CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-10026 HIGH

CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution

CVSS 7.2 EPSS n/a Oct 2, 2026
CVE-2026-93367 HIGH

Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)

CVSS 7.2 EPSS n/a Oct 2, 2026
CVE-2026-103098 HIGH

Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted…

CVSS 7.5 EPSS n/a Oct 2, 2026
CVE-2026-103097 HIGH

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials…

CVSS 7.5 EPSS n/a Oct 2, 2026
CVE-2026-103096 HIGH

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials di…

CVSS 7.5 EPSS n/a Oct 2, 2026
CVE-2026-103766 HIGH

ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter

CVSS 8.6 EPSS n/a Oct 1, 2026
CVE-2026-103765 HIGH

Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server

CVSS 8.8 EPSS n/a Oct 1, 2026
CVE-2026-103761 HIGH

Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue

CVSS 8.7 EPSS n/a Oct 1, 2026
CVE-2026-103760 HIGH

Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write

CVSS 8.2 EPSS n/a Oct 1, 2026
CVE-2025-71427 HIGH

Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image

CVSS 7.6 EPSS n/a Oct 1, 2026
CVE-2026-86344 HIGH

389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue

CVSS 7.5 EPSS n/a Oct 1, 2026
CVE-2026-64893 HIGH

- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO…

CVSS 7.3 EPSS n/a Oct 1, 2026
CVE-2026-104356 HIGH

PictShare < 3.7.1 Predictable Delete Code via rand()

CVSS 8.2 EPSS n/a Oct 1, 2026
CVE-2026-34494 HIGH

- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series M…

CVSS 7.2 EPSS n/a Oct 1, 2026
CVE-2026-34493 HIGH

- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: bef…

CVSS 7.2 EPSS n/a Oct 1, 2026
CVE-2026-104051 HIGH

PictShare < 3.7.1 Sensitive Information Disclosure via info API

CVSS 8.8 EPSS n/a Oct 1, 2026
CVE-2026-71452 HIGH

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.

CVSS 7.2 EPSS n/a Oct 1, 2026
CVE-2026-104020 HIGH

Uncontrolled recursion in the Ion reader in Amazon Ion Python

CVSS 8.7 EPSS n/a Oct 1, 2026
CVE-2026-96780 HIGH

figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width

CVSS 8.2 EPSS n/a Oct 1, 2026
CVE-2026-102514 HIGH

Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive

CVSS 8.4 EPSS n/a Oct 1, 2026
CVE-2026-55396 HIGH

Unencrypted UDP Control Traffic in Teledyne FLIR Robots running Aware2

CVSS 8.5 EPSS n/a Oct 1, 2026
CVE-2026-14983 HIGH

Missing Authentication in Teledyne FLIR Robots running Aware2

CVSS 7.1 EPSS n/a Oct 1, 2026
CVE-2026-53964 HIGH

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

CVSS 7.2 EPSS n/a Oct 1, 2026
CVE-2026-103484 HIGH

pgvector buffer overflow in IVFFlat index build

CVSS 8.8 EPSS n/a Oct 1, 2026
CVE-2026-54049 HIGH

Sakai Conversations has a Stored XSS Issue

CVSS 8.7 EPSS 0.03% Oct 1, 2026

Showing 1 to 25 CVEs · page 1 (more available)