Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2014-0496 | Act now | 40.0% | — | ● | Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code e… |
| CVE-2021-27860 | Act now | 39.8% | — | ● | A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software… |
| CVE-2013-6282 | Act now | 39.7% | — | ● | The get_user and put_user API functions of the Linux kernel fail to validate the target ad… |
| CVE-2025-20352 | Act now | 39.4% | — | ● | Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Ne… |
| CVE-2021-1647 | Act now | 39.4% | — | ● | Microsoft Defender contains an unspecified vulnerability that allows for remote code execu… |
| CVE-2021-26828 | Act now | 39.4% | — | ● | OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability … |
| CVE-2013-3660 | Act now | 39.3% | — | ● | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft… |
| CVE-2020-1464 | Act now | 38.9% | — | ● | Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates fil… |
| CVE-2008-0655 | Act now | 38.9% | — | ● | Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw… |
| CVE-2021-38003 | Act now | 38.6% | — | ● | Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value ca… |
| CVE-2015-2424 | Act now | 38.5% | — | ● | Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial o… |
| CVE-2024-55550 | Act now | 37.9% | 2.7 | ● | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative p… |
| CVE-2018-13374 | Act now | 37.8% | 4.3 | ● | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0… |
| CVE-2019-11707 | Act now | 37.7% | — | ● | Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when… |
| CVE-2019-11001 | Act now | 37.5% | — | ● | Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticat… |
| CVE-2014-3153 | Act now | 37.2% | — | ● | The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls ha… |
| CVE-2016-0099 | Act now | 36.9% | — | ● | A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary … |
| CVE-2017-16651 | Act now | 36.7% | — | ● | Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input va… |
| CVE-2019-19006 | Act now | 36.6% | — | ● | Sangoma FreePBX contains an improper authentication vulnerability that potentially allows … |
| CVE-2017-6884 | Act now | 36.5% | 8.8 | ● | A command injection vulnerability was discovered on the Zyxel EMG2926 home router with fir… |
| CVE-2020-17144 | Act now | 36.5% | — | ● | Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to… |
| CVE-2026-48710 | Act now | 36.3% | 6.5 | ● | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host`… |
| CVE-2018-4990 | Act now | 36.2% | — | ● | Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code e… |
| CVE-2020-5735 | Act now | 36.2% | — | ● | Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 3… |
| CVE-2021-38163 | Act now | 36.0% | — | ● | SAP NetWeaver contains a vulnerability that allows unrestricted file upload. |
| CVE-2022-31199 | Act now | 36.0% | — | ● | Netwrix Auditor User Activity Video Recording component contains an insecure objection des… |
| CVE-2017-6327 | Act now | 35.9% | — | ● | Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remot… |
| CVE-2022-22960 | Act now | 35.8% | — | ● | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege … |
| CVE-2021-39935 | Act now | 35.6% | — | ● | GitLab Community and Enterprise Editions contain a server-side request forgery vulnerabili… |
| CVE-2018-17480 | Act now | 35.6% | — | ● | Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote … |
| CVE-2020-13671 | Act now | 35.4% | — | ● | Improper sanitization in the extension file names is present in Drupal core. |
| CVE-2015-1770 | Act now | 35.2% | — | ● | Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office do… |
| CVE-2021-37975 | Act now | 34.9% | — | ● | Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote att… |
| CVE-2015-2387 | Act now | 34.9% | — | ● | ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local u… |
| CVE-2013-5065 | Act now | 34.7% | — | ● | Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerab… |
| CVE-2026-6973 | Act now | 34.5% | — | ● | Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability … |
| CVE-2016-5198 | Act now | 34.2% | — | ● | Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allow… |
| CVE-2008-4128 | Act now | 33.9% | — | ● | Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote att… |
| CVE-2010-5330 | Act now | 33.8% | — | ● | Certain Ubiquiti devices contain a command injection vulnerability via a GET request to st… |
| CVE-2022-40799 | Act now | 33.7% | — | ● | D-Link DNR-322L contains a download of code without integrity check vulnerability that cou… |
| CVE-2018-13383 | Act now | 33.6% | — | ● | A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web servic… |
| CVE-2015-0071 | Act now | 33.6% | — | ● | Microsoft Internet Explorer allows remote attackers to bypass the address space layout ran… |
| CVE-2025-9377 | Act now | 33.5% | — | ● | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability t… |
| CVE-2020-2509 | Act now | 33.4% | — | ● | QNAP NAS devices contain a command injection vulnerability which could allow attackers to … |
| CVE-2026-20131 | Act now | 33.4% | — | ● | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (S… |
| CVE-2016-3298 | Act now | 33.3% | — | ● | An information disclosure vulnerability exists when the Microsoft Internet Messaging API i… |
| CVE-2025-21042 | Act now | 33.2% | — | ● | Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram… |
| CVE-2016-4655 | Act now | 33.1% | — | ● | The Apple iOS kernel allows attackers to obtain sensitive information from memory via a cr… |
| CVE-2020-8195 | Act now | 33.0% | — | ● | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an i… |
| CVE-2020-8218 | Act now | 32.7% | — | ● | A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to c… |