Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-40033 | Medium | 1.1% | 8.8 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface … | |
| CVE-2026-44186 | Medium | 1.1% | 7.3 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp … | |
| CVE-2026-67623 | Medium | 1.1% | 8.8 | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows atta… | |
| CVE-2026-5608 | Medium | 1.1% | 8.8 | A vulnerability was detected in Belkin F9K1122 1.00.33. Affected is the function formWlanS… | |
| CVE-2026-5610 | Medium | 1.1% | 8.8 | A vulnerability has been found in Belkin F9K1015 1.00.10. Affected by this issue is the fu… | |
| CVE-2026-5611 | Medium | 1.1% | 8.8 | A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBa… | |
| CVE-2026-5612 | Medium | 1.1% | 8.8 | A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the f… | |
| CVE-2026-5613 | Medium | 1.1% | 8.8 | A vulnerability was identified in Belkin F9K1015 1.00.10. This issue affects the function … | |
| CVE-2026-5628 | Medium | 1.1% | 8.8 | A security vulnerability has been detected in Belkin F9K1015 1.00.10. Impacted is the func… | |
| CVE-2026-5629 | Medium | 1.1% | 8.8 | A vulnerability was detected in Belkin F9K1015 1.00.10. The affected element is the functi… | |
| CVE-2026-73720 | Medium | 1.1% | 7.2 | Insecure file operations in the API of HPE Networking Fabric Composer could allow an authe… | |
| CVE-2026-73769 | Medium | 1.1% | 7.2 | A vulnerability in the web-based management interface of vulnerable CPPM systems could all… | |
| CVE-2026-76690 | Medium | 1.1% | 7.2 | A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways th… | |
| CVE-2023-21800 | Medium | 1.1% | 7.8 | Windows Installer Elevation of Privilege Vulnerability | |
| CVE-2026-34182 | Medium | 1.1% | 9.1 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient… | |
| CVE-2026-3987 | Medium | 1.1% | 7.2 | A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may… | |
| CVE-2026-55175 | Medium | 1.1% | 7.5 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2… | |
| CVE-2021-26887 | Medium | 1.1% | 7.8 | An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirectio… | |
| CVE-2023-1829 | Medium | 1.1% | 7.8 | A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) … | |
| CVE-2026-3243 | Medium | 1.1% | 8.8 | The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion… | |
| CVE-2026-39862 | Medium | 1.1% | 8.8 | Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by rem… | |
| CVE-2026-65770 | Medium | 1.1% | 10.0 | Improper neutralization of argument delimiters in a command ('argument injection') in Azur… | |
| CVE-2023-35387 | Medium | 1.1% | 8.8 | Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability | |
| CVE-2025-50329 | Medium | 1.1% | 9.8 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker t… | |
| CVE-2026-47114 | Medium | 1.1% | 8.8 | IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows rem… | |
| CVE-2025-66273 | Medium | 1.1% | 7.2 | A command injection vulnerability has been reported to affect several QNAP operating syste… | |
| CVE-2025-66279 | Medium | 1.1% | 7.2 | A command injection vulnerability has been reported to affect several QNAP operating syste… | |
| CVE-2026-75686 | Medium | 1.1% | 9.3 | Adobe Connect is affected by an Improper Input Validation vulnerability that could result … | |
| CVE-2026-15068 | Medium | 1.1% | 9.9 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attac… | |
| CVE-2021-34498 | Medium | 1.0% | 7.8 | Windows GDI Elevation of Privilege Vulnerability | |
| CVE-2021-34512 | Medium | 1.0% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2021-34513 | Medium | 1.0% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2026-34183 | Medium | 1.0% | 7.5 | Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by floodin… | |
| CVE-2026-45661 | Medium | 1.0% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a cr… | |
| CVE-2026-77521 | Medium | 1.0% | 10.0 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistan… | |
| CVE-2026-88889 | Medium | 1.0% | 7.8 | Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper ma… | |
| CVE-2023-21695 | Medium | 1.0% | 7.5 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulner… | |
| CVE-2026-27305 | Medium | 1.0% | 8.6 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of … | |
| CVE-2026-48310 | Medium | 1.0% | 8.6 | Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restrict… | |
| CVE-2026-54718 | Medium | 1.0% | 7.2 | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior … | |
| CVE-2026-7262 | Medium | 1.0% | 7.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* b… | |
| CVE-2026-18351 | Medium | 1.0% | 9.8 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Ar… | |
| CVE-2026-42587 | Medium | 1.0% | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Fina… | |
| CVE-2024-5974 | Medium | 1.0% | 7.2 | A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attack… | |
| CVE-2026-26147 | Medium | 1.0% | 7.7 | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclo… | |
| CVE-2026-11572 | Medium | 1.0% | 8.8 | Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to … | |
| CVE-2026-73240 | Medium | 1.0% | 9.8 | Specifically crafted inputs may lead to git argument injection in Apache Allura. This iss… | |
| CVE-2026-76943 | Medium | 1.0% | 9.8 | Xiiaozet LK100Wt contains an authentication weakness within an administrative service tha… | |
| CVE-2026-44495 | Medium | 1.0% | 7.0 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.… | |
| CVE-2026-8505 | Medium | 1.0% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentica… |