Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-73314 | Medium | 0.7% | 7.5 | XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST web… | |
| CVE-2026-78677 | Medium | 0.7% | 7.5 | GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing a… | |
| CVE-2026-80205 | Medium | 0.7% | 7.5 | NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability i… | |
| CVE-2026-88277 | Medium | 0.7% | 8.8 | GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands thr… | |
| CVE-2026-88937 | Medium | 0.7% | 8.8 | knowns through 0.33.0 fails to properly validate template destination paths in the code ge… | |
| CVE-2026-91200 | Medium | 0.7% | 8.8 | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from … | |
| CVE-2026-9800 | Medium | 0.7% | 8.1 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated … | |
| CVE-2023-23377 | Medium | 0.7% | 7.8 | 3D Builder Remote Code Execution Vulnerability | |
| CVE-2024-43883 | Medium | 0.7% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not… | |
| CVE-2026-24209 | Medium | 0.7% | 7.5 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a pa… | |
| CVE-2026-41672 | Medium | 0.7% | 7.5 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XML… | |
| CVE-2026-41674 | Medium | 0.7% | 7.5 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XML… | |
| CVE-2026-55416 | Medium | 0.7% | 8.8 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10… | |
| CVE-2026-55565 | Medium | 0.7% | 9.9 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fil… | |
| CVE-2026-55634 | Medium | 0.7% | 9.9 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10… | |
| CVE-2026-55897 | Medium | 0.7% | 8.8 | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a… | |
| CVE-2026-62675 | Medium | 0.7% | 8.8 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding ag… | |
| CVE-2026-63919 | Medium | 0.7% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold net… | |
| CVE-2026-64726 | Medium | 0.7% | 9.8 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 … | |
| CVE-2026-71805 | Medium | 0.7% | 9.8 | An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unaut… | |
| CVE-2026-72865 | Medium | 0.7% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compo… | |
| CVE-2026-72869 | Medium | 0.7% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backu… | |
| CVE-2026-72872 | Medium | 0.7% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, applicati… | |
| CVE-2026-73263 | Medium | 0.7% | 9.9 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection … | |
| CVE-2026-73294 | Medium | 0.7% | 9.9 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-bet… | |
| CVE-2026-82412 | Medium | 0.7% | 8.8 | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vul… | |
| CVE-2026-89046 | Medium | 0.7% | 8.2 | zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in … | |
| CVE-2026-92969 | Medium | 0.7% | 8.1 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerabl… | |
| CVE-2022-41096 | Medium | 0.6% | 7.8 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
| CVE-2025-12107 | Medium | 0.6% | 8.4 | The Velocity template engine, utilized by the affected product, accepts and processes temp… | |
| CVE-2025-59326 | Medium | 0.6% | 9.8 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protect… | |
| CVE-2026-45481 | Medium | 0.6% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Mi… | |
| CVE-2026-46325 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to… | |
| CVE-2026-58586 | Medium | 0.6% | 9.8 | Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image:… | |
| CVE-2026-63857 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not r… | |
| CVE-2026-63979 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand o… | |
| CVE-2026-64035 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: igc: set tx buffer ty… | |
| CVE-2026-64066 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read… | |
| CVE-2026-64069 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix cancellati… | |
| CVE-2026-64150 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner:… | |
| CVE-2026-64162 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_cl… | |
| CVE-2026-64459 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grac… | |
| CVE-2026-64566 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagat… | |
| CVE-2026-64900 | Medium | 0.6% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Mi… | |
| CVE-2026-67967 | Medium | 0.6% | 9.8 | Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute… | |
| CVE-2026-71644 | Medium | 0.6% | 9.8 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcd… | |
| CVE-2026-72200 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-… | |
| CVE-2026-72355 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix barriering… | |
| CVE-2026-72366 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_crea… | |
| CVE-2026-72429 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix type … |