CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-104123 MEDIUM

SourceCodester Online Reviewer Management System btn_functions.php activity sql injection

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-104120 MEDIUM

modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-104054 MEDIUM

calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization

CVSS 5.3 EPSS n/a Oct 2, 2026
CVE-2026-104053 MEDIUM

itsourcecode Pet Shop Management System admin_reservefilter.php sql injection

CVSS 5.3 EPSS n/a Oct 2, 2026
CVE-2026-21140 MEDIUM

Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

CVSS 6.9 EPSS n/a Oct 2, 2026
CVE-2026-104052 MEDIUM

itsourcecode Pet Shop Management System admin_reject_completed.php sql injection

CVSS 5.3 EPSS n/a Oct 2, 2026
CVE-2026-27873 MEDIUM

- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.

CVSS 5.6 EPSS n/a Oct 1, 2026
CVE-2026-64892 MEDIUM

- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy I…

CVSS 6.3 EPSS n/a Oct 1, 2026
CVE-2026-71448 MEDIUM

: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: befo…

CVSS 5.6 EPSS n/a Oct 1, 2026
CVE-2026-71454 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site…

CVSS 5.8 EPSS n/a Oct 1, 2026
CVE-2026-71453 MEDIUM

- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.

CVSS 5.6 EPSS n/a Oct 1, 2026
CVE-2026-104002 MEDIUM

Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

CVSS 6.0 EPSS n/a Oct 1, 2026
CVE-2026-71451 MEDIUM

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.

CVSS 5.6 EPSS n/a Oct 1, 2026
CVE-2026-27874 MEDIUM

: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects Ea…

CVSS 5.0 EPSS n/a Oct 1, 2026
CVE-2026-102370 MEDIUM

Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71

CVSS 5.4 EPSS n/a Oct 1, 2026
CVE-2026-104183 MEDIUM

stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects

CVSS 5.1 EPSS n/a Oct 1, 2026
CVE-2026-104182 MEDIUM

stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk

CVSS 6.2 EPSS n/a Oct 1, 2026
CVE-2026-104181 MEDIUM

Filament: Multi-factor authentication (app) management actions do not require password reauthentication

CVSS 5.4 EPSS n/a Oct 1, 2026
CVE-2026-55394 MEDIUM

Unencrypted 802.11 Network in Teledyne FLIR Robots running Aware2

CVSS 5.3 EPSS n/a Oct 1, 2026
CVE-2026-55252 MEDIUM

OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect

CVSS 5.1 EPSS n/a Oct 1, 2026
Go
CVE-2026-55251 MEDIUM

NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files

CVSS 6.5 EPSS n/a Oct 1, 2026
CVE-2026-100251 MEDIUM

Wormhole.app SSRF

CVSS 6.9 EPSS n/a Oct 1, 2026
CVE-2026-93832 MEDIUM

A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.

CVSS 4.8 EPSS n/a Oct 1, 2026
CVE-2026-102671 MEDIUM

Joyland AI WebView accepts invalid SSL certificates

CVSS 6.9 EPSS n/a Oct 1, 2026
CVE-2026-102670 MEDIUM

Joyland AI enables HTTP

CVSS 5.3 EPSS n/a Oct 1, 2026

Showing 1 to 25 CVEs · page 1 (more available)