Browse vulnerabilities
157 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2014-6271 | Act now | 100.0% | — | ● | GNU Bash through 4.3 processes trailing strings after function definitions in the values o… |
| CVE-2014-7169 | Act now | 99.9% | — | ● | GNU Bash through 4.3 processes trailing strings after function definitions in the values o… |
| CVE-2014-6278 | Act now | 99.6% | — | ● | GNU Bash contains an OS command injection vulnerability which allows remote attackers to e… |
| CVE-2026-24061 | Act now | 99.0% | — | ● | GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for… |
| CVE-2023-4911 | Act now | 81.4% | — | ● | GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when process… |
| CVE-2000-0974 | Medium | 3.0% | 7.5 | GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple doc… | |
| CVE-2000-0947 | Medium | 2.5% | 10.0 | Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers… | |
| CVE-2000-0803 | Medium | 2.3% | 10.0 | GNU Groff uses the current working directory to find a device description file, which allo… | |
| CVE-2026-1584 | Medium | 1.3% | 7.5 | A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerabil… | |
| CVE-2026-89036 | Medium | 1.3% | 8.8 | Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticat… | |
| CVE-2026-16606 | Medium | 1.1% | 9.8 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openF… | |
| CVE-2025-2609 | Medium | 1.1% | 8.2 | Improper neutralization of input during web page generation vulnerability in MagnusSolutio… | |
| CVE-2026-42009 | Medium | 1.1% | 7.5 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Trans… | |
| CVE-2026-33846 | Medium | 1.1% | 7.5 | A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logi… | |
| CVE-2026-5260 | Medium | 0.9% | 8.2 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster … | |
| CVE-2025-2610 | Medium | 0.9% | 7.6 | Improper neutralization of input during web page generation vulnerability in MagnusSolutio… | |
| CVE-2026-42010 | Medium | 0.9% | 7.1 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-S… | |
| CVE-2026-33845 | Medium | 0.9% | 7.5 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and no… | |
| CVE-2026-55585 | Medium | 0.8% | 8.8 | QWED is open-source AI verification infrastructure for deterministic verification of LLM o… | |
| CVE-2026-91752 | Medium | 0.7% | 7.5 | GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the p… | |
| CVE-2026-89260 | Medium | 0.7% | 7.5 | MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat… | |
| CVE-2026-59932 | Medium | 0.7% | 7.5 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In version… | |
| CVE-2026-81180 | Medium | 0.7% | 8.8 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authentica… | |
| CVE-2026-53542 | Medium | 0.7% | 8.8 | Termix is a web-based server management platform with SSH terminal, tunneling, and file ed… | |
| CVE-2025-66390 | Medium | 0.6% | 9.8 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/p… | |
| CVE-2024-58362 | Medium | 0.6% | 8.8 | SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in… | |
| CVE-2026-31070 | Medium | 0.6% | 9.8 | The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote … | |
| CVE-2026-48829 | Medium | 0.6% | 7.5 | In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients… | |
| CVE-2024-53920 | Medium | 0.6% | 7.8 | In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-a… | |
| CVE-2026-72839 | Medium | 0.6% | 9.8 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-sig… | |
| CVE-2026-42011 | Medium | 0.6% | 7.4 | A flaw was found in gnutls. This vulnerability occurs because permitted name constraints w… | |
| CVE-2026-9605 | Medium | 0.6% | 7.3 | A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function b… | |
| CVE-2026-41992 | Medium | 0.6% | 7.5 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic ca… | |
| CVE-2026-42013 | Medium | 0.6% | 8.2 | A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative… | |
| CVE-2026-10130 | Medium | 0.6% | 8.2 | QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated at… | |
| CVE-2026-72836 | Medium | 0.6% | 8.1 | FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking… | |
| CVE-2023-4692 | Medium | 0.5% | 7.5 | An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may al… | |
| CVE-2026-73566 | Medium | 0.5% | 7.5 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's fi… | |
| CVE-2026-90856 | Medium | 0.5% | 7.3 | A security vulnerability has been detected in SourceCodester College Notes Gallery Managem… | |
| CVE-2026-42012 | Medium | 0.5% | 7.1 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenti… | |
| CVE-2017-20234 | Medium | 0.5% | 9.8 | GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerabili… | |
| CVE-2026-19211 | Medium | 0.4% | 7.3 | A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unkno… | |
| CVE-2026-15206 | Medium | 0.4% | 7.5 | The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session f… | |
| CVE-2026-57163 | Medium | 0.4% | 9.1 | PJSIP is a free and open source multimedia communication library written in C. Prior to co… | |
| CVE-2026-48486 | Medium | 0.3% | 7.5 | Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Comm… | |
| CVE-2018-25372 | Medium | 0.3% | 8.2 | MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows u… | |
| CVE-2026-19499 | Medium | 0.3% | 7.7 | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the… | |
| CVE-2017-20245 | Medium | 0.3% | 8.2 | Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows… | |
| CVE-2026-60122 | Medium | 0.3% | 7.8 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerabil… | |
| CVE-2024-26706 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: parisc: Fix random da… |
Page 1 of 4
Next →