Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2018-4939 | Act now | 62.1% | — | ● | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could all… |
| CVE-2010-1428 | Act now | 62.1% | 7.5 | ● | The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platf… |
| CVE-2017-0059 | Act now | 62.0% | — | ● | Microsoft Internet Explorer allow remote attackers to obtain sensitive information from pr… |
| CVE-2018-8373 | Act now | 61.9% | — | ● | A remote code execution vulnerability exists in the way that the scripting engine handles … |
| CVE-2024-23113 | Act now | 61.7% | — | ● | Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability… |
| CVE-2020-4428 | Act now | 61.7% | — | ● | IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, au… |
| CVE-2019-5786 | Act now | 61.5% | — | ● | Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker t… |
| CVE-2023-21608 | Act now | 61.5% | — | ● | Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code exec… |
| CVE-2024-8956 | Act now | 61.3% | — | ● | PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnera… |
| CVE-2015-7755 | Act now | 61.1% | — | ● | Juniper ScreenOS contains an improper authentication vulnerability that could allow unauth… |
| CVE-2021-22991 | Act now | 61.1% | — | ● | The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnera… |
| CVE-2018-7445 | Act now | 60.8% | — | ● | In MikroTik RouterOS, a stack-based buffer overflow occurs when processing NetBIOS session… |
| CVE-2024-54085 | Act now | 60.7% | — | ● | AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish… |
| CVE-2026-9198 | Act now | 60.6% | 9.8 | ● | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/au… |
| CVE-2018-6065 | Act now | 60.3% | — | ● | Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote … |
| CVE-2020-8655 | Act now | 60.1% | — | ● | EyesOfNetwork contains an improper privilege management vulnerability that may allow a use… |
| CVE-2024-21338 | Act now | 59.8% | 7.8 | ● | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2017-11774 | Act now | 59.6% | — | ● | Microsoft Office Outlook contains a security feature bypass vulnerability due to improperl… |
| CVE-2014-4148 | Act now | 59.5% | — | ● | A remote code execution vulnerability exists when the Windows kernel-mode driver improperl… |
| CVE-2025-32463 | Act now | 59.4% | — | ● | Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. T… |
| CVE-2021-33742 | Act now | 59.4% | — | ● | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for re… |
| CVE-2022-21882 | Act now | 59.2% | 7.0 | ● | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-33634 | Act now | 59.2% | — | ● | Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an a… |
| CVE-2025-2746 | Act now | 59.1% | — | ● | Kentico Xperience CMS contains an authentication bypass using an alternate path or channel… |
| CVE-2025-24054 | Act now | 58.9% | — | ● | Microsoft Windows NTLM contains an external control of file name or path vulnerability tha… |
| CVE-2009-0557 | Act now | 58.6% | — | ● | Microsoft Office contains an object record corruption vulnerability that allows remote att… |
| CVE-2023-43770 | Act now | 58.5% | — | ● | Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can … |
| CVE-2025-31125 | Act now | 58.5% | — | ● | Vite Vitejs contains an improper access control vulnerability that exposes content of non-… |
| CVE-2013-7331 | Act now | 57.9% | — | ● | An information disclosure vulnerability exists in Internet Explorer which allows resources… |
| CVE-2016-7262 | Act now | 57.7% | — | ● | A security feature bypass vulnerability exists when Microsoft Office improperly handles in… |
| CVE-2023-6549 | Act now | 57.6% | — | ● | Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that al… |
| CVE-2016-7193 | Act now | 57.6% | — | ● | Microsoft Office contains a memory corruption vulnerability which can allow for remote cod… |
| CVE-2017-0101 | Act now | 57.5% | — | ● | A privilege escalation vulnerability exists when the Windows Transaction Manager improperl… |
| CVE-2020-26919 | Act now | 57.5% | — | ● | Netgear JGS516PE devices contain a missing function level access control vulnerability. |
| CVE-2025-25181 | Act now | 57.0% | — | ● | Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allow… |
| CVE-2021-27104 | Act now | 56.7% | — | ● | Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST … |
| CVE-2021-25297 | Act now | 56.7% | — | ● | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI… |
| CVE-2020-25079 | Act now | 56.3% | — | ● | D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the c… |
| CVE-2015-1701 | Act now | 56.2% | 7.8 | ● | Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and… |
| CVE-2019-5825 | Act now | 55.9% | — | ● | Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remo… |
| CVE-2019-11708 | Act now | 55.9% | — | ● | Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result i… |
| CVE-2022-29499 | Act now | 55.6% | 9.8 | ● | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote co… |
| CVE-2025-58034 | Act now | 55.6% | — | ● | Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authent… |
| CVE-2022-37055 | Act now | 55.5% | — | ● | D-Link Routers contains a buffer overflow vulnerability that has a high impact on confiden… |
| CVE-2018-0125 | Act now | 55.2% | — | ● | A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticat… |
| CVE-2006-1547 | Act now | 54.6% | — | ● | ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerabil… |
| CVE-2015-1671 | Act now | 54.6% | — | ● | A remote code execution vulnerability exists when components of Windows, .NET Framework, O… |
| CVE-2014-4077 | Act now | 54.6% | — | ● | Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that c… |
| CVE-2024-38812 | Act now | 54.6% | — | ● | VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implement… |
| CVE-2016-0984 | Act now | 54.5% | — | ● | Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execu… |