Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-93019 | Medium | 0.7% | 9.1 | Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map len… | |
| CVE-2026-96891 | Medium | 0.7% | 9.8 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_… | |
| CVE-2023-20086 | Medium | 0.7% | 8.6 | A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software a… | |
| CVE-2024-36913 | Medium | 0.7% | 9.3 | In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: L… | |
| CVE-2024-47726 | Medium | 0.7% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait dio… | |
| CVE-2026-15572 | Medium | 0.7% | 8.8 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy managemen… | |
| CVE-2026-15704 | Medium | 0.7% | 9.8 | In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployment… | |
| CVE-2026-16524 | Medium | 0.7% | 7.8 | A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters… | |
| CVE-2026-3357 | Medium | 0.7% | 8.8 | IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to exe… | |
| CVE-2026-3644 | Medium | 0.7% | 7.5 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was i… | |
| CVE-2026-4671 | Medium | 0.7% | 7.5 | justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS sele… | |
| CVE-2026-53010 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-… | |
| CVE-2026-53260 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{dis… | |
| CVE-2026-64025 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: bpf, skmsg: fix verdi… | |
| CVE-2026-64061 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put … | |
| CVE-2026-65432 | Medium | 0.7% | 7.5 | Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML … | |
| CVE-2026-72317 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: pin upper rpc… | |
| CVE-2026-72381 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-… | |
| CVE-2026-72472 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfs: use nfsi->rwsem … | |
| CVE-2026-73719 | Medium | 0.7% | 7.2 | An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer … | |
| CVE-2026-74345 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix endpoin… | |
| CVE-2026-74401 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg hand… | |
| CVE-2026-74752 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie… | |
| CVE-2026-76179 | Medium | 0.7% | 9.8 | An improper protection of authentication tokens vulnerability exists in certain Ebyte gat… | |
| CVE-2026-76395 | Medium | 0.7% | 8.8 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could … | |
| CVE-2026-80926 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-… | |
| CVE-2026-82435 | Medium | 0.7% | 9.8 | Description The worker's Netty message decoder is installed ahead of the SASL authenticat… | |
| CVE-2026-88895 | Medium | 0.7% | 7.2 | CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allow… | |
| CVE-2026-89658 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client … | |
| CVE-2026-89659 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client … | |
| CVE-2026-89660 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client … | |
| CVE-2026-89688 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the statei… | |
| CVE-2026-89703 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_F… | |
| CVE-2026-89708 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_… | |
| CVE-2026-90036 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client … | |
| CVE-2026-90037 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client … | |
| CVE-2026-9546 | Medium | 0.7% | 7.5 | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicit… | |
| CVE-2026-96560 | Medium | 0.7% | 9.8 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer w… | |
| CVE-2025-38488 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-… | |
| CVE-2025-40343 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid sched… | |
| CVE-2026-19480 | Medium | 0.7% | 7.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that cou… | |
| CVE-2026-31071 | Medium | 0.7% | 9.1 | API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authenticati… | |
| CVE-2026-35214 | Medium | 0.7% | 8.7 | Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upl… | |
| CVE-2026-48048 | Medium | 0.7% | 7.5 | XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-v… | |
| CVE-2026-51152 | Medium | 0.7% | 9.1 | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 202508… | |
| CVE-2026-62384 | Medium | 0.7% | 7.5 | NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader… | |
| CVE-2026-63312 | Medium | 0.7% | 7.5 | NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorp… | |
| CVE-2026-67291 | Medium | 0.7% | 7.5 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in … | |
| CVE-2026-67301 | Medium | 0.7% | 7.5 | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update mess… | |
| CVE-2026-67304 | Medium | 0.7% | 7.5 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard devic… |