Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-71398 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2026-75723 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2026-75745 | Medium | 1.2% | 10.0 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability… | |
| CVE-2026-85437 | Medium | 1.2% | 9.8 | MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function … | |
| CVE-2021-26431 | Medium | 1.2% | 7.8 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | |
| CVE-2026-31843 | Medium | 1.2% | 9.8 | The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the … | |
| CVE-2026-47391 | Medium | 1.2% | 9.8 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party … | |
| CVE-2026-67587 | Medium | 1.2% | 8.8 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running i… | |
| CVE-2026-5212 | Medium | 1.2% | 8.8 | A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, D… | |
| CVE-2024-38263 | Medium | 1.2% | 7.5 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | |
| CVE-2022-41118 | Medium | 1.2% | 7.5 | Windows Scripting Languages Remote Code Execution Vulnerability | |
| CVE-2026-63073 | Medium | 1.2% | 9.8 | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distin… | |
| CVE-2026-84675 | Medium | 1.2% | 7.4 | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows atta… | |
| CVE-2021-26862 | Medium | 1.2% | 7.0 | Windows Installer Elevation of Privilege Vulnerability | |
| CVE-2024-21389 | Medium | 1.2% | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2024-21393 | Medium | 1.2% | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2024-21396 | Medium | 1.2% | 7.6 | Dynamics 365 Sales Spoofing Vulnerability | |
| CVE-2024-6592 | Medium | 1.2% | 9.1 | An incorrect authorization vulnerability in the protocol communication between the WatchGu… | |
| CVE-2026-8260 | Medium | 1.2% | 8.8 | A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the fu… | |
| CVE-2026-94139 | Medium | 1.2% | 7.4 | A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202… | |
| CVE-2026-1460 | Medium | 1.2% | 7.2 | A post-authentication command injection vulnerability in the “DomainName” parameter of the… | |
| CVE-2026-54569 | Medium | 1.2% | 9.8 | SENAITE.CORE is the core framework for the SENAITE laboratory information management syste… | |
| CVE-2026-44724 | Medium | 1.2% | 7.8 | systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.… | |
| CVE-2019-12627 | Medium | 1.2% | 7.5 | A vulnerability in the application policy configuration of the Cisco Firepower Threat Defe… | |
| CVE-2022-41120 | Medium | 1.2% | 7.8 | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | |
| CVE-2026-16585 | Medium | 1.2% | 7.2 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for W… | |
| CVE-2026-42578 | Medium | 1.2% | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Fina… | |
| CVE-2026-51934 | Medium | 1.2% | 9.8 | Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.… | |
| CVE-2026-17524 | Medium | 1.2% | 7.5 | Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the… | |
| CVE-2026-48746 | Medium | 1.2% | 9.1 | vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until… | |
| CVE-2023-21686 | Medium | 1.2% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-1526 | Medium | 1.2% | 7.5 | The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memo… | |
| CVE-2026-35002 | Medium | 1.2% | 9.8 | Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the mod… | |
| CVE-2026-45117 | Medium | 1.1% | 9.8 | MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer modul… | |
| CVE-2026-51785 | Medium | 1.1% | 9.8 | An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute ar… | |
| CVE-2026-72571 | Medium | 1.1% | 7.5 | A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an una… | |
| CVE-2026-72572 | Medium | 1.1% | 7.5 | A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated re… | |
| CVE-2023-21808 | Medium | 1.1% | 7.8 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2026-15244 | Medium | 1.1% | 7.2 | The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against … | |
| CVE-2026-66909 | Medium | 1.1% | 9.8 | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using na… | |
| CVE-2026-68771 | Medium | 1.1% | 9.8 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDatase… | |
| CVE-2021-26866 | Medium | 1.1% | 7.1 | Windows Update Service Elevation of Privilege Vulnerability | |
| CVE-2020-5403 | Medium | 1.1% | 7.5 | Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException tha… | |
| CVE-2026-5485 | Medium | 1.1% | 7.8 | OS command injection in the browser-based authentication component in Amazon Athena ODBC d… | |
| CVE-2021-36963 | Medium | 1.1% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2026-34619 | Medium | 1.1% | 7.7 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of … | |
| CVE-2026-89040 | Medium | 1.1% | 9.8 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to… | |
| CVE-2026-8778 | Medium | 1.1% | 9.8 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. p… | |
| CVE-2026-87796 | Medium | 1.1% | 9.8 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File … | |
| CVE-2024-21395 | Medium | 1.1% | 8.2 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |