Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2014-1776 | Act now | 88.0% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote … |
| CVE-2024-12356 | Act now | 88.0% | — | ● | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injec… |
| CVE-2025-54253 | Act now | 88.0% | — | ● | Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows fo… |
| CVE-2026-24423 | Act now | 88.0% | 9.8 | ● | SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote co… |
| CVE-2025-29635 | Act now | 87.9% | — | ● | D-Link DIR-823X contains a command injection vulnerability that allows an authorized attac… |
| CVE-2022-27593 | Act now | 87.9% | — | ● | Certain QNAP NAS running Photo Station with internet exposure contain an externally contro… |
| CVE-2024-58136 | Act now | 87.8% | — | ● | Yii Framework contains an improper protection of alternate path vulnerability that may all… |
| CVE-2020-17496 | Act now | 87.7% | — | ● | The PHP module within vBulletin contains an unspecified vulnerability that allows for remo… |
| CVE-2023-2868 | Act now | 87.7% | — | ● | Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vul… |
| CVE-2016-6415 | Act now | 87.7% | — | ● | Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the cod… |
| CVE-2021-21973 | Act now | 87.6% | — | ● | VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to impr… |
| CVE-2025-33053 | Act now | 87.6% | — | ● | Microsoft Windows contains an external control of file name or path vulnerability that cou… |
| CVE-2016-6366 | Act now | 87.6% | — | ● | A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of C… |
| CVE-2026-34910 | Act now | 87.5% | 10.0 | ● | A malicious actor with access to the network could exploit an Improper Input Validation vu… |
| CVE-2016-9079 | Act now | 87.4% | — | ● | Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SV… |
| CVE-2014-6324 | Act now | 87.3% | — | ● | The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain… |
| CVE-2022-26143 | Act now | 87.3% | — | ● | A vulnerability has been identified in MiCollab and MiVoice Business Express that may allo… |
| CVE-2026-3055 | Act now | 87.2% | — | ● | Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) an… |
| CVE-2025-20362 | Act now | 87.1% | 6.5 | ● | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices ru… |
| CVE-2019-16057 | Act now | 87.1% | — | ● | The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. |
| CVE-2014-4113 | Act now | 87.0% | — | ● | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalatio… |
| CVE-2018-9276 | Act now | 87.0% | — | ● | Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows a… |
| CVE-2013-0640 | Act now | 86.9% | — | ● | An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows … |
| CVE-2021-31755 | Act now | 86.9% | — | ● | Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which a… |
| CVE-2020-0674 | Act now | 86.9% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the … |
| CVE-2017-18362 | Act now | 86.8% | 9.8 | ● | ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthe… |
| CVE-2026-60004 | Act now | 86.8% | 9.8 | ● | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook in… |
| CVE-2020-8644 | Act now | 86.7% | — | ● | PlaySMS contains a server-side template injection vulnerability that allows for remote cod… |
| CVE-2021-40655 | Act now | 86.7% | — | ● | D-Link DIR-605 routers contain an information disclosure vulnerability that allows attacke… |
| CVE-2024-51567 | Act now | 86.6% | 10.0 | ● | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 al… |
| CVE-2009-3459 | Act now | 86.6% | — | ● | Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could al… |
| CVE-2015-2426 | Act now | 86.6% | — | ● | A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe T… |
| CVE-2011-2462 | Act now | 86.6% | — | ● | The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption … |
| CVE-2025-4428 | Act now | 86.5% | — | ● | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API c… |
| CVE-2026-63077 | Act now | 86.5% | 9.8 | ● | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was… |
| CVE-2019-4716 | Act now | 86.4% | — | ● | IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthent… |
| CVE-2021-21017 | Act now | 86.3% | — | ● | Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could a… |
| CVE-2018-6961 | Act now | 86.3% | — | ● | VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local we… |
| CVE-2020-11652 | Act now | 86.2% | — | ● | SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFun… |
| CVE-2021-1675 | Act now | 86.1% | 7.8 | ● | Windows Print Spooler Remote Code Execution Vulnerability |
| CVE-2026-24858 | Act now | 86.1% | — | ● | Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication by… |
| CVE-2015-2545 | Act now | 85.9% | — | ● | Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image… |
| CVE-2015-0311 | Act now | 85.8% | — | ● | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. |
| CVE-2013-3893 | Act now | 85.8% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability that allows for rem… |
| CVE-2023-36847 | Act now | 85.8% | — | ● | Juniper Junos OS on EX Series contains a missing authentication for critical function vuln… |
| CVE-2021-30116 | Act now | 85.7% | 10.0 | ● | Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 202… |
| CVE-2023-27997 | Act now | 85.7% | 9.8 | ● | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, v… |
| CVE-2025-52691 | Act now | 85.7% | — | ● | SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulne… |
| CVE-2009-3129 | Act now | 85.6% | — | ● | Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet… |
| CVE-2020-3580 | Act now | 85.6% | 6.1 | ● | Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Applianc… |