Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2019-12991 | Act now | 74.1% | — | ● | Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance. |
| CVE-2018-15811 | Act now | 74.0% | — | ● | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from t… |
| CVE-2018-18325 | Act now | 74.0% | — | ● | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from t… |
| CVE-2018-8414 | Act now | 74.0% | — | ● | A remote code execution vulnerability exists when the Windows Shell does not properly vali… |
| CVE-2015-3043 | Act now | 73.9% | — | ● | A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to … |
| CVE-2019-1003029 | Act now | 73.9% | — | ● | Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attack… |
| CVE-2013-3918 | Act now | 73.7% | — | ● | Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSign… |
| CVE-2018-8120 | Act now | 73.4% | 7.0 | ● | An elevation of privilege vulnerability exists in Windows when the Win32k component fails … |
| CVE-2025-6205 | Act now | 73.3% | — | ● | Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could … |
| CVE-2021-42278 | Act now | 73.3% | 7.5 | ● | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2024-37383 | Act now | 73.3% | — | ● | RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of S… |
| CVE-2023-47565 | Act now | 73.3% | — | ● | QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated … |
| CVE-2018-0824 | Act now | 73.2% | — | ● | Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that … |
| CVE-2017-6316 | Act now | 73.0% | — | ● | A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN… |
| CVE-2019-13720 | Act now | 73.0% | — | ● | Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attack… |
| CVE-2019-9978 | Act now | 72.9% | — | ● | WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that a… |
| CVE-2020-5741 | Act now | 72.9% | — | ● | Plex Media Server contains a remote code execution vulnerability that allows an attacker w… |
| CVE-2026-33824 | Act now | 72.7% | 9.8 | ● | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over … |
| CVE-2018-7841 | Act now | 72.7% | — | ● | A SQL Injection vulnerability exists in U.motion Builder software which could cause unwant… |
| CVE-2017-6334 | Act now | 72.6% | — | ● | dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote aut… |
| CVE-2026-21509 | Act now | 72.6% | — | ● | Microsoft Office contains a security feature bypass vulnerability in which reliance on unt… |
| CVE-2022-20699 | Act now | 72.5% | — | ● | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers coul… |
| CVE-2012-1856 | Act now | 72.2% | — | ● | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office al… |
| CVE-2021-25296 | Act now | 72.2% | — | ● | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI… |
| CVE-2019-2215 | Act now | 72.1% | — | ● | Android Kernel contains a use-after-free vulnerability in binder.c that allows for privile… |
| CVE-2026-16232 | Act now | 72.1% | 9.8 | ● | An authentication bypass vulnerability in the Check Point SmartConsole login process allow… |
| CVE-2017-8540 | Act now | 71.9% | — | ● | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defen… |
| CVE-2020-3259 | Act now | 71.8% | 7.5 | ● | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) S… |
| CVE-2026-42897 | Act now | 71.8% | — | ● | Microsoft Exchange Server contains a cross-site scripting vulnerability during web page ge… |
| CVE-2010-4344 | Act now | 71.7% | — | ● | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 … |
| CVE-2016-2386 | Act now | 71.5% | — | ● | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows re… |
| CVE-2015-4495 | Act now | 71.3% | — | ● | Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary… |
| CVE-2022-28810 | Act now | 71.0% | — | ● | Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for re… |
| CVE-2024-20353 | Act now | 70.7% | 8.6 | ● | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Applianc… |
| CVE-2013-3163 | Act now | 70.7% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote … |
| CVE-2025-20333 | Act now | 70.7% | 9.9 | ● | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance… |
| CVE-2020-36193 | Act now | 70.6% | — | ● | PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequat… |
| CVE-2022-2294 | Act now | 70.5% | 8.8 | ● | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote a… |
| CVE-2021-21220 | Act now | 70.4% | — | ● | Google Chromium V8 Engine contains an improper input validation vulnerability that allows … |
| CVE-2012-1535 | Act now | 70.4% | — | ● | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitra… |
| CVE-2017-6736 | Act now | 70.4% | — | ● | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a… |
| CVE-2018-8453 | Act now | 70.0% | 7.8 | ● | An elevation of privilege vulnerability exists in Windows when the Win32k component fails … |
| CVE-2020-4427 | Act now | 70.0% | — | ● | IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote a… |
| CVE-2016-0185 | Act now | 69.8% | — | ● | Microsoft Windows Media Center contains a remote code execution vulnerability when Windows… |
| CVE-2025-30066 | Act now | 69.8% | — | ● | tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability t… |
| CVE-2013-3896 | Act now | 69.4% | — | ● | Microsoft Silverlight does not properly validate pointers during access to Silverlight ele… |
| CVE-2016-0034 | Act now | 69.4% | 8.8 | ● | Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, wh… |
| CVE-2020-0938 | Act now | 69.2% | — | ● | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when ha… |
| CVE-2013-1690 | Act now | 69.0% | — | ● | Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjun… |
| CVE-2016-11021 | Act now | 68.9% | — | ● | setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via a… |