Browse vulnerabilities
5,288 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-7854 | High | 5.9% | 9.8 | A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this … | |
| CVE-2026-25244 | High | 2.8% | 9.8 | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDr… | |
| CVE-2023-27202 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27203 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27204 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27205 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2026-66897 | High | 0.7% | 9.9 | A path traversal vulnerability in LXD's instance template processing allows an attacker wi… | |
| CVE-2026-40035 | High | 0.6% | 9.1 | Unfurl through 2025.08 contains an improper input validation vulnerability in config parsi… | |
| CVE-2026-54058 | High | 0.5% | 9.1 | Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McI… | |
| CVE-2025-21760 | Medium | 36.8% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU pro… | |
| CVE-2026-64638 | Medium | 31.2% | — | WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. … | |
| CVE-2022-20759 | Medium | 28.2% | 8.8 | A vulnerability in the web services interface for remote access VPN features of Cisco Adap… | |
| CVE-2024-6409 | Medium | 27.9% | 7.0 | A race condition vulnerability was discovered in how signals are handled by OpenSSH's serv… | |
| CVE-2021-24122 | Medium | 22.9% | 5.9 | When serving resources from a network location using the NTFS file system, Apache Tomcat v… | |
| CVE-2026-45502 | Medium | 20.3% | 5.0 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attac… | |
| CVE-2022-20866 | Medium | 17.4% | 7.4 | A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security App… | |
| CVE-2017-4971 | Medium | 14.7% | 5.9 | An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not… | |
| CVE-2026-9440 | Medium | 13.0% | 6.3 | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is… | |
| CVE-2026-9441 | Medium | 11.7% | 6.3 | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is th… | |
| CVE-2026-9256 | Medium | 10.9% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module modul… | |
| CVE-2026-9514 | Medium | 10.8% | 6.3 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the… | |
| CVE-2026-9532 | Medium | 10.8% | 6.3 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected el… | |
| CVE-2018-15756 | Medium | 9.2% | 7.5 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3… | |
| CVE-2020-10673 | Medium | 8.0% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2020-10683 | Medium | 7.3% | 9.8 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by de… | |
| CVE-2021-38665 | Medium | 7.0% | 7.4 | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
| CVE-2025-20363 | Medium | 6.9% | 9.0 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (… | |
| CVE-2026-42055 | Medium | 6.5% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and … | |
| CVE-2020-11113 | Medium | 6.3% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2026-20200 | Medium | 5.7% | 8.8 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenti… | |
| CVE-2020-9546 | Medium | 4.6% | 9.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2018-0231 | Medium | 4.5% | 8.6 | A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security A… | |
| CVE-2024-38257 | Medium | 4.5% | 7.5 | Microsoft AllJoyn API Information Disclosure Vulnerability | |
| CVE-2018-15454 | Medium | 4.4% | 8.6 | A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adapti… | |
| CVE-2026-7857 | Medium | 4.2% | 7.2 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects th… | |
| CVE-2019-15992 | Medium | 4.1% | 7.2 | A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive … | |
| CVE-2020-3304 | Medium | 3.9% | 8.6 | A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software a… | |
| CVE-2018-0240 | Medium | 3.9% | 8.6 | Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Ada… | |
| CVE-2025-71210 | Medium | 3.8% | 9.8 | A vulnerability in the Trend Micro Apex One management console could allow a remote attack… | |
| CVE-2025-71211 | Medium | 3.8% | 9.8 | A vulnerability in the Trend Micro Apex One management console could allow a remote attack… | |
| CVE-2020-11112 | Medium | 3.7% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2020-10968 | Medium | 3.6% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2019-1971 | Medium | 3.6% | 9.8 | A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) … | |
| CVE-2018-0228 | Medium | 3.6% | 8.6 | A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appl… | |
| CVE-2020-10969 | Medium | 3.6% | 8.8 | FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serializ… | |
| CVE-2021-26433 | Medium | 3.5% | 7.5 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | |
| CVE-2026-23921 | Medium | 3.5% | 8.8 | A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerabilit… | |
| CVE-2021-36926 | Medium | 3.5% | 7.5 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | |
| CVE-2021-36932 | Medium | 3.5% | 7.5 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | |
| CVE-2021-36933 | Medium | 3.5% | 7.5 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |