Browse vulnerabilities

112 results

CVEPriorityEPSSCVSSKEVWhat
CVE-2020-35730 Act now 32.7% — ● Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attac…
CVE-2026-9385 Medium 3.3% 9.8 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects…
CVE-2026-94095 Medium 3.2% 9.9 A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vul…
CVE-2026-71947 Medium 3.2% 9.8 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_2026…
CVE-2026-49199 Medium 2.2% 9.8 Crafted MQTT messages can trigger command injection, resulting in root-level code executio…
CVE-2026-53611 Medium 2.0% 9.8 Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained…
CVE-2026-8365 Medium 1.6% 8.8 The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Co…
CVE-2000-0949 Medium 1.2% 7.2 Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user…
CVE-2026-49190 Medium 0.8% 8.8 The system fails to evaluate instructional permissions over multiple internal operation co…
CVE-2026-50270 Medium 0.8% 7.5 dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction do…
CVE-2026-50276 Medium 0.8% 7.5 dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction …
CVE-2026-50277 Medium 0.8% 7.5 dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-…
CVE-2026-74717 Medium 0.7% 7.5 In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, …
CVE-2026-50275 Medium 0.7% 7.5 The Datadog PHP Tracer provides application performance monitoring and distributed tracing…
CVE-2026-49196 Medium 0.7% 7.2 The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection …
CVE-2026-71644 Medium 0.6% 9.8 An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcd…
CVE-2023-52834 Medium 0.6% 7.5 In the Linux kernel, the following vulnerability has been resolved: atl1c: Work around th…
CVE-2026-49188 Medium 0.6% 9.8 The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to…
CVE-2026-49200 Medium 0.6% 9.8 The acer_cgi.log file in the device firmware is accessible without authentication via the …
CVE-2026-71645 Medium 0.6% 7.5 An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcd…
CVE-2026-49185 Medium 0.6% 9.8 The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec()…
CVE-2026-49191 Medium 0.5% 9.8 The production build of the M3WebServer hard-codes its backend API keys, which can be easi…
CVE-2026-49197 Medium 0.5% 9.8 Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization…
CVE-2026-50211 Medium 0.5% 9.8 Leftover engineering diagnostics and factory-level diagnostic software remain exposed on r…
CVE-2026-65754 Medium 0.5% 7.5 Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - …
CVE-2026-71646 Medium 0.5% 7.5 An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcd…
CVE-2026-49186 Medium 0.5% 9.8 The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allow…
CVE-2026-85237 Medium 0.5% 8.1 A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed …
CVE-2026-49202 Medium 0.5% 8.6 Internal multimedia session archives are accessible without authentication, exacerbated by…
CVE-2026-50225 Medium 0.4% 9.1 The registration path /v1/account/register provides no bot mitigation mechanisms, allowing…
CVE-2026-63685 Medium 0.4% 8.8 Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Admin…
CVE-2026-49194 Medium 0.4% 8.8 The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device …
CVE-2026-49187 Medium 0.4% 7.5 The hard-coded APK resource files never expire, and the shared scepter leads to informatio…
CVE-2026-49193 Medium 0.4% 7.5 Overly permissive configuration settings on cloud storage containers expose active telemet…
CVE-2026-50210 Medium 0.4% 7.5 The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs…
CVE-2026-50205 Medium 0.4% 8.2 System log files output unencrypted SMTP server authentication passwords alongside sensiti…
CVE-2026-50213 Medium 0.4% 7.5 The account validation endpoint /v1/User/validate returns comprehensive user profile data …
CVE-2026-55953 Medium 0.4% 7.4 The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher s…
CVE-2026-49195 Medium 0.4% 8.8 Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 withou…
CVE-2022-49022 Medium 0.3% 8.1 In the Linux kernel, the following vulnerability has been resolved: wifi: mac8021: fix po…
CVE-2026-18092 Medium 0.3% 8.1 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signatur…
CVE-2026-14893 Medium 0.3% 7.3 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js t…
CVE-2026-49201 Medium 0.3% 9.8 The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES…
CVE-2026-86304 Medium 0.3% 9.8 MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass beca…
CVE-2026-49203 Medium 0.3% 8.3 Crucial management API endpoints for cellular eSIM allocation do not validate caller autho…
CVE-2024-26759 Medium 0.3% 7.8 In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race whe…
CVE-2024-40954 Medium 0.3% 7.8 In the Linux kernel, the following vulnerability has been resolved: net: do not leave a d…
CVE-2026-50214 Medium 0.3% 9.8 The /v1/Plan service relies entirely on a shared global API token for full administrative …
CVE-2026-49457 Medium 0.2% 9.1 erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client …
CVE-2021-46933 Medium 0.2% 7.8 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Cl…
Page 1 of 3 Next →