Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-26889 | Medium | 1.1% | 7.8 | Windows Update Stack Elevation of Privilege Vulnerability | |
| CVE-2021-42296 | Medium | 1.1% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2026-19942 | Medium | 1.1% | 8.1 | The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client F… | |
| CVE-2026-74469 | Medium | 1.1% | 8.8 | In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer tr… | |
| CVE-2026-52103 | Medium | 1.1% | 9.8 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs co… | |
| CVE-2026-53451 | Medium | 1.1% | 9.8 | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware co… | |
| CVE-2026-9064 | Medium | 1.1% | 7.5 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP s… | |
| CVE-2026-25855 | Medium | 1.1% | 8.8 | OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allo… | |
| CVE-2026-85656 | Medium | 1.1% | 7.8 | An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux… | |
| CVE-2021-34483 | Medium | 1.1% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2026-49819 | Medium | 1.1% | 9.8 | UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-… | |
| CVE-2025-48431 | Medium | 1.1% | 7.5 | Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindi… | |
| CVE-2026-18948 | Medium | 1.1% | 9.9 | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs… | |
| CVE-2026-86439 | Medium | 1.1% | 8.8 | knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, all… | |
| CVE-2026-58662 | Medium | 1.1% | 9.1 | Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Ap… | |
| CVE-2026-65414 | Medium | 1.1% | 9.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fi… | |
| CVE-2025-31104 | Medium | 1.1% | 7.2 | A improper neutralization of special elements used in an os command ('os command injection… | |
| CVE-2026-16610 | Medium | 1.1% | 9.8 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Cod… | |
| CVE-2026-4424 | Medium | 1.1% | 7.5 | A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the R… | |
| CVE-2026-57967 | Medium | 1.1% | 9.8 | An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to st… | |
| CVE-2026-75431 | Medium | 1.1% | 9.1 | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for … | |
| CVE-2026-78175 | Medium | 1.1% | 8.8 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to… | |
| CVE-2020-1143 | Medium | 1.1% | 7.0 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode dri… | |
| CVE-2026-15991 | Medium | 1.1% | 8.8 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insu… | |
| CVE-2026-71957 | Medium | 1.1% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_20260211004… | |
| CVE-2026-71958 | Medium | 1.1% | 9.8 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_20260211004… | |
| CVE-2020-15670 | Medium | 1.1% | 8.8 | Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of … | |
| CVE-2022-41044 | Medium | 1.1% | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | |
| CVE-2026-26897 | Medium | 1.1% | 9.8 | An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allow… | |
| CVE-2026-32173 | Medium | 1.1% | 8.6 | Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose inf… | |
| CVE-2026-50429 | Medium | 1.1% | 8.2 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose informati… | |
| CVE-2026-11527 | Medium | 1.1% | 8.6 | Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file ove… | |
| CVE-2026-4890 | Medium | 1.1% | 7.5 | A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote … | |
| CVE-2026-48913 | Medium | 1.1% | 7.3 | Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are … | |
| CVE-2023-23374 | Medium | 1.1% | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| CVE-2026-1615 | Medium | 1.1% | 9.8 | Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection v… | |
| CVE-2026-2942 | Medium | 1.1% | 9.8 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due… | |
| CVE-2021-26865 | Medium | 1.1% | 8.8 | Windows Container Execution Agent Elevation of Privilege Vulnerability | |
| CVE-2026-31228 | Medium | 1.1% | 9.8 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vuln… | |
| CVE-2026-66321 | Medium | 1.1% | 7.4 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-… | |
| CVE-2026-86184 | Medium | 1.1% | 9.8 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screens… | |
| CVE-2026-40984 | Medium | 1.1% | 7.5 | In Micrometer, it is possible for a user to provide specially crafted HTTP requests that m… | |
| CVE-2026-42440 | Medium | 1.1% | 7.5 | OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader… | |
| CVE-2023-22460 | Medium | 1.1% | 7.5 | go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interface… | |
| CVE-2026-86242 | Medium | 1.1% | 8.1 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP… | |
| CVE-2026-31040 | Medium | 1.1% | 9.8 | A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation… | |
| CVE-2026-67868 | Medium | 1.1% | 9.8 | A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventF… | |
| CVE-2026-67870 | Medium | 1.1% | 9.8 | In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete v… | |
| CVE-2026-75050 | Medium | 1.1% | 7.1 | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via craft… | |
| CVE-2026-18911 | Medium | 1.1% | 7.5 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authenticat… |