Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2014-0160 | Act now | 100.0% | — | ● | The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension pac… |
| CVE-2014-6271 | Act now | 100.0% | — | ● | GNU Bash through 4.3 processes trailing strings after function definitions in the values o… |
| CVE-2015-1635 | Act now | 100.0% | — | ● | Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote c… |
| CVE-2017-5638 | Act now | 100.0% | — | ● | Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-… |
| CVE-2017-9841 | Act now | 100.0% | — | ● | PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning… |
| CVE-2018-13379 | Act now | 100.0% | — | ● | Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow… |
| CVE-2019-0708 | Act now | 100.0% | — | ● | Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspeci… |
| CVE-2019-11510 | Act now | 100.0% | — | ● | Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an u… |
| CVE-2019-19781 | Act now | 100.0% | 9.8 | ● | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, … |
| CVE-2020-5902 | Act now | 100.0% | — | ● | F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulner… |
| CVE-2021-1498 | Act now | 100.0% | — | ● | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vul… |
| CVE-2021-21985 | Act now | 100.0% | 9.8 | ● | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of i… |
| CVE-2021-22005 | Act now | 100.0% | — | ● | VMware vCenter Server contains a file upload vulnerability in the Analytics service that a… |
| CVE-2021-26084 | Act now | 100.0% | — | ● | Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (O… |
| CVE-2021-26086 | Act now | 100.0% | — | ● | Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a… |
| CVE-2021-34473 | Act now | 100.0% | 9.1 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-35464 | Act now | 100.0% | — | ● | ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially craf… |
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an origin server … |
| CVE-2021-44228 | Act now | 100.0% | 10.0 | ● | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.… |
| CVE-2022-26134 | Act now | 100.0% | — | ● | Atlassian Confluence Server and Data Center contain a remote code execution vulnerability … |
| CVE-2022-29464 | Act now | 100.0% | — | ● | Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execut… |
| CVE-2023-0669 | Act now | 100.0% | 7.2 | ● | Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command in… |
| CVE-2023-1389 | Act now | 100.0% | — | ● | TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote cod… |
| CVE-2023-1671 | Act now | 100.0% | — | ● | Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handle… |
| CVE-2023-22518 | Act now | 100.0% | — | ● | Atlassian Confluence Data Center and Server contain an improper authorization vulnerabilit… |
| CVE-2023-27350 | Act now | 100.0% | — | ● | PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted… |
| CVE-2023-32315 | Act now | 100.0% | — | ● | Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenti… |
| CVE-2023-35078 | Act now | 100.0% | 9.8 | ● | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access … |
| CVE-2023-35082 | Act now | 100.0% | — | ● | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass… |
| CVE-2023-44487 | Act now | 100.0% | 7.5 | ● | The HTTP/2 protocol allows a denial of service (server resource consumption) because reque… |
| CVE-2023-4966 | Act now | 100.0% | 9.4 | ● | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as… |
| CVE-2024-21887 | Act now | 100.0% | 9.1 | ● | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) a… |
| CVE-2024-21893 | Act now | 100.0% | 8.2 | ● | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure… |
| CVE-2024-23897 | Act now | 100.0% | — | ● | Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows a… |
| CVE-2024-3400 | Act now | 100.0% | — | ● | Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability… |
| CVE-2012-1823 | Act now | 100.0% | — | ● | sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle quer… |
| CVE-2013-2251 | Act now | 100.0% | — | ● | Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Languag… |
| CVE-2017-7921 | Act now | 100.0% | — | ● | Multiple Hikvision products contain an improper authentication vulnerability that could al… |
| CVE-2025-53770 | Act now | 100.0% | 9.8 | ● | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an una… |
| CVE-2020-14882 | Act now | 100.0% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow f… |
| CVE-2022-22954 | Act now | 100.0% | — | ● | VMware Workspace ONE Access and Identity Manager allow for remote code execution due to se… |
| CVE-2024-3273 | Act now | 100.0% | — | ● | D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability… |
| CVE-2019-16920 | Act now | 100.0% | — | ● | Multiple D-Link routers contain a command injection vulnerability which can allow attacker… |
| CVE-2021-26855 | Act now | 100.0% | 9.1 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2022-44877 | Act now | 100.0% | — | ● | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnera… |
| CVE-2025-49704 | Act now | 100.0% | — | ● | Microsoft SharePoint contains a code injection vulnerability that could allow an authorize… |
| CVE-2024-34102 | Act now | 100.0% | — | ● | Adobe Commerce and Magento Open Source contain an improper restriction of XML external ent… |
| CVE-2020-8515 | Act now | 100.0% | — | ● | DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability t… |
| CVE-2020-3452 | Act now | 100.0% | 7.5 | ● | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) S… |
| CVE-2021-41773 | Act now | 100.0% | — | ● | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perf… |
Page 1 of 7,555
Next →