Browse vulnerabilities
112 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2020-35730 | Act now | 32.7% | — | ● | Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attac… |
| CVE-2026-9385 | Medium | 3.3% | 9.8 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects… | |
| CVE-2026-94095 | Medium | 3.2% | 9.9 | A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vul… | |
| CVE-2026-71947 | Medium | 3.2% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026… | |
| CVE-2026-49199 | Medium | 2.2% | 9.8 | Crafted MQTT messages can trigger command injection, resulting in root-level code executio… | |
| CVE-2026-53611 | Medium | 2.0% | 9.8 | Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained… | |
| CVE-2026-8365 | Medium | 1.6% | 8.8 | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Co… | |
| CVE-2000-0949 | Medium | 1.2% | 7.2 | Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user… | |
| CVE-2026-49190 | Medium | 0.8% | 8.8 | The system fails to evaluate instructional permissions over multiple internal operation co… | |
| CVE-2026-50270 | Medium | 0.8% | 7.5 | dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction do… | |
| CVE-2026-50276 | Medium | 0.8% | 7.5 | dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction … | |
| CVE-2026-50277 | Medium | 0.8% | 7.5 | dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-… | |
| CVE-2026-74717 | Medium | 0.7% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, … | |
| CVE-2026-50275 | Medium | 0.7% | 7.5 | The Datadog PHP Tracer provides application performance monitoring and distributed tracing… | |
| CVE-2026-49196 | Medium | 0.7% | 7.2 | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection … | |
| CVE-2026-71644 | Medium | 0.6% | 9.8 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcd… | |
| CVE-2023-52834 | Medium | 0.6% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: atl1c: Work around th… | |
| CVE-2026-49188 | Medium | 0.6% | 9.8 | The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to… | |
| CVE-2026-49200 | Medium | 0.6% | 9.8 | The acer_cgi.log file in the device firmware is accessible without authentication via the … | |
| CVE-2026-71645 | Medium | 0.6% | 7.5 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcd… | |
| CVE-2026-49185 | Medium | 0.6% | 9.8 | The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec()… | |
| CVE-2026-49191 | Medium | 0.5% | 9.8 | The production build of the M3WebServer hard-codes its backend API keys, which can be easi… | |
| CVE-2026-49197 | Medium | 0.5% | 9.8 | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization… | |
| CVE-2026-50211 | Medium | 0.5% | 9.8 | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on r… | |
| CVE-2026-65754 | Medium | 0.5% | 7.5 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - … | |
| CVE-2026-71646 | Medium | 0.5% | 7.5 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcd… | |
| CVE-2026-49186 | Medium | 0.5% | 9.8 | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allow… | |
| CVE-2026-85237 | Medium | 0.5% | 8.1 | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed … | |
| CVE-2026-49202 | Medium | 0.5% | 8.6 | Internal multimedia session archives are accessible without authentication, exacerbated by… | |
| CVE-2026-50225 | Medium | 0.4% | 9.1 | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing… | |
| CVE-2026-63685 | Medium | 0.4% | 8.8 | Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Admin… | |
| CVE-2026-49194 | Medium | 0.4% | 8.8 | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device … | |
| CVE-2026-49187 | Medium | 0.4% | 7.5 | The hard-coded APK resource files never expire, and the shared scepter leads to informatio… | |
| CVE-2026-49193 | Medium | 0.4% | 7.5 | Overly permissive configuration settings on cloud storage containers expose active telemet… | |
| CVE-2026-50210 | Medium | 0.4% | 7.5 | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs… | |
| CVE-2026-50205 | Medium | 0.4% | 8.2 | System log files output unencrypted SMTP server authentication passwords alongside sensiti… | |
| CVE-2026-50213 | Medium | 0.4% | 7.5 | The account validation endpoint /v1/User/validate returns comprehensive user profile data … | |
| CVE-2026-55953 | Medium | 0.4% | 7.4 | The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher s… | |
| CVE-2026-49195 | Medium | 0.4% | 8.8 | Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 withou… | |
| CVE-2022-49022 | Medium | 0.3% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac8021: fix po… | |
| CVE-2026-18092 | Medium | 0.3% | 8.1 | Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signatur… | |
| CVE-2026-14893 | Medium | 0.3% | 7.3 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js t… | |
| CVE-2026-49201 | Medium | 0.3% | 9.8 | The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES… | |
| CVE-2026-86304 | Medium | 0.3% | 9.8 | MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass beca… | |
| CVE-2026-49203 | Medium | 0.3% | 8.3 | Crucial management API endpoints for cellular eSIM allocation do not validate caller autho… | |
| CVE-2024-26759 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race whe… | |
| CVE-2024-40954 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: net: do not leave a d… | |
| CVE-2026-50214 | Medium | 0.3% | 9.8 | The /v1/Plan service relies entirely on a shared global API token for full administrative … | |
| CVE-2026-49457 | Medium | 0.2% | 9.1 | erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client … | |
| CVE-2021-46933 | Medium | 0.2% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Cl… |
Page 1 of 3
Next →