Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-10025 | Medium | 0.6% | 8.2 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an X… | |
| CVE-2026-14357 | Medium | 0.6% | 8.8 | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up … | |
| CVE-2026-14950 | Medium | 0.6% | 9.8 | An unauthenticated remote attacker in possession of a valid session identifier is able to … | |
| CVE-2026-15780 | Medium | 0.6% | 7.2 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordP… | |
| CVE-2026-19773 | Medium | 0.6% | 9.8 | libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution V… | |
| CVE-2026-41731 | Medium | 0.6% | 8.1 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers aga… | |
| CVE-2026-62645 | Medium | 0.6% | 9.8 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information i… | |
| CVE-2026-64830 | Medium | 0.6% | 8.8 | FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the Vob… | |
| CVE-2026-7198 | Medium | 0.6% | 9.8 | CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 1… | |
| CVE-2026-86173 | Medium | 0.6% | 7.5 | MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web cra… | |
| CVE-2026-5526 | Medium | 0.6% | 7.3 | A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.… | |
| CVE-2022-49065 | Medium | 0.6% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix the svc_d… | |
| CVE-2022-49142 | Medium | 0.6% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: preserve skb_end… | |
| CVE-2022-49325 | Medium | 0.6% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: tcp: add accessors to… | |
| CVE-2024-20268 | Medium | 0.6% | 7.7 | A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive… | |
| CVE-2024-26760 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: … | |
| CVE-2024-36476 | Medium | 0.6% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib… | |
| CVE-2026-19425 | Medium | 0.6% | 9.8 | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vul… | |
| CVE-2026-49476 | Medium | 0.6% | 7.5 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2… | |
| CVE-2026-49477 | Medium | 0.6% | 7.5 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2… | |
| CVE-2026-56816 | Medium | 0.6% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-59887 | Medium | 0.6% | 7.5 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the m… | |
| CVE-2026-59941 | Medium | 0.6% | 7.5 | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and… | |
| CVE-2026-63040 | Medium | 0.6% | 8.1 | Files or Directories Accessible to External Parties vulnerability in Apache InLong. Stream… | |
| CVE-2026-63042 | Medium | 0.6% | 8.1 | Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any us… | |
| CVE-2026-72492 | Medium | 0.6% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-… | |
| CVE-2026-73712 | Medium | 0.6% | 8.1 | A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticate… | |
| CVE-2026-75878 | Medium | 0.6% | 9.1 | IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtai… | |
| CVE-2026-87011 | Medium | 0.6% | 7.5 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From… | |
| CVE-2026-9368 | Medium | 0.6% | 7.3 | A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts … | |
| CVE-2023-52909 | Medium | 0.6% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix handling of… | |
| CVE-2024-26611 | Medium | 0.6% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: xsk: fix usage of mul… | |
| CVE-2025-21795 | Medium | 0.6% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfs… | |
| CVE-2026-14257 | Medium | 0.6% | 7.5 | brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. Th… | |
| CVE-2026-15706 | Medium | 0.6% | 9.8 | Missing authentication for critical function vulnerability in Baylan Measuring Instruments… | |
| CVE-2026-25646 | Medium | 0.6% | 8.1 | LIBPNG is a reference library for use in applications that read, create, and manipulate PN… | |
| CVE-2026-56209 | Medium | 0.6% | 7.1 | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec impl… | |
| CVE-2026-59243 | Medium | 0.6% | 9.8 | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decodi… | |
| CVE-2026-65317 | Medium | 0.6% | 8.6 | Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability c… | |
| CVE-2026-73043 | Medium | 0.6% | 9.0 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Templat… | |
| CVE-2026-75325 | Medium | 0.6% | 9.8 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' a… | |
| CVE-2026-85671 | Medium | 0.6% | 7.5 | QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/g… | |
| CVE-2022-49017 | Medium | 0.6% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: tipc: re-fetch skb cb… | |
| CVE-2023-21802 | Medium | 0.6% | 7.8 | Windows Media Remote Code Execution Vulnerability | |
| CVE-2025-53837 | Medium | 0.6% | 9.9 | XWiki Rendering is a generic rendering system that converts textual input in a given synta… | |
| CVE-2025-66390 | Medium | 0.6% | 9.8 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/p… | |
| CVE-2026-13050 | Medium | 0.6% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allo… | |
| CVE-2026-13053 | Medium | 0.6% | 7.2 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authen… | |
| CVE-2026-13117 | Medium | 0.6% | 8.1 | An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows re… | |
| CVE-2026-34265 | Medium | 0.6% | 9.8 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logica… |