Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-1579 | Medium | 0.9% | 9.8 | The MAVLink communication protocol does not require cryptographic authentication by defau… | |
| CVE-2026-50772 | Medium | 0.9% | 9.8 | An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrar… | |
| CVE-2026-51990 | Medium | 0.9% | 9.8 | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote … | |
| CVE-2026-52439 | Medium | 0.9% | 9.8 | An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via t… | |
| CVE-2026-63586 | Medium | 0.9% | 9.8 | The web-based management interface uses a modified uhttpd server with CGI shell scripts. T… | |
| CVE-2026-67919 | Medium | 0.9% | 9.8 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginE… | |
| CVE-2026-71624 | Medium | 0.9% | 9.8 | An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the c… | |
| CVE-2026-75357 | Medium | 0.9% | 9.8 | An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code v… | |
| CVE-2026-18431 | Medium | 0.9% | 9.8 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to,… | |
| CVE-2026-72735 | Medium | 0.9% | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTrae… | |
| CVE-2021-1729 | Medium | 0.9% | 7.1 | Windows Update Stack Setup Elevation of Privilege Vulnerability | |
| CVE-2026-42033 | Medium | 0.9% | 7.4 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31… | |
| CVE-2026-48567 | Medium | 0.9% | 10.0 | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to el… | |
| CVE-2026-5436 | Medium | 0.9% | 8.1 | The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versi… | |
| CVE-2026-58275 | Medium | 0.9% | 10.0 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges o… | |
| CVE-2026-62825 | Medium | 0.9% | 10.0 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate priv… | |
| CVE-2026-66047 | Medium | 0.9% | 8.1 | ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated r… | |
| CVE-2018-25427 | Medium | 0.9% | 9.8 | Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote att… | |
| CVE-2022-20854 | Medium | 0.9% | 7.5 | A vulnerability in the processing of SSH connections of Cisco Firepower Management Center … | |
| CVE-2022-20946 | Medium | 0.9% | 8.6 | A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of… | |
| CVE-2022-20947 | Medium | 0.9% | 8.6 | A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security … | |
| CVE-2024-38216 | Medium | 0.9% | 8.2 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| CVE-2026-17142 | Medium | 0.9% | 9.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arb… | |
| CVE-2026-19874 | Medium | 0.9% | 9.1 | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, origina… | |
| CVE-2026-19912 | Medium | 0.9% | 9.8 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code exec… | |
| CVE-2026-32641 | Medium | 0.9% | 7.5 | Parseable is a log analytics platform built for high-volume data ingestion and analysis. P… | |
| CVE-2026-57281 | Medium | 0.9% | 7.5 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST t… | |
| CVE-2026-58076 | Medium | 0.9% | 8.8 | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_stri… | |
| CVE-2026-72950 | Medium | 0.9% | 8.8 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker … | |
| CVE-2026-73625 | Medium | 0.9% | 8.8 | GitPython versions before 3.1.54 contain a remote code execution vulnerability in the chec… | |
| CVE-2024-42284 | Medium | 0.9% | 9.1 | In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero… | |
| CVE-2026-57990 | Medium | 0.9% | 7.4 | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) all… | |
| CVE-2026-65802 | Medium | 0.9% | 7.4 | External control of file name or path in Microsoft Edge for Android allows an unauthorized… | |
| CVE-2026-75865 | Medium | 0.9% | 9.8 | The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Conse… | |
| CVE-2026-81383 | Medium | 0.9% | 7.4 | Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized… | |
| CVE-2026-85426 | Medium | 0.9% | 9.8 | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS clie… | |
| CVE-2020-37216 | Medium | 0.9% | 7.5 | Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service… | |
| CVE-2026-69399 | Medium | 0.9% | 10.0 | Azure Arc Elevation of Privilege Vulnerability | |
| CVE-2026-69843 | Medium | 0.9% | 10.0 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to e… | |
| CVE-2026-70352 | Medium | 0.9% | 10.0 | Missing authentication for critical function in Azure AI Language allows an unauthorized a… | |
| CVE-2026-85889 | Medium | 0.9% | 10.0 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized at… | |
| CVE-2026-16843 | Medium | 0.9% | 7.2 | Some Hikvision Networking Products are vulnerable to authenticated command execution due t… | |
| CVE-2026-21837 | Medium | 0.9% | 8.8 | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital… | |
| CVE-2026-32286 | Medium | 0.9% | 7.5 | The DataRow.Decode function fails to properly validate field lengths. A malicious or compr… | |
| CVE-2023-20006 | Medium | 0.9% | 8.6 | A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive… | |
| CVE-2026-34647 | Medium | 0.9% | 7.4 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 a… | |
| CVE-2026-35031 | Medium | 0.9% | 9.9 | Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a v… | |
| CVE-2026-44604 | Medium | 0.9% | 7.0 | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. Wh… | |
| CVE-2026-56748 | Medium | 0.9% | 8.8 | Improper validation of symbolic links in the Pack Git import feature in Cribl Stream befor… | |
| CVE-2026-5857 | Medium | 0.9% | 8.1 | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_l… |