Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-7424 | Medium | 1.2% | 7.5 | A flaw was found in the libxslt library. The same memory field, psvi, is used for both sty… | |
| CVE-2024-5154 | Medium | 1.2% | 8.1 | A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary f… | |
| CVE-2026-12646 | Medium | 1.2% | 9.9 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a re… | |
| CVE-2026-12647 | Medium | 1.2% | 9.9 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a re… | |
| CVE-2021-33768 | Medium | 1.2% | 8.0 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2026-75430 | Medium | 1.2% | 9.8 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployCont… | |
| CVE-2020-3303 | Medium | 1.2% | 7.5 | A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive S… | |
| CVE-2020-3305 | Medium | 1.2% | 7.5 | A vulnerability in the implementation of the Border Gateway Protocol (BGP) module in Cisco… | |
| CVE-2020-3306 | Medium | 1.2% | 7.5 | A vulnerability in the DHCP module of Cisco Adaptive Security Appliance (ASA) Software and… | |
| CVE-2026-70554 | Medium | 1.2% | 9.8 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated atta… | |
| CVE-2026-50524 | Medium | 1.2% | 7.5 | Improper validation of specified type of input in .NET Framework allows an unauthorized at… | |
| CVE-2026-62901 | Medium | 1.2% | 7.5 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service… | |
| CVE-2024-21399 | Medium | 1.2% | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| CVE-2026-81476 | Medium | 1.2% | 8.1 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neu… | |
| CVE-2026-7654 | Medium | 1.2% | 8.8 | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Re… | |
| CVE-2026-7856 | Medium | 1.2% | 7.2 | A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the fi… | |
| CVE-2026-54513 | Medium | 1.2% | 8.1 | jackson-databind contains the general-purpose data-binding functionality and tree-model fo… | |
| CVE-2026-61539 | Medium | 1.2% | 10.0 | Xinference is an inference API for running open-source, speech, and multimodal models. In … | |
| CVE-2026-40858 | Medium | 1.2% | 8.8 | The camel-infinispan component's ProtoStream-based remote aggregation repository deseriali… | |
| CVE-2026-65660 | Medium | 1.2% | 8.8 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint a… | |
| CVE-2026-22739 | Medium | 1.2% | 8.6 | Vulnerability in Spring Cloud when substituting the profile parameter from a request made … | |
| CVE-2026-15979 | Medium | 1.2% | 8.1 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vu… | |
| CVE-2026-71471 | Medium | 1.2% | 9.0 | A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the… | |
| CVE-2026-55799 | Medium | 1.2% | 9.8 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 … | |
| CVE-2020-3478 | Medium | 1.2% | 8.1 | A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) co… | |
| CVE-2026-34070 | Medium | 1.2% | 7.5 | LangChain is a framework for building agents and LLM-powered applications. Prior to versio… | |
| CVE-2026-3183 | Medium | 1.2% | 7.1 | Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Fact… | |
| CVE-2026-4224 | Medium | 1.2% | 7.5 | When an Expat parser with a registered ElementDeclHandler parses an inline document type d… | |
| CVE-2026-9614 | Medium | 1.2% | 8.8 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises… | |
| CVE-2026-34356 | Medium | 1.2% | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend serv… | |
| CVE-2000-0957 | Medium | 1.2% | 7.5 | The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly c… | |
| CVE-2026-3085 | Medium | 1.2% | 8.8 | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. Thi… | |
| CVE-2026-47294 | Medium | 1.2% | 8.0 | Improper neutralization of special elements used in an os command ('os command injection')… | |
| CVE-2022-41061 | Medium | 1.2% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2023-21685 | Medium | 1.2% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-48358 | Medium | 1.2% | 9.1 | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability tha… | |
| CVE-2026-40478 | Medium | 1.2% | 9.0 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versi… | |
| CVE-2026-82533 | Medium | 1.2% | 9.6 | DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that… | |
| CVE-2017-11508 | Medium | 1.2% | 8.8 | SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that … | |
| CVE-2026-14484 | Medium | 1.2% | 9.1 | The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnera… | |
| CVE-2026-14544 | Medium | 1.2% | 9.8 | A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an… | |
| CVE-2026-16236 | Medium | 1.2% | 8.8 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in ve… | |
| CVE-2026-33871 | Medium | 1.2% | 7.5 | Netty is an asynchronous, event-driven network application framework. In versions prior to… | |
| CVE-2026-57099 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorize… | |
| CVE-2026-69329 | Medium | 1.2% | 7.5 | Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a n… | |
| CVE-2026-69378 | Medium | 1.2% | 7.5 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to den… | |
| CVE-2026-72923 | Medium | 1.2% | 7.5 | In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.… | |
| CVE-2026-84837 | Medium | 1.2% | 7.8 | A flaw was found in rpm. An attacker can exploit a command injection vulnerability by infl… | |
| CVE-2021-1493 | Medium | 1.2% | 8.5 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) S… | |
| CVE-2026-16098 | Medium | 1.2% | 9.8 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in a… |