Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2016-0752 | Act now | 95.5% | — | ● | Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers … |
| CVE-2024-1708 | Act now | 95.5% | — | ● | ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an att… |
| CVE-2022-41352 | Act now | 95.5% | 9.8 | ● | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can uplo… |
| CVE-2026-35273 | Act now | 95.5% | 9.8 | ● | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (compo… |
| CVE-2024-21412 | Act now | 95.4% | 8.1 | ● | Internet Shortcut Files Security Feature Bypass Vulnerability |
| CVE-2022-36537 | Act now | 95.4% | — | ● | ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an … |
| CVE-2024-1212 | Act now | 95.4% | — | ● | Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an una… |
| CVE-2019-11580 | Act now | 95.4% | — | ● | Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability result… |
| CVE-2019-7609 | Act now | 95.3% | — | ● | Kibana contain an arbitrary code execution flaw in the Timelion visualizer. |
| CVE-2015-0313 | Act now | 95.3% | — | ● | Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code… |
| CVE-2026-0257 | Act now | 95.2% | — | ● | Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows atta… |
| CVE-2024-57727 | Act now | 95.2% | 7.5 | ● | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traver… |
| CVE-2024-53704 | Act now | 95.1% | 9.8 | ● | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a r… |
| CVE-2018-0798 | Act now | 95.1% | — | ● | Microsoft Office contains a memory corruption vulnerability due to the way objects are han… |
| CVE-2017-12637 | Act now | 95.1% | — | ● | SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in… |
| CVE-2019-10068 | Act now | 95.1% | — | ● | Kentico contains a failure to validate security headers. This deserialization can led to u… |
| CVE-2023-36845 | Act now | 95.1% | — | ● | Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification… |
| CVE-2024-47575 | Act now | 95.1% | — | ● | Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon … |
| CVE-2014-6332 | Act now | 95.0% | — | ● | OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code … |
| CVE-2020-2883 | Act now | 94.9% | — | ● | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecif… |
| CVE-2021-4034 | Act now | 94.9% | 7.8 | ● | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexe… |
| CVE-2025-54309 | Act now | 94.9% | — | ● | CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy featu… |
| CVE-2018-14933 | Act now | 94.9% | — | ● | NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability all… |
| CVE-2023-36846 | Act now | 94.8% | — | ● | Juniper Junos OS on SRX Series contains a missing authentication for critical function vul… |
| CVE-2017-9822 | Act now | 94.8% | — | ● | DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via coo… |
| CVE-2020-6287 | Act now | 94.7% | — | ● | SAP NetWeaver Application Server Java Platforms contains a missing authentication for crit… |
| CVE-2024-9474 | Act now | 94.7% | 7.2 | ● | A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS… |
| CVE-2024-51378 | Act now | 94.7% | 10.0 | ● | getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0… |
| CVE-2024-21413 | Act now | 94.7% | 9.8 | ● | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2023-7028 | Act now | 94.6% | — | ● | GitLab Community and Enterprise Editions contain an improper access control vulnerability.… |
| CVE-2020-14644 | Act now | 94.5% | — | ● | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deseriali… |
| CVE-2025-54236 | Act now | 94.5% | — | ● | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability … |
| CVE-2017-18368 | Act now | 94.4% | — | ● | Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Lo… |
| CVE-2024-48248 | Act now | 94.4% | — | ● | NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enabl… |
| CVE-2016-4117 | Act now | 94.4% | 9.8 | ● | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary cod… |
| CVE-2025-30406 | Act now | 94.3% | — | ● | Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerabil… |
| CVE-2026-72898 | Act now | 94.2% | 10.0 | ● | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset… |
| CVE-2019-12989 | Act now | 94.1% | — | ● | Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection. |
| CVE-2017-1000486 | Act now | 94.1% | — | ● | Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execu… |
| CVE-2026-21643 | Act now | 94.1% | — | ● | Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthen… |
| CVE-2016-0189 | Act now | 94.1% | — | ● | The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products… |
| CVE-2025-8088 | Act now | 94.1% | 8.8 | ● | A path traversal vulnerability affecting the Windows version of WinRAR allows the attacker… |
| CVE-2024-55956 | Act now | 94.0% | 9.8 | ● | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an… |
| CVE-2007-5659 | Act now | 94.0% | — | ● | Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attack… |
| CVE-2025-11953 | Act now | 94.0% | — | ● | React Native Community CLI contains an OS command injection vulnerability which could allo… |
| CVE-2015-5122 | Act now | 94.0% | — | ● | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implem… |
| CVE-2020-1147 | Act now | 94.0% | — | ● | Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code ex… |
| CVE-2025-24016 | Act now | 93.8% | — | ● | Wazuh contains a deserialization of untrusted data vulnerability that allows for remote co… |
| CVE-2013-0625 | Act now | 93.8% | — | ● | Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an… |
| CVE-2012-1723 | Act now | 93.7% | 9.8 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |