Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-42039 | Medium | 1.0% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31… | |
| CVE-2026-44496 | Medium | 1.0% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.… | |
| CVE-2026-48553 | Medium | 1.0% | 7.5 | Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated re… | |
| CVE-2026-48554 | Medium | 1.0% | 7.5 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated re… | |
| CVE-2026-54629 | Medium | 1.0% | 7.5 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server ex… | |
| CVE-2021-26899 | Medium | 1.0% | 7.8 | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
| CVE-2021-27364 | Medium | 1.0% | 7.1 | An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_is… | |
| CVE-2026-42264 | Medium | 1.0% | 7.4 | Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to be… | |
| CVE-2026-91103 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-4598 | Medium | 1.0% | 7.5 | Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bn… | |
| CVE-2026-67614 | Medium | 1.0% | 9.8 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal … | |
| CVE-2026-91101 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-91104 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-91106 | Medium | 1.0% | 9.8 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP… | |
| CVE-2026-13423 | Medium | 1.0% | 9.8 | The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce ver… | |
| CVE-2026-18391 | Medium | 1.0% | 9.8 | The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input b… | |
| CVE-2026-19952 | Medium | 1.0% | 7.5 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file dele… | |
| CVE-2026-67191 | Medium | 1.0% | 9.8 | Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerab… | |
| CVE-2026-76578 | Medium | 1.0% | 9.8 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authenticatio… | |
| CVE-2026-82954 | Medium | 1.0% | 9.9 | A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writ… | |
| CVE-2022-32981 | Medium | 1.0% | 7.8 | An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. Th… | |
| CVE-2026-75149 | Medium | 1.0% | 8.8 | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuratio… | |
| CVE-2026-81642 | Medium | 1.0% | 9.8 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC … | |
| CVE-2026-83497 | Medium | 1.0% | 8.8 | Unrestricted deserialization of untrusted data in the cursor pagination component in the O… | |
| CVE-2017-20237 | Medium | 1.0% | 9.8 | Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentic… | |
| CVE-2026-18649 | Medium | 1.0% | 7.5 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265de… | |
| CVE-2026-48386 | Medium | 1.0% | 7.5 | ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability… | |
| CVE-2026-23600 | Medium | 1.0% | 9.8 | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APL… | |
| CVE-2026-43642 | Medium | 1.0% | 8.1 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection v… | |
| CVE-2026-5598 | Medium | 1.0% | 7.5 | Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on al… | |
| CVE-2024-27388 | Medium | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some meml… | |
| CVE-2026-47871 | Medium | 1.0% | 8.8 | VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path … | |
| CVE-2026-50027 | Medium | 1.0% | 9.8 | mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all H… | |
| CVE-2017-20284 | Medium | 1.0% | 7.5 | Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-do… | |
| CVE-2026-11430 | Medium | 1.0% | 7.3 | Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token… | |
| CVE-2026-40411 | Medium | 1.0% | 9.9 | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker t… | |
| CVE-2026-54120 | Medium | 1.0% | 9.9 | Improper input validation in Microsoft Surface allows an authorized attacker to execute co… | |
| CVE-2026-65811 | Medium | 1.0% | 8.8 | Improper input validation in Power BI allows an authorized attacker to execute code over a… | |
| CVE-2024-36912 | Medium | 1.0% | 9.6 | In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: T… | |
| CVE-2026-23823 | Medium | 1.0% | 7.2 | A vulnerability in the command line interface of Access Points running AOS-10 could allow … | |
| CVE-2026-63520 | Medium | 1.0% | 8.1 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker t… | |
| CVE-2026-5550 | Medium | 1.0% | 8.8 | A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the fun… | |
| CVE-2022-50671 | Medium | 1.0% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix "kernel… | |
| CVE-2022-50676 | Medium | 1.0% | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: rds: don't hold … | |
| CVE-2026-15011 | Medium | 1.0% | 9.8 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code I… | |
| CVE-2026-44189 | Medium | 1.0% | 7.8 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookR… | |
| CVE-2026-55159 | Medium | 1.0% | 8.8 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that … | |
| CVE-2026-72867 | Medium | 1.0% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, … | |
| CVE-2026-72901 | Medium | 1.0% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy a… | |
| CVE-2026-90817 | Medium | 1.0% | 9.8 | An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough… |