Browse vulnerabilities
378,245 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-27634 | High | 0.7% | 9.8 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, t… | |
| CVE-2026-2587 | High | 0.6% | 9.6 | A critical Remote Code Execution (RCE) vulnerability was identified in the server-side tem… | |
| CVE-2026-5067 | High | 0.6% | 9.8 | A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server W… | |
| CVE-2026-53622 | High | 0.6% | 10.0 | Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2… | |
| CVE-2026-34745 | High | 0.6% | 9.1 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix … | |
| CVE-2026-39907 | High | 0.6% | 10.0 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthe… | |
| CVE-2026-30285 | High | 0.6% | 9.8 | An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows… | |
| CVE-2026-61800 | High | 0.6% | 9.1 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for en… | |
| CVE-2026-10536 | High | 0.6% | 9.8 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 … | |
| CVE-2026-5241 | High | 0.6% | 9.6 | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.… | |
| CVE-2026-42074 | High | 0.6% | 9.8 | OpenClaude is an open-source coding-agent command line interface for cloud and local model… | |
| CVE-2026-9079 | High | 0.6% | 9.8 | libcurl had a flaw that when instructed to clear proxy authentication credentials which ma… | |
| CVE-2026-62948 | High | 0.6% | 9.6 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd w… | |
| CVE-2025-70146 | High | 0.6% | 9.1 | Missing authentication in multiple administrative action scripts under /admin/ in ProjectW… | |
| CVE-2026-48162 | High | 0.6% | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-45411 | High | 0.6% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a h… | |
| CVE-2026-40035 | High | 0.6% | 9.1 | Unfurl through 2025.08 contains an improper input validation vulnerability in config parsi… | |
| CVE-2026-44180 | High | 0.6% | 9.8 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-27962 | High | 0.5% | 9.1 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to versio… | |
| CVE-2026-35053 | High | 0.5% | 9.8 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.4… | |
| CVE-2026-33229 | High | 0.5% | 9.8 | XWiki Platform is a generic wiki platform offering runtime services for applications built… | |
| CVE-2026-34934 | High | 0.5% | 9.8 | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads… | |
| CVE-2026-41586 | High | 0.5% | 9.8 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for de… | |
| CVE-2026-66421 | High | 0.5% | 9.3 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauth… | |
| CVE-2025-38089 | High | 0.5% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GA… | |
| CVE-2026-60113 | High | 0.5% | 9.8 | AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a … | |
| CVE-2026-49441 | High | 0.5% | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-54058 | High | 0.5% | 9.1 | Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McI… | |
| CVE-2026-66418 | High | 0.5% | 9.3 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows… | |
| CVE-2026-35579 | High | 0.5% | 9.8 | CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, a… | |
| CVE-2026-42880 | High | 0.5% | 9.6 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.… | |
| CVE-2026-44210 | High | 0.5% | 9.9 | Kata Containers is an open source project focusing on a standard implementation of lightwe… | |
| CVE-2026-8927 | High | 0.5% | 9.1 | When reusing a libcurl handle for sequential transfers driven by environment-variable prox… | |
| CVE-2026-34449 | High | 0.5% | 9.6 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious webs… | |
| CVE-2026-44182 | High | 0.5% | 10.0 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-51536 | High | 0.5% | 9.1 | In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) ne… | |
| CVE-2026-74899 | High | 0.5% | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPl… | |
| CVE-2026-34448 | High | 0.5% | 9.0 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who … | |
| CVE-2026-10050 | High | 0.5% | 9.1 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encod… | |
| CVE-2026-46624 | High | 0.5% | 9.9 | Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution … | |
| CVE-2026-51537 | High | 0.5% | 9.1 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection … | |
| CVE-2026-63293 | High | 0.5% | 9.9 | A link following vulnerability in LXD allows an attacker to achieve arbitrary file read an… | |
| CVE-2026-4599 | High | 0.5% | 9.1 | Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplet… | |
| CVE-2026-69263 | High | 0.5% | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-25896 | High | 0.5% | 9.3 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS… | |
| CVE-2026-63298 | High | 0.5% | 9.9 | An improper neutralization of special elements vulnerability in LXD's NVIDIA instance conf… | |
| CVE-2026-48773 | High | 0.5% | 9.8 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 throug… | |
| CVE-2025-59703 | High | 0.5% | 9.1 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched… | |
| CVE-2026-69258 | High | 0.5% | 9.1 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2025-70152 | High | 0.4% | 9.8 | code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injectio… |