Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-44673 | Medium | 1.0% | 7.5 | libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in… | |
| CVE-2026-58115 | Medium | 1.0% | 10.0 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All … | |
| CVE-2026-7863 | Medium | 1.0% | 8.4 | Improper neutralization of special elements used in an OS command ('OS command injection')… | |
| CVE-2026-9277 | Medium | 1.0% | 8.1 | shell-quote's `quote()` function did not validate object-token inputs against the operator… | |
| CVE-2024-35248 | Medium | 1.0% | 7.3 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| CVE-2026-6147 | Medium | 1.0% | 8.8 | The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to miss… | |
| CVE-2026-94104 | Medium | 1.0% | 8.8 | NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager… | |
| CVE-2020-3549 | Medium | 1.0% | 8.1 | A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) S… | |
| CVE-2026-3805 | Medium | 1.0% | 7.5 | When doing a second SMB request to the same host again, curl would wrongly use a data poin… | |
| CVE-2026-82003 | Medium | 1.0% | 8.5 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability tha… | |
| CVE-2023-6291 | Medium | 1.0% | 7.1 | A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a … | |
| CVE-2024-38249 | Medium | 1.0% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2026-84218 | Medium | 0.9% | 8.1 | A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of… | |
| CVE-2026-29167 | Medium | 0.9% | 9.8 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configur… | |
| CVE-2026-42359 | Medium | 0.9% | 8.8 | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an… | |
| CVE-2026-47938 | Medium | 0.9% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Serve… | |
| CVE-2026-48331 | Medium | 0.9% | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerabi… | |
| CVE-2026-48333 | Medium | 0.9% | 9.8 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that … | |
| CVE-2026-5260 | Medium | 0.9% | 8.2 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster … | |
| CVE-2020-1068 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in Windows Media Service that allows file c… | |
| CVE-2020-1081 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Printer Service improperly… | |
| CVE-2020-1110 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Update Stack fails to prop… | |
| CVE-2020-1111 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Cl… | |
| CVE-2020-1114 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly h… | |
| CVE-2020-1137 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in the way the Windows Push Notification Se… | |
| CVE-2020-1140 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in … | |
| CVE-2020-1142 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in the way that the Windows Graphics Device… | |
| CVE-2020-1154 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Common Log File System (CL… | |
| CVE-2020-1165 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Cl… | |
| CVE-2020-1166 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Cl… | |
| CVE-2025-2610 | Medium | 0.9% | 7.6 | Improper neutralization of input during web page generation vulnerability in MagnusSolutio… | |
| CVE-2026-40477 | Medium | 0.9% | 9.0 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versi… | |
| CVE-2026-42010 | Medium | 0.9% | 7.1 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-S… | |
| CVE-2026-56718 | Medium | 0.9% | 7.5 | AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnera… | |
| CVE-2026-12940 | Medium | 0.9% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execu… | |
| CVE-2026-28387 | Medium | 0.9% | 8.1 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server auth… | |
| CVE-2026-8633 | Medium | 0.9% | 9.8 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IB… | |
| CVE-2026-16469 | Medium | 0.9% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated … | |
| CVE-2026-48317 | Medium | 0.9% | 9.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dy… | |
| CVE-2026-62906 | Medium | 0.9% | 7.4 | Improper neutralization of special elements in data query logic in Microsoft Discovery Stu… | |
| CVE-2026-80379 | Medium | 0.9% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to… | |
| CVE-2026-80425 | Medium | 0.9% | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to… | |
| CVE-2026-85694 | Medium | 0.9% | 8.1 | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtract… | |
| CVE-2026-13339 | Medium | 0.9% | 7.5 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all vers… | |
| CVE-2026-3843 | Medium | 0.9% | 9.8 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL … | |
| CVE-2026-52778 | Medium | 0.9% | 9.8 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulne… | |
| CVE-2026-61551 | Medium | 0.9% | 8.6 | Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing… | |
| CVE-2026-67920 | Medium | 0.9% | 8.8 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.hal… | |
| CVE-2026-74845 | Medium | 0.9% | 8.8 | Official Document Management System developed by 2100 Technology has an Arbitrary File Upl… | |
| CVE-2026-77929 | Medium | 0.9% | 8.8 | ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authentic… |