Browse vulnerabilities
378,245 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-47429 | High | 0.9% | 9.8 | Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API… | |
| CVE-2018-25254 | High | 0.9% | 9.8 | NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability th… | |
| CVE-2025-59693 | High | 0.9% | 9.8 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi t… | |
| CVE-2026-18924 | High | 0.9% | 9.1 | A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set … | |
| CVE-2026-70470 | High | 0.9% | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-44008 | High | 0.9% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeAr… | |
| CVE-2026-64620 | High | 0.9% | 9.8 | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_… | |
| CVE-2021-47107 | High | 0.8% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buf… | |
| CVE-2026-73602 | High | 0.8% | 9.9 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox… | |
| CVE-2026-2586 | High | 0.8% | 9.1 | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's A… | |
| CVE-2026-44005 | High | 0.8% | 10.0 | vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes m… | |
| CVE-2023-43902 | High | 0.8% | 9.8 | Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 a… | |
| CVE-2026-34935 | High | 0.8% | 9.8 | PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the… | |
| CVE-2025-57631 | High | 0.8% | 9.8 | SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitr… | |
| CVE-2026-44006 | High | 0.8% | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach Bas… | |
| CVE-2026-27727 | High | 0.8% | 9.8 | mchange-commons-java, a library that provides Java utilities, includes code that mirrors e… | |
| CVE-2026-44009 | High | 0.8% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixe… | |
| CVE-2025-55526 | High | 0.8% | 9.1 | n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via th… | |
| CVE-2026-33228 | High | 0.8% | 9.8 | flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted… | |
| CVE-2026-41473 | High | 0.8% | 9.1 | CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the A… | |
| CVE-2023-27202 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27203 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27204 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2023-27205 | High | 0.8% | 9.8 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via… | |
| CVE-2026-48020 | High | 0.8% | 10.0 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, t… | |
| CVE-2026-41242 | High | 0.8% | 9.8 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior… | |
| CVE-2018-25412 | High | 0.8% | 9.8 | Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticate… | |
| CVE-2026-8984 | High | 0.8% | 9.8 | Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code exe… | |
| CVE-2026-13716 | High | 0.7% | 9.1 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remot… | |
| CVE-2026-48024 | High | 0.7% | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and respon… | |
| CVE-2026-34084 | High | 0.7% | 9.8 | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 … | |
| CVE-2026-44181 | High | 0.7% | 10.0 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clu… | |
| CVE-2026-30281 | High | 0.7% | 9.8 | An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to over… | |
| CVE-2025-70141 | High | 0.7% | 9.4 | SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerabil… | |
| CVE-2026-11856 | High | 0.7% | 9.8 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Dig… | |
| CVE-2023-27172 | High | 0.7% | 9.1 | Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows a… | |
| CVE-2026-39906 | High | 0.7% | 10.0 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecat… | |
| CVE-2026-35392 | High | 0.7% | 9.8 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver… | |
| CVE-2026-35393 | High | 0.7% | 9.8 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart uploa… | |
| CVE-2026-35471 | High | 0.7% | 9.8 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing re… | |
| CVE-2026-22872 | High | 0.7% | 9.1 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controll… | |
| CVE-2026-48689 | High | 0.7% | 9.8 | FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overfl… | |
| CVE-2026-8925 | High | 0.7% | 9.8 | The curl logic that works with SASL authentication could end up cleaning up the GSASL cont… | |
| CVE-2025-59695 | High | 0.7% | 9.8 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched… | |
| CVE-2026-30276 | High | 0.7% | 9.8 | An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows atta… | |
| CVE-2026-66897 | High | 0.7% | 9.9 | A path traversal vulnerability in LXD's instance template processing allows an attacker wi… | |
| CVE-2026-8924 | High | 0.7% | 9.1 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies… | |
| CVE-2025-70150 | High | 0.7% | 9.8 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability… | |
| CVE-2026-34612 | High | 0.7% | 9.9 | Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kes… | |
| CVE-2026-28384 | High | 0.7% | 9.9 | An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an… |