Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2017-3066 | Act now | 90.6% | — | ● | Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library th… |
| CVE-2025-6218 | Act now | 90.5% | — | ● | RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code… |
| CVE-2025-12480 | Act now | 90.5% | — | ● | Gladinet Triofox contains an improper access control vulnerability that allows access to i… |
| CVE-2021-21311 | Act now | 90.5% | — | ● | Adminer contains a server-side request forgery vulnerability that, when exploited, allows … |
| CVE-2021-32648 | Act now | 90.4% | — | ● | In affected versions of the october/system package an attacker can request an account pass… |
| CVE-2020-3952 | Act now | 90.4% | — | ● | VMware vCenter Server contains an information disclosure vulnerability in the VMware Direc… |
| CVE-2024-40711 | Act now | 90.4% | — | ● | Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthen… |
| CVE-2023-41763 | Act now | 90.4% | — | ● | Microsoft Skype for Business contains an unspecified vulnerability that allows for privile… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x… |
| CVE-2013-0431 | Act now | 90.3% | 5.3 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |
| CVE-2021-20123 | Act now | 90.2% | — | ● | Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet en… |
| CVE-2025-37164 | Act now | 90.2% | — | ● | Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allo… |
| CVE-2020-29583 | Act now | 90.2% | — | ● | Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of h… |
| CVE-2023-40044 | Act now | 90.2% | — | ● | Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the A… |
| CVE-2024-13161 | Act now | 90.1% | — | ● | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allow… |
| CVE-2009-3960 | Act now | 90.0% | 6.5 | ● | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, a… |
| CVE-2026-9082 | Act now | 90.0% | 9.8 | ● | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulne… |
| CVE-2023-36844 | Act now | 90.0% | — | ● | Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability … |
| CVE-2017-8464 | Act now | 89.9% | — | ● | Windows Shell in multiple versions of Microsoft Windows allows local users or remote attac… |
| CVE-2017-8570 | Act now | 89.9% | — | ● | A remote code execution vulnerability exists in Microsoft Office software when it fails to… |
| CVE-2017-0146 | Act now | 89.9% | — | ● | The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execu… |
| CVE-2017-0145 | Act now | 89.9% | 8.8 | ● | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windo… |
| CVE-2022-0847 | Act now | 89.7% | — | ● | Linux kernel contains an improper initialization vulnerability where an unprivileged local… |
| CVE-2020-17463 | Act now | 89.7% | — | ● | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/it… |
| CVE-2019-7195 | Act now | 89.7% | — | ● | QNAP devices running Photo Station contain an external control of file name or path vulner… |
| CVE-2023-20273 | Act now | 89.6% | — | ● | Cisco IOS XE contains a command injection vulnerability in the web user interface. When ch… |
| CVE-2019-17621 | Act now | 89.6% | — | ● | D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL,… |
| CVE-2018-4878 | Act now | 89.5% | — | ● | Adobe Flash Player contains a use-after-free vulnerability that could allow for code execu… |
| CVE-2025-26399 | Act now | 89.5% | — | ● | SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in Ajax… |
| CVE-2026-1731 | Act now | 89.5% | — | ● | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command in… |
| CVE-2010-3333 | Act now | 89.5% | — | ● | A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft… |
| CVE-2020-0601 | Act now | 89.4% | — | ● | Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it … |
| CVE-2026-42208 | Act now | 89.4% | — | ● | BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read dat… |
| CVE-2018-14839 | Act now | 89.4% | — | ● | LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability. |
| CVE-2017-5521 | Act now | 89.2% | — | ● | Multiple NETGEAR devices are prone to admin password disclosure via simple crafted request… |
| CVE-2018-15982 | Act now | 89.1% | 7.8 | ● | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after … |
| CVE-2012-0151 | Act now | 88.8% | — | ● | The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) doe… |
| CVE-2017-8759 | Act now | 88.7% | — | ● | Microsoft .NET Framework contains a remote code execution vulnerability when processing un… |
| CVE-2014-3120 | Act now | 88.6% | — | ● | Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrar… |
| CVE-2024-8190 | Act now | 88.5% | — | ● | Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in th… |
| CVE-2021-43798 | Act now | 88.5% | — | ● | Grafana contains a path traversal vulnerability that could allow access to local files. |
| CVE-2020-8193 | Act now | 88.4% | — | ● | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an a… |
| CVE-2018-8174 | Act now | 88.3% | 7.5 | ● | A remote code execution vulnerability exists in the way that the VBScript engine handles o… |
| CVE-2025-61757 | Act now | 88.3% | — | ● | Oracle Fusion Middleware contains a missing authentication for critical function vulnerabi… |
| CVE-2010-0188 | Act now | 88.2% | 7.8 | ● | Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.… |
| CVE-2026-20127 | Act now | 88.2% | — | ● | Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manage… |
| CVE-2023-41265 | Act now | 88.2% | 9.6 | ● | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for ver… |
| CVE-2019-7192 | Act now | 88.2% | — | ● | QNAP NAS devices running Photo Station contain an improper access control vulnerability al… |
| CVE-2026-20230 | Act now | 88.2% | 8.6 | ● | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Com… |
| CVE-2023-36025 | Act now | 88.1% | — | ● | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could … |