Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-43461 | Act now | 54.5% | 8.8 | ● | Windows MSHTML Platform Spoofing Vulnerability |
| CVE-2020-29557 | Act now | 54.3% | — | ● | D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface tha… |
| CVE-2020-1054 | Act now | 54.2% | 7.0 | ● | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode dri… |
| CVE-2023-20118 | Act now | 54.1% | — | ● | Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability… |
| CVE-2026-18577 | Act now | 54.1% | 8.1 | ● | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeov… |
| CVE-2021-31196 | Act now | 54.1% | 7.2 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2022-21971 | Act now | 53.9% | — | ● | Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote cod… |
| CVE-2014-0130 | Act now | 53.7% | — | ● | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the imp… |
| CVE-2021-22941 | Act now | 53.6% | — | ● | Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthen… |
| CVE-2021-22175 | Act now | 53.4% | — | ● | GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the in… |
| CVE-2025-14611 | Act now | 53.3% | — | ● | Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for … |
| CVE-2023-45249 | Act now | 53.3% | — | ● | Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remo… |
| CVE-2019-0541 | Act now | 53.2% | — | ● | Microsoft MSHTML engine contains an improper input validation vulnerability that allows fo… |
| CVE-2015-2419 | Act now | 53.1% | — | ● | JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or c… |
| CVE-2015-1642 | Act now | 53.1% | — | ● | Microsoft Office contains a memory corruption vulnerability that allows remote attackers t… |
| CVE-2012-2539 | Act now | 53.0% | — | ● | Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) … |
| CVE-2019-0808 | Act now | 53.0% | — | ● | Microsoft Win32k contains a privilege escalation vulnerability due to the component failin… |
| CVE-2019-1068 | Act now | 52.8% | 8.8 | ● | A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly h… |
| CVE-2019-1367 | Act now | 52.4% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability in how the scriptin… |
| CVE-2016-2388 | Act now | 52.2% | — | ● | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers … |
| CVE-2019-13272 | Act now | 52.2% | — | ● | Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulne… |
| CVE-2021-28550 | Act now | 52.0% | — | ● | Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unaut… |
| CVE-2023-32434 | Act now | 51.5% | — | ● | Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could… |
| CVE-2021-20023 | Act now | 51.4% | 4.9 | ● | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-auth… |
| CVE-2009-1537 | Act now | 51.2% | — | ● | Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Pars… |
| CVE-2025-53690 | Act now | 51.1% | — | ● | Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and … |
| CVE-2015-2502 | Act now | 51.0% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability that allows an atta… |
| CVE-2024-38094 | Act now | 50.9% | — | ● | Microsoft SharePoint contains a deserialization vulnerability that allows for remote code … |
| CVE-2013-5223 | Act now | 50.8% | — | ● | A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowin… |
| CVE-2026-55040 | Act now | 50.6% | 9.1 | ● | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypa… |
| CVE-2023-49897 | Act now | 50.4% | — | ● | FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenti… |
| CVE-2026-59310 | Act now | 49.7% | 9.8 | ● | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malici… |
| CVE-2018-5430 | Act now | 49.6% | — | ● | TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user … |
| CVE-2020-12812 | Act now | 49.3% | 9.8 | ● | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.… |
| CVE-2021-22017 | Act now | 49.2% | — | ● | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementatio… |
| CVE-2021-3493 | Act now | 49.2% | — | ● | The overlayfs stacking file system in Linux kernel does not properly validate the applicat… |
| CVE-2011-1889 | Act now | 49.0% | — | ● | A remote code execution vulnerability exists in the Forefront Threat Management Gateway (T… |
| CVE-2023-5217 | Act now | 49.0% | — | ● | Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that … |
| CVE-2023-28252 | Act now | 49.0% | — | ● | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerabili… |
| CVE-2014-4404 | Act now | 48.9% | — | ● | Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and A… |
| CVE-2025-68645 | Act now | 48.9% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerabilit… |
| CVE-2020-9715 | Act now | 48.6% | — | ● | Adobe Acrobat contains a use-after-free vulnerability that allows for code execution |
| CVE-2022-23227 | Act now | 48.5% | — | ● | NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauth… |
| CVE-2020-16009 | Act now | 48.3% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote att… |
| CVE-2016-1646 | Act now | 48.1% | — | ● | Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remot… |
| CVE-2006-2492 | Act now | 48.1% | — | ● | Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows … |
| CVE-2021-26829 | Act now | 48.1% | — | ● | OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm. |
| CVE-2013-2094 | Act now | 47.7% | — | ● | Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to … |
| CVE-2021-40407 | Act now | 47.6% | — | ● | Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in… |
| CVE-2016-3976 | Act now | 47.3% | — | ● | SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerabili… |