Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-52680 | Medium | 1.1% | 9.8 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart file… | |
| CVE-2026-33701 | Medium | 1.1% | 9.8 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrum… | |
| CVE-2026-41252 | Medium | 1.1% | 9.8 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds chec… | |
| CVE-2026-80104 | Medium | 1.1% | 9.8 | DB-GPT builds the destination path for an uploaded skill from the multipart filename witho… | |
| CVE-2026-56186 | Medium | 1.1% | 8.1 | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose informati… | |
| CVE-2026-67367 | Medium | 1.1% | 8.6 | A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), … | |
| CVE-2025-9566 | Medium | 1.1% | 8.1 | There's a vulnerability in podman where an attacker may use the kube play command to overw… | |
| CVE-2026-85684 | Medium | 1.1% | 9.1 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload… | |
| CVE-2026-3083 | Medium | 1.1% | 8.8 | GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulne… | |
| CVE-2026-50223 | Medium | 1.1% | 8.8 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz al… | |
| CVE-2026-86438 | Medium | 1.1% | 7.2 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule … | |
| CVE-2026-20854 | Medium | 1.1% | 7.5 | Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an aut… | |
| CVE-2026-20922 | Medium | 1.1% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code l… | |
| CVE-2026-72776 | Medium | 1.1% | 9.8 | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerabili… | |
| CVE-2026-39276 | Medium | 1.1% | 7.2 | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowi… | |
| CVE-2026-69111 | Medium | 1.1% | 7.5 | Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerabilit… | |
| CVE-2026-73601 | Medium | 1.1% | 8.8 | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom … | |
| CVE-2026-16099 | Medium | 1.1% | 8.8 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletio… | |
| CVE-2026-80156 | Medium | 1.1% | 9.1 | Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and … | |
| CVE-2026-48318 | Medium | 1.1% | 9.9 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory (… | |
| CVE-2026-71513 | Medium | 1.1% | 8.8 | NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler th… | |
| CVE-2026-72579 | Medium | 1.1% | 7.5 | An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjac… | |
| CVE-2026-18588 | Medium | 1.1% | 9.8 | A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the func… | |
| CVE-2026-18589 | Medium | 1.1% | 9.8 | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function … | |
| CVE-2026-5680 | Medium | 1.1% | 7.5 | A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sendin… | |
| CVE-2026-75784 | Medium | 1.1% | 10.0 | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is t… | |
| CVE-2026-79911 | Medium | 1.1% | 10.0 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The a… | |
| CVE-2026-82542 | Medium | 1.1% | 10.0 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the func… | |
| CVE-2026-85109 | Medium | 1.1% | 9.8 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function fo… | |
| CVE-2023-21717 | Medium | 1.1% | 8.8 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| CVE-2025-37778 | Medium | 1.1% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix dangling p… | |
| CVE-2026-15307 | Medium | 1.1% | 8.8 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatia… | |
| CVE-2026-15358 | Medium | 1.1% | 7.5 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671… | |
| CVE-2026-1771 | Medium | 1.1% | 7.2 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil… | |
| CVE-2026-35091 | Medium | 1.1% | 8.2 | A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return… | |
| CVE-2026-77110 | Medium | 1.1% | 7.6 | Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directo… | |
| CVE-2026-41939 | Medium | 1.1% | 9.8 | Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bun… | |
| CVE-2025-43433 | Medium | 1.1% | 8.8 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1,… | |
| CVE-2026-14524 | Medium | 1.1% | 9.1 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion du… | |
| CVE-2026-3593 | Medium | 1.1% | 7.4 | A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue… | |
| CVE-2026-12357 | Medium | 1.1% | 7.2 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vuln… | |
| CVE-2026-22893 | Medium | 1.1% | 7.2 | A command injection vulnerability has been reported to affect several QNAP operating syste… | |
| CVE-2026-75825 | Medium | 1.1% | 8.8 | ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager P… | |
| CVE-2024-21329 | Medium | 1.1% | 7.3 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | |
| CVE-2026-48324 | Medium | 1.1% | 9.1 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Co… | |
| CVE-2026-45018 | Medium | 1.1% | 9.8 | Chainlit is a Python framework for building production-ready conversational AI application… | |
| CVE-2026-59561 | Medium | 1.1% | 7.8 | Sakura Editor provided by Sakura Editor Development Community contains an OS command injec… | |
| CVE-2026-88622 | Medium | 1.1% | 8.8 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_priv… | |
| CVE-2026-90919 | Medium | 1.1% | 9.8 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server… | |
| CVE-2026-9133 | Medium | 1.1% | 7.7 | Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.… |