Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-24212 | Medium | 0.7% | 7.5 | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is … | |
| CVE-2026-50142 | Medium | 0.7% | 7.5 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a cr… | |
| CVE-2026-54348 | Medium | 0.7% | 7.2 | Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and … | |
| CVE-2026-59200 | Medium | 0.7% | 7.5 | Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() … | |
| CVE-2026-59204 | Medium | 0.7% | 7.5 | Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode… | |
| CVE-2026-73069 | Medium | 0.7% | 9.1 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0,… | |
| CVE-2026-73089 | Medium | 0.7% | 7.5 | Browserslist is a configuration tool for sharing target browsers and Node.js versions betw… | |
| CVE-2026-74894 | Medium | 0.7% | 9.8 | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify… | |
| CVE-2026-75574 | Medium | 0.7% | 8.8 | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-control… | |
| CVE-2026-78314 | Medium | 0.7% | 8.8 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | |
| CVE-2026-78315 | Medium | 0.7% | 8.8 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | |
| CVE-2026-78316 | Medium | 0.7% | 8.8 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | |
| CVE-2026-78317 | Medium | 0.7% | 8.8 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | |
| CVE-2026-80255 | Medium | 0.7% | 7.5 | A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii co… | |
| CVE-2026-82770 | Medium | 0.7% | 8.8 | Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker send… | |
| CVE-2026-82772 | Medium | 0.7% | 8.8 | Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a… | |
| CVE-2026-84446 | Medium | 0.7% | 7.5 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF … | |
| CVE-2026-89528 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Read … | |
| CVE-2026-18255 | Medium | 0.7% | 7.2 | A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view… | |
| CVE-2026-18810 | Medium | 0.7% | 7.3 | A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown fu… | |
| CVE-2026-28324 | Medium | 0.7% | 9.8 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote… | |
| CVE-2026-42508 | Medium | 0.7% | 9.1 | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revoc… | |
| CVE-2026-50502 | Medium | 0.7% | 8.0 | Insufficient granularity of access control in Windows Event Logging Service allows an auth… | |
| CVE-2026-5632 | Medium | 0.7% | 7.3 | A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unkno… | |
| CVE-2026-68062 | Medium | 0.7% | 8.5 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this v… | |
| CVE-2026-68959 | Medium | 0.7% | 8.5 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this v… | |
| CVE-2026-73615 | Medium | 0.7% | 8.8 | Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where Sa… | |
| CVE-2026-8216 | Medium | 0.7% | 7.3 | A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. Thi… | |
| CVE-2026-82919 | Medium | 0.7% | 7.3 | A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability i… | |
| CVE-2026-86214 | Medium | 0.7% | 7.3 | A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unkno… | |
| CVE-2026-90504 | Medium | 0.7% | 7.3 | A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e5… | |
| CVE-2026-90579 | Medium | 0.7% | 7.3 | A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affect… | |
| CVE-2026-90620 | Medium | 0.7% | 7.3 | A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e9… | |
| CVE-2026-9195 | Medium | 0.7% | 9.3 | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server bef… | |
| CVE-2026-92574 | Medium | 0.7% | 8.8 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a mali… | |
| CVE-2026-92762 | Medium | 0.7% | 8.8 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through … | |
| CVE-2026-92948 | Medium | 0.7% | 9.9 | vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that… | |
| CVE-2026-93559 | Medium | 0.7% | 7.3 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2… | |
| CVE-2026-95271 | Medium | 0.7% | 7.3 | A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted e… | |
| CVE-2022-48829 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETAT… | |
| CVE-2024-58368 | Medium | 0.7% | 7.5 | SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP … | |
| CVE-2026-43197 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB… | |
| CVE-2026-56015 | Medium | 0.7% | 9.1 | Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounde… | |
| CVE-2026-76315 | Medium | 0.7% | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does no… | |
| CVE-2026-78569 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arb… | |
| CVE-2026-8182 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execut… | |
| CVE-2026-85658 | Medium | 0.7% | 8.1 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & … | |
| CVE-2026-87078 | Medium | 0.7% | 9.1 | Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on eve… | |
| CVE-2026-90230 | Medium | 0.7% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-o… | |
| CVE-2026-9207 | Medium | 0.7% | 8.8 | Tanium addressed an unauthorized code execution vulnerability in Connect. |