Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-18427 | Medium | 0.7% | 7.5 | @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guar… | |
| CVE-2026-51219 | Medium | 0.7% | 7.5 | A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of li… | |
| CVE-2026-65906 | Medium | 0.7% | 8.8 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox esc… | |
| CVE-2026-67309 | Medium | 0.7% | 7.5 | Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kub… | |
| CVE-2026-74490 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: tipc: avoid use-after… | |
| CVE-2026-89663 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: revoke copy-not… | |
| CVE-2019-25762 | Medium | 0.7% | 7.5 | Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability tha… | |
| CVE-2023-54357 | Medium | 0.7% | 7.5 | Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that a… | |
| CVE-2026-18983 | Medium | 0.7% | 7.5 | The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cr… | |
| CVE-2026-34689 | Medium | 0.7% | 8.6 | Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Director… | |
| CVE-2026-34827 | Medium | 0.7% | 7.5 | Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, a… | |
| CVE-2026-34829 | Medium | 0.7% | 7.5 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, … | |
| CVE-2026-41076 | Medium | 0.7% | 8.1 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 an… | |
| CVE-2026-57859 | Medium | 0.7% | 7.5 | e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deseria… | |
| CVE-2026-65375 | Medium | 0.7% | 7.5 | The issue was addressed with improved authentication. This issue is fixed in macOS Golden … | |
| CVE-2026-71314 | Medium | 0.7% | 7.5 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and … | |
| CVE-2026-72709 | Medium | 0.7% | 9.8 | SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive act… | |
| CVE-2026-73088 | Medium | 0.7% | 7.5 | Browserslist is a configuration tool for sharing target browsers and Node.js versions betw… | |
| CVE-2026-79678 | Medium | 0.7% | 8.1 | A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organizati… | |
| CVE-2026-85441 | Medium | 0.7% | 7.5 | MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-neg… | |
| CVE-2026-85664 | Medium | 0.7% | 7.5 | Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_c… | |
| CVE-2026-85702 | Medium | 0.7% | 7.3 | A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb4… | |
| CVE-2026-91080 | Medium | 0.7% | 7.5 | webhook through 2.8.3 reads the entire request body into memory before evaluating trigger … | |
| CVE-2026-92625 | Medium | 0.7% | 7.5 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of… | |
| CVE-2026-92983 | Medium | 0.7% | 7.5 | InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to … | |
| CVE-2019-25671 | Medium | 0.7% | 8.8 | VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated atta… | |
| CVE-2023-23378 | Medium | 0.7% | 7.8 | Print 3D Remote Code Execution Vulnerability | |
| CVE-2023-23390 | Medium | 0.7% | 7.8 | 3D Builder Remote Code Execution Vulnerability | |
| CVE-2026-17632 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execu… | |
| CVE-2026-28814 | Medium | 0.7% | 7.5 | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12… | |
| CVE-2026-37604 | Medium | 0.7% | 9.8 | pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP addre… | |
| CVE-2026-55814 | Medium | 0.7% | 7.5 | Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are reco… | |
| CVE-2026-5773 | Medium | 0.7% | 7.5 | libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libc… | |
| CVE-2026-65819 | Medium | 0.7% | 7.5 | gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple l… | |
| CVE-2026-70619 | Medium | 0.7% | 8.8 | Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows … | |
| CVE-2026-82253 | Medium | 0.7% | 7.5 | gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal … | |
| CVE-2026-93741 | Medium | 0.7% | 10.0 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by thi… | |
| CVE-2021-47936 | Medium | 0.7% | 9.8 | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated … | |
| CVE-2024-26953 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net: esp: fix bad han… | |
| CVE-2026-28220 | Medium | 0.7% | 8.4 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-34457 | Medium | 0.7% | 9.1 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versi… | |
| CVE-2026-42588 | Medium | 0.7% | 8.1 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulne… | |
| CVE-2026-44422 | Medium | 0.7% | 7.5 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP'… | |
| CVE-2026-59092 | Medium | 0.7% | 7.7 | JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerab… | |
| CVE-2026-92619 | Medium | 0.7% | 7.2 | The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all ver… | |
| CVE-2022-49362 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix potential u… | |
| CVE-2024-38612 | Medium | 0.7% | 7.0 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid… | |
| CVE-2025-59711 | Medium | 0.7% | 8.3 | An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided… | |
| CVE-2026-15406 | Medium | 0.7% | 7.5 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin fo… | |
| CVE-2026-22620 | Medium | 0.7% | 8.6 | Improper input validation in the authentication component of Eaton's Tripp Lite series PAD… |