Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-31020 | Medium | 1.0% | 9.8 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows … | |
| CVE-2026-55976 | Medium | 1.0% | 9.1 | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4… | |
| CVE-2026-74843 | Medium | 1.0% | 10.0 | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vu… | |
| CVE-2026-75728 | Medium | 1.0% | 9.1 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2023-36895 | Medium | 1.0% | 7.8 | Microsoft Outlook Remote Code Execution Vulnerability | |
| CVE-2026-3945 | Medium | 1.0% | 7.5 | An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyprox… | |
| CVE-2026-48330 | Medium | 1.0% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2026-78461 | Medium | 1.0% | 7.4 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual S… | |
| CVE-2024-42467 | Medium | 1.0% | 10.0 | openHAB, a provider of open-source home automation software, has add-ons including the vis… | |
| CVE-2026-12872 | Medium | 1.0% | 9.8 | The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded f… | |
| CVE-2026-57124 | Medium | 1.0% | 9.8 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications… | |
| CVE-2026-91105 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2024-21536 | Medium | 1.0% | 7.5 | Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 ar… | |
| CVE-2026-19446 | Medium | 1.0% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can… | |
| CVE-2026-41449 | Medium | 1.0% | 7.8 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vu… | |
| CVE-2026-8461 | Medium | 1.0% | 8.8 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the M… | |
| CVE-2026-92937 | Medium | 1.0% | 10.0 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host … | |
| CVE-2026-28703 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-28754 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-28756 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-34660 | Medium | 1.0% | 9.3 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Auth… | |
| CVE-2026-3879 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-3880 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-4108 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-31790 | Medium | 1.0% | 7.5 | Issue summary: Applications using RSASVE key encapsulation to establish a secret encryptio… | |
| CVE-2026-41608 | Medium | 1.0% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache T… | |
| CVE-2026-43871 | Medium | 1.0% | 7.5 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Pyth… | |
| CVE-2026-45112 | Medium | 1.0% | 7.5 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java b… | |
| CVE-2026-45815 | Medium | 1.0% | 7.5 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple … | |
| CVE-2026-45816 | Medium | 1.0% | 7.5 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.… | |
| CVE-2026-48586 | Medium | 1.0% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache T… | |
| CVE-2026-49158 | Medium | 1.0% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache T… | |
| CVE-2026-55968 | Medium | 1.0% | 7.5 | Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling v… | |
| CVE-2026-55969 | Medium | 1.0% | 7.5 | Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Del… | |
| CVE-2026-58389 | Medium | 1.0% | 7.5 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust b… | |
| CVE-2026-61483 | Medium | 1.0% | 7.5 | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. Th… | |
| CVE-2026-85440 | Medium | 1.0% | 9.8 | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in… | |
| CVE-2024-38220 | Medium | 1.0% | 9.0 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| CVE-2026-26740 | Medium | 1.0% | 8.2 | Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial… | |
| CVE-2026-65974 | Medium | 1.0% | 9.9 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and… | |
| CVE-2026-76841 | Medium | 1.0% | 8.8 | Xinference loads models with Hugging Face remote code execution unconditionally enabled, a… | |
| CVE-2026-42605 | Medium | 1.0% | 8.8 | AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6… | |
| CVE-2026-48315 | Medium | 1.0% | 9.3 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validati… | |
| CVE-2026-48334 | Medium | 1.0% | 9.3 | Illustrator is affected by an Improper Input Validation vulnerability that could result in… | |
| CVE-2026-77086 | Medium | 1.0% | 9.1 | SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uni… | |
| CVE-2024-7409 | Medium | 1.0% | 7.5 | A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (Do… | |
| CVE-2026-14498 | Medium | 1.0% | 8.8 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all vers… | |
| CVE-2026-32981 | Medium | 1.0% | 7.5 | A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray … | |
| CVE-2026-42908 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information … | |
| CVE-2026-45639 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information … |