Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-19264 | Medium | 1.0% | 9.8 | Postiz is an open-source social media scheduling tool. The route that serves locally store… | |
| CVE-2026-80351 | Medium | 1.0% | 9.8 | Improper neutralization of directives in dynamically evaluated code ('eval injection') vul… | |
| CVE-2026-44795 | Medium | 1.0% | 8.8 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, … | |
| CVE-2026-72551 | Medium | 1.0% | 8.8 | A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with… | |
| CVE-2026-72556 | Medium | 1.0% | 8.8 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user … | |
| CVE-2026-63732 | Medium | 1.0% | 9.9 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default … | |
| CVE-2026-89009 | Medium | 1.0% | 9.1 | WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an una… | |
| CVE-2023-2008 | Medium | 1.0% | 8.2 | A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This… | |
| CVE-2026-55005 | Medium | 1.0% | 8.8 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to e… | |
| CVE-2026-69256 | Medium | 1.0% | 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-91097 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-9863 | Medium | 1.0% | 7.5 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade a… | |
| CVE-2026-5204 | Medium | 1.0% | 8.8 | A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebType… | |
| CVE-2026-5349 | Medium | 1.0% | 8.8 | A vulnerability was identified in Trendnet TEW-657BRM 1.00.1. The affected element is the … | |
| CVE-2026-5350 | Medium | 1.0% | 8.8 | A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is… | |
| CVE-2026-5567 | Medium | 1.0% | 8.8 | A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdv… | |
| CVE-2026-5609 | Medium | 1.0% | 8.8 | A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the f… | |
| CVE-2026-63072 | Medium | 1.0% | 7.5 | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying… | |
| CVE-2026-70306 | Medium | 1.0% | 9.3 | Improper neutralization of input during web page generation ('cross-site scripting') in Mi… | |
| CVE-2026-93839 | Medium | 1.0% | 9.8 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register… | |
| CVE-2026-33210 | Medium | 1.0% | 9.1 | Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2… | |
| CVE-2026-47299 | Medium | 1.0% | 7.2 | Improper neutralization of special elements used in a command ('command injection') in Azu… | |
| CVE-2026-59826 | Medium | 1.0% | 9.1 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 … | |
| CVE-2026-81349 | Medium | 1.0% | 7.2 | Improper neutralization of special elements used in an os command ('os command injection')… | |
| CVE-2026-31072 | Medium | 1.0% | 9.8 | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.… | |
| CVE-2026-46372 | Medium | 1.0% | 8.5 | SillyTavern is a locally installed user interface that allows users to interact with text … | |
| CVE-2026-78657 | Medium | 1.0% | 9.8 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary fi… | |
| CVE-2024-26621 | Medium | 1.0% | 8.2 | In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don'… | |
| CVE-2026-62144 | Medium | 1.0% | 9.1 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain… | |
| CVE-2026-6473 | Medium | 1.0% | 8.8 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database … | |
| CVE-2026-91098 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-18352 | Medium | 1.0% | 7.5 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all v… | |
| CVE-2026-34711 | Medium | 1.0% | 7.5 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by … | |
| CVE-2026-48359 | Medium | 1.0% | 9.6 | Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Ref… | |
| CVE-2026-82310 | Medium | 1.0% | 7.2 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to th… | |
| CVE-2019-25758 | Medium | 1.0% | 8.8 | Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allo… | |
| CVE-2026-59692 | Medium | 1.0% | 7.5 | A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS … | |
| CVE-2026-62910 | Medium | 1.0% | 7.2 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Serv… | |
| CVE-2025-2240 | Medium | 1.0% | 7.5 | A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-me… | |
| CVE-2026-48356 | Medium | 1.0% | 9.3 | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerabi… | |
| CVE-2026-67615 | Medium | 1.0% | 8.8 | openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability … | |
| CVE-2024-41040 | Medium | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix UAF wh… | |
| CVE-2026-5830 | Medium | 1.0% | 8.8 | A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGe… | |
| CVE-2026-80442 | Medium | 1.0% | 9.9 | IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection v… | |
| CVE-2026-84838 | Medium | 1.0% | 7.8 | A flaw was found in rpmuncompress. This command injection vulnerability allows a local att… | |
| CVE-2025-37899 | Medium | 1.0% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-… | |
| CVE-2026-18428 | Medium | 1.0% | 8.8 | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL p… | |
| CVE-2026-32211 | Medium | 1.0% | 9.1 | Missing authentication for critical function in Azure MCP Server allows an unauthorized at… | |
| CVE-2026-48579 | Medium | 1.0% | 9.1 | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to dis… | |
| CVE-2026-82450 | Medium | 1.0% | 8.8 | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZI… |