Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2022-0609 | Act now | 22.9% | — | ● | Google Chromium Animation contains a use-after-free vulnerability that allows a remote att… |
| CVE-2021-22899 | Act now | 22.9% | — | ● | Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote … |
| CVE-2023-32435 | Act now | 22.8% | — | ● | Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that… |
| CVE-2024-44309 | Act now | 22.6% | — | ● | Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when proce… |
| CVE-2016-6367 | Act now | 22.6% | — | ● | A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could all… |
| CVE-2014-0196 | Act now | 22.5% | — | ● | Linux Kernel contains a race condition vulnerability within the n_tty_write function that … |
| CVE-2026-2441 | Act now | 22.4% | — | ● | Google Chromium CSS contains a use-after-free vulnerability that could allow a remote atta… |
| CVE-2024-37079 | Act now | 22.4% | — | ● | Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implem… |
| CVE-2017-0210 | Act now | 22.3% | — | ● | A privilege escalation vulnerability exists when Internet Explorer does not properly enfor… |
| CVE-2014-0546 | Act now | 22.3% | — | ● | Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechani… |
| CVE-2025-14174 | Act now | 22.3% | — | ● | Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could … |
| CVE-2016-1019 | Act now | 22.3% | 9.8 | ● | Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of ser… |
| CVE-2021-31956 | Act now | 22.3% | — | ● | Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability … |
| CVE-2024-40890 | Act now | 22.3% | — | ● | Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerabili… |
| CVE-2018-8639 | Act now | 22.2% | — | ● | Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability t… |
| CVE-2023-29360 | Act now | 22.1% | — | ● | Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that a… |
| CVE-2025-54948 | Act now | 22.0% | — | ● | Trend Micro Apex One Management Console (on-premise) contains an OS command injection vuln… |
| CVE-2016-0162 | Act now | 22.0% | — | ● | An information disclosure vulnerability exists when Internet Explorer does not properly ha… |
| CVE-2020-27930 | Act now | 22.0% | — | ● | Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability… |
| CVE-2025-43300 | Act now | 22.0% | — | ● | Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O… |
| CVE-2021-34484 | Act now | 21.8% | 7.8 | ● | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2019-1297 | Act now | 21.8% | — | ● | A remote code execution vulnerability exists in Microsoft Excel when the software fails to… |
| CVE-2025-23209 | Act now | 21.8% | — | ● | Craft CMS contains a code injection vulnerability caused by improper validation of the dat… |
| CVE-2019-0903 | Act now | 21.7% | — | ● | A remote code execution vulnerability exists in the way that the Windows Graphics Device I… |
| CVE-2024-40891 | Act now | 21.5% | — | ● | Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerabili… |
| CVE-2017-6742 | Act now | 21.4% | — | ● | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a… |
| CVE-2020-9377 | Act now | 21.3% | — | ● | D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php. |
| CVE-2012-5054 | Act now | 21.2% | — | ● | Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers… |
| CVE-2012-1854 | Act now | 21.0% | — | ● | Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnera… |
| CVE-2014-9163 | Act now | 20.7% | — | ● | Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotel… |
| CVE-2023-36563 | Act now | 20.7% | — | ● | Microsoft WordPad contains an unspecified vulnerability that allows for information disclo… |
| CVE-2024-7971 | Act now | 20.7% | — | ● | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker t… |
| CVE-2020-24363 | Act now | 20.7% | — | ● | TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. … |
| CVE-2016-3309 | Act now | 20.5% | — | ● | A privilege escalation vulnerability exists when the Windows kernel fails to properly hand… |
| CVE-2014-8439 | Act now | 20.4% | — | ● | Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer… |
| CVE-2026-48939 | Act now | 20.1% | — | ● | iCagenda contains an unrestricted upload of file with dangerous type vulnerability that al… |
| CVE-2016-4171 | Act now | 20.1% | — | ● | Unspecified vulnerability in Adobe Flash Player allows for remote code execution. |
| CVE-2021-21148 | Act now | 20.0% | — | ● | Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remo… |
| CVE-2021-37976 | Act now | 19.7% | — | ● | Google Chromium contains an information disclosure vulnerability within the core memory co… |
| CVE-2022-26871 | Act now | 19.6% | — | ● | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote … |
| CVE-2025-7775 | Act now | 19.6% | — | ● | Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that co… |
| CVE-2023-36761 | Act now | 19.6% | — | ● | Microsoft Word contains an unspecified vulnerability that allows for information disclosur… |
| CVE-2025-66376 | Act now | 19.6% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in … |
| CVE-2021-41379 | Act now | 19.5% | 5.5 | ● | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2024-20359 | Act now | 19.4% | 6.0 | ● | A vulnerability in a legacy capability that allowed for the preloading of VPN clients and … |
| CVE-2016-1010 | Act now | 19.3% | — | ● | Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute c… |
| CVE-2025-67038 | Act now | 19.3% | 9.8 | ● | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a she… |
| CVE-2019-1215 | Act now | 19.3% | — | ● | Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsoc… |
| CVE-2016-7836 | Act now | 19.2% | — | ● | SKYSEA Client View contains an improper authentication vulnerability that allows remote co… |
| CVE-2019-1322 | Act now | 19.2% | — | ● | A privilege escalation vulnerability exists when Windows improperly handles authentication… |