|
cve-2026-2699
|
CVE-2026-2699 |
CRITICAL
|
9.8
|
59.51%
|
cvelistv5 |
|
|
cve-2026-2652
|
mlflow: mlflow: Authentication bypass allows unauthorized job management and data injection |
HIGH
|
8.6
|
20.78%
|
cvelistv5 |
2026-07-08 |
|
cve-2026-20253
|
Splunk Enterprise Missing Authentication for Critical Function Vulnerability |
CRITICAL
|
9.8
|
96.94%
|
cvelistv5 |
2026-06-18 |
|
cve-2026-1547
|
Totolink A7000R cstecgi.cgi setUnloadUserData command injection |
MEDIUM
|
6.3
|
2.88%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-1207
|
Django: Django: SQL Injection via RasterField band index parameter |
HIGH
|
8.3
|
13.25%
|
cvelistv5 |
2026-07-15 |
|
cve-2025-60702
|
CVE-2025-60702 |
MEDIUM
|
6.5
|
2.54%
|
cvelistv5 |
|
|
cve-2025-60698
|
CVE-2025-60698 |
HIGH
|
7.3
|
3.93%
|
cvelistv5 |
|
|
cve-2025-60687
|
CVE-2025-60687 |
MEDIUM
|
6.5
|
6.61%
|
cvelistv5 |
|
|
cve-2025-6068
|
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
MEDIUM
|
6.4
|
0.22%
|
cvelistv5 |
2026-06-17 |
|
cve-2025-14208
|
CVE-2025-14208 |
MEDIUM
|
6.5
|
3.39%
|
cvelistv5 |
|
|
cve-2025-10164
|
CVE-2025-10164 |
HIGH
|
7.5
|
0.40%
|
cvelistv5 |
|
|
cve-2024-12912
|
CVE-2024-12912 |
HIGH
|
7.2
|
1.24%
|
cvelistv5 |
|
|
cve-2023-37569
|
CVE-2023-37569 |
HIGH
|
8.8
|
33.89%
|
cvelistv5 |
|
|
cve-2022-50992
|
CVE-2022-50992 |
HIGH
|
8.7
|
0.70%
|
cvelistv5 |
|
|
cve-2021-27691
|
CVE-2021-27691 |
HIGH
|
N/A
|
25.18%
|
cvelistv5 |
|
|
cve-2019-12725
|
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters. |
CRITICAL
|
9.8
|
89.85%
|
cvelistv5 |
2026-06-17 |
|
cve-2019-10655
|
CVE-2019-10655 |
HIGH
|
N/A
|
15.47%
|
cvelistv5 |
|
|
cve-2016-5312
|
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream. |
MEDIUM
|
6.5
|
53.70%
|
cvelistv5 |
2026-06-17 |
|
cve-2026-87491
|
Google Chromium V8 Out of Bounds Write Vulnerability |
HIGH
|
N/A
|
1.00%
|
cvelistv5 |
2026-09-09 |
|
cve-2026-20079
|
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability |
CRITICAL
|
10.0
|
75.75%
|
cvelistv5 |
2026-09-09 |
|
cve-2026-19490
|
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability |
CRITICAL
|
9.3
|
5.60%
|
cvelistv5 |
2026-09-09 |
|
cve-2025-25249
|
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability |
HIGH
|
8.1
|
2.40%
|
cvelistv5 |
2026-09-09 |
|
cve-2026-21509
|
Microsoft Office Security Feature Bypass Vulnerability |
HIGH
|
N/A
|
72.55%
|
cvelistv5 |
2026-01-26 |
|
cve-2025-53770
|
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
CRITICAL
|
9.8
|
100.00%
|
cvelistv5 |
2025-07-20 |
|
cve-2026-1340
|
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability |
HIGH
|
N/A
|
98.68%
|
cvelistv5 |
2026-04-08 |
|
cve-2026-1281
|
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability |
HIGH
|
N/A
|
98.58%
|
cvelistv5 |
2026-01-29 |
|
cve-2023-28771
|
Zyxel Multiple Firewalls OS Command Injection Vulnerability |
CRITICAL
|
9.8
|
99.28%
|
cvelistv5 |
2023-05-31 |
|
cve-2026-21509
|
Microsoft Office Security Feature Bypass Vulnerability |
HIGH
|
N/A
|
72.55%
|
cvelistv5 |
2026-01-26 |
|
cve-2026-1340
|
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability |
HIGH
|
N/A
|
98.68%
|
cvelistv5 |
2026-04-08 |
|
cve-2026-1281
|
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability |
HIGH
|
N/A
|
98.58%
|
cvelistv5 |
2026-01-29 |