Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-50463 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose informati… | |
| CVE-2026-50470 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker t… | |
| CVE-2026-62898 | Medium | 1.0% | 7.5 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information o… | |
| CVE-2026-69443 | Medium | 1.0% | 7.5 | Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Se… | |
| CVE-2026-69519 | Medium | 1.0% | 8.6 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disc… | |
| CVE-2026-70579 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose… | |
| CVE-2026-70587 | Medium | 1.0% | 7.5 | Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attack… | |
| CVE-2026-71330 | Medium | 1.0% | 7.5 | Exposure of sensitive system information to an unauthorized control sphere in Windows Serv… | |
| CVE-2026-72932 | Medium | 1.0% | 7.5 | Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker … | |
| CVE-2026-72989 | Medium | 1.0% | 7.5 | Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker … | |
| CVE-2025-67447 | Medium | 1.0% | 9.8 | The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is… | |
| CVE-2026-20849 | Medium | 1.0% | 7.5 | Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authoriz… | |
| CVE-2026-28323 | Medium | 1.0% | 9.8 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerabi… | |
| CVE-2026-28356 | Medium | 1.0% | 7.5 | multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0… | |
| CVE-2026-94367 | Medium | 1.0% | 7.2 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command inject… | |
| CVE-2026-15965 | Medium | 1.0% | 8.8 | The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress … | |
| CVE-2026-18851 | Medium | 1.0% | 8.8 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2… | |
| CVE-2026-61524 | Medium | 1.0% | 7.2 | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the … | |
| CVE-2026-67192 | Medium | 1.0% | 8.1 | Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnera… | |
| CVE-2026-15969 | Medium | 1.0% | 9.8 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of Sa… | |
| CVE-2026-34648 | Medium | 1.0% | 7.5 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-49163 | Medium | 1.0% | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') in Applicat… | |
| CVE-2026-56196 | Medium | 1.0% | 8.8 | Relative path traversal in Windows Admin Center allows an authorized attacker to execute c… | |
| CVE-2026-59115 | Medium | 1.0% | 9.9 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized atta… | |
| CVE-2026-63509 | Medium | 1.0% | 9.9 | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privi… | |
| CVE-2026-67368 | Medium | 1.0% | 8.8 | Improper link resolution before file access ('link following') in SQL Server allows an aut… | |
| CVE-2026-18284 | Medium | 1.0% | 7.8 | Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerabil… | |
| CVE-2026-50628 | Medium | 1.0% | 9.8 | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound… | |
| CVE-2026-68839 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized… | |
| CVE-2026-69845 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execu… | |
| CVE-2026-14457 | Medium | 1.0% | 7.5 | Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) ena… | |
| CVE-2023-52434 | Medium | 1.0% | 8.1 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix pote… | |
| CVE-2026-76008 | Medium | 1.0% | 10.0 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_… | |
| CVE-2026-77946 | Medium | 1.0% | 10.0 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerab… | |
| CVE-2026-94003 | Medium | 1.0% | 10.0 | A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_cs… | |
| CVE-2021-38633 | Medium | 1.0% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2023-52798 | Medium | 1.0% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix dfs… | |
| CVE-2026-61343 | Medium | 1.0% | 7.2 | LibreBooking's email template editor save action passes the submitted template name direct… | |
| CVE-2026-69100 | Medium | 1.0% | 8.8 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote … | |
| CVE-2026-58023 | Medium | 1.0% | 9.1 | Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apa… | |
| CVE-2022-31339 | Medium | 1.0% | 7.2 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php. | |
| CVE-2023-5379 | Medium | 1.0% | 7.5 | A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size… | |
| CVE-2024-45496 | Medium | 1.0% | 9.9 | A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges … | |
| CVE-2026-14522 | Medium | 1.0% | 8.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 coul… | |
| CVE-2026-4107 | Medium | 1.0% | 7.3 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored… | |
| CVE-2026-34653 | Medium | 1.0% | 8.7 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-27577 | Medium | 1.0% | 9.9 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1… | |
| CVE-2026-76674 | Medium | 1.0% | 9.8 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking… | |
| CVE-2022-37315 | Medium | 1.0% | 7.5 | graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definitio… | |
| CVE-2022-41088 | Medium | 1.0% | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |