Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-14890 | Medium | 1.0% | 9.1 | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a rou… | |
| CVE-2026-39849 | Medium | 1.0% | 8.8 | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker bloc… | |
| CVE-2021-2316 | Medium | 1.0% | 8.1 | Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: F… | |
| CVE-2026-69276 | Medium | 1.0% | 9.8 | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows a… | |
| CVE-2026-69431 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute cod… | |
| CVE-2026-69493 | Medium | 1.0% | 9.8 | Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to exe… | |
| CVE-2026-18613 | Medium | 1.0% | 9.8 | A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the fu… | |
| CVE-2026-34838 | Medium | 1.0% | 9.9 | Group-Office is an enterprise customer relationship management and groupware tool. Prior t… | |
| CVE-2026-68791 | Medium | 1.0% | 8.6 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to discl… | |
| CVE-2026-85917 | Medium | 1.0% | 7.5 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to … | |
| CVE-2026-32725 | Medium | 1.0% | 8.3 | SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior t… | |
| CVE-2026-37007 | Medium | 1.0% | 9.8 | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to… | |
| CVE-2026-5570 | Medium | 1.0% | 7.3 | A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affect… | |
| CVE-2026-58016 | Medium | 1.0% | 7.5 | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml()… | |
| CVE-2026-49849 | Medium | 1.0% | 9.1 | xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerabili… | |
| CVE-2026-32141 | Medium | 1.0% | 7.5 | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recur… | |
| CVE-2026-47992 | Medium | 1.0% | 7.2 | Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQ… | |
| CVE-2026-75746 | Medium | 1.0% | 9.1 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Co… | |
| CVE-2026-82009 | Medium | 1.0% | 9.1 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2025-5459 | Medium | 1.0% | 8.8 | A user with specific node group editing permissions and a specially crafted class paramete… | |
| CVE-2026-43501 | Medium | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve ma… | |
| CVE-2026-71558 | Medium | 1.0% | 9.8 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects … | |
| CVE-2026-65098 | Medium | 1.0% | 8.1 | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, w… | |
| CVE-2026-85102 | Medium | 1.0% | 9.8 | Improper certificate trust validation during VPN negotiation in Check Point Quantum Securi… | |
| CVE-2026-18245 | Medium | 1.0% | 9.0 | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 … | |
| CVE-2026-45162 | Medium | 1.0% | 8.0 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) an… | |
| CVE-2026-47295 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… | |
| CVE-2026-56197 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in a command ('command injection') in Win… | |
| CVE-2026-5685 | Medium | 1.0% | 8.8 | A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromA… | |
| CVE-2026-5686 | Medium | 1.0% | 8.8 | A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects… | |
| CVE-2026-5687 | Medium | 1.0% | 8.8 | A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function… | |
| CVE-2026-66819 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… | |
| CVE-2026-66820 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… | |
| CVE-2026-67370 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQ… | |
| CVE-2026-68782 | Medium | 1.0% | 9.9 | Improper neutralization of special elements used in an sql command ('sql injection') in Az… | |
| CVE-2026-68789 | Medium | 1.0% | 9.9 | Improper neutralization of special elements used in an sql command ('sql injection') in Az… | |
| CVE-2026-69716 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in Mi… | |
| CVE-2026-77908 | Medium | 1.0% | 8.8 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows… | |
| CVE-2026-85885 | Medium | 1.0% | 9.9 | Improper neutralization of special elements used in a command ('command injection') in M36… | |
| CVE-2026-46625 | Medium | 1.0% | 7.5 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version … | |
| CVE-2020-1079 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists when the Windows fails to properly handle o… | |
| CVE-2023-35371 | Medium | 1.0% | 7.8 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2023-35372 | Medium | 1.0% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2023-36896 | Medium | 1.0% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2026-10973 | Medium | 1.0% | 7.4 | Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacke… | |
| CVE-2026-5707 | Medium | 1.0% | 8.8 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Res… | |
| CVE-2026-5709 | Medium | 1.0% | 8.8 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) vers… | |
| CVE-2026-75429 | Medium | 1.0% | 9.8 | PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulne… | |
| CVE-2026-81537 | Medium | 1.0% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to… | |
| CVE-2026-86124 | Medium | 1.0% | 9.8 | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP serve… |