medium | 0.7% | 9.8 | Arithmetic over induction variables in loops were not correctly checked for underflow or o… | |
| CVE-2026-30075 | Medium | 0.7% | 7.5 | OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNAS… | |
| CVE-2026-35847 | Medium | 0.7% | 9.8 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via… | |
| CVE-2026-43778 | Medium | 0.7% | 9.8 | A use after free issue was addressed with improved memory management. This issue is fixed … | |
| CVE-2026-43799 | Medium | 0.7% | 9.8 | A use after free issue was addressed with improved memory management. This issue is fixed … | |
| CVE-2026-43822 | Medium | 0.7% | 9.8 | A use after free issue was addressed with improved memory management. This issue is fixed … | |
| CVE-2026-50635 | Medium | 0.7% | 8.8 | LimeSurvey constructs account password-reset links from the client-supplied HTTP Host head… | |
| CVE-2026-53542 | Medium | 0.7% | 8.8 | Termix is a web-based server management platform with SSH terminal, tunneling, and file ed… | |
| CVE-2026-5581 | Medium | 0.7% | 9.1 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized ar… | |
| CVE-2026-64700 | Medium | 0.7% | 9.8 | A use after free issue was addressed with improved memory management. This issue is fixed … | |
| CVE-2026-74860 | Medium | 0.7% | 8.5 | A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit … | |
| CVE-2026-90819 | Medium | 0.7% | 7.3 | A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the f… | |
| CVE-2024-53066 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfs: Fix KMSAN warnin… | |
| CVE-2026-15815 | Medium | 0.7% | 8.8 | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting p… | |
| CVE-2026-22797 | Medium | 0.7% | 9.9 | An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 1… | |
| CVE-2026-36669 | Medium | 0.7% | 9.8 | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Of… | |
| CVE-2026-4035 | Medium | 0.7% | 7.7 | A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of env… | |
| CVE-2026-53674 | Medium | 0.7% | 7.1 | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity me… | |
| CVE-2026-54752 | Medium | 0.7% | 9.6 | NetBox Device Type Library is a collection of community-sourced device type definitions fo… | |
| CVE-2026-55553 | Medium | 0.7% | 7.5 | urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, an… | |
| CVE-2026-56171 | Medium | 0.7% | 7.1 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an… | |
| CVE-2026-6627 | Medium | 0.7% | 8.2 | The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable … | |
| CVE-2026-90944 | Medium | 0.7% | 8.2 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authe… | |
| CVE-2023-45858 | Medium | 0.7% | 8.6 | A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it pos… | |
| CVE-2024-49978 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: gso: fix udp gso frag… | |
| CVE-2024-53120 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: CT: Fix nu… | |
| CVE-2026-15426 | Medium | 0.7% | 8.8 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordP… |