Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-22893 | Act now | 47.2% | 10.0 | ● | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vuln… |
| CVE-2014-4123 | Act now | 47.1% | — | ● | Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attac… |
| CVE-2023-37580 | Act now | 46.7% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability imp… |
| CVE-2022-39197 | Act now | 46.4% | — | ● | Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver tha… |
| CVE-2019-17026 | Act now | 46.3% | — | ● | Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect al… |
| CVE-2019-1579 | Act now | 46.2% | 8.1 | ● | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-… |
| CVE-2024-43573 | Act now | 46.1% | — | ● | Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can… |
| CVE-2017-6737 | Act now | 45.2% | — | ● | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a… |
| CVE-2023-41064 | Act now | 45.1% | — | ● | Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when proce… |
| CVE-2019-0803 | Act now | 45.0% | — | ● | Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handl… |
| CVE-2024-29988 | Act now | 44.9% | — | ● | Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows … |
| CVE-2015-2425 | Act now | 44.7% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote … |
| CVE-2013-3900 | Act now | 44.6% | — | ● | A remote code execution vulnerability exists in the way that the WinVerifyTrust function h… |
| CVE-2020-15999 | Act now | 44.3% | — | ● | Google Chrome uses FreeType, an open-source software library to render fonts, which contai… |
| CVE-2024-9379 | Act now | 43.8% | — | ● | Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin … |
| CVE-2014-100005 | Act now | 43.5% | — | ● | D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allo… |
| CVE-2023-36874 | Act now | 43.4% | — | ● | Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allow… |
| CVE-2026-32201 | Act now | 43.4% | — | ● | Microsoft SharePoint Server contains an improper input validation vulnerability that allow… |
| CVE-2017-6862 | Act now | 43.3% | — | ● | Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentic… |
| CVE-2016-3235 | Act now | 43.3% | — | ● | Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a si… |
| CVE-2009-0238 | Act now | 43.2% | — | ● | Microsoft Office Excel contains a remote code execution vulnerability that could allow an … |
| CVE-2023-49105 | Act now | 43.2% | 9.8 | ● | An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, … |
| CVE-2021-42292 | Act now | 43.0% | 7.8 | ● | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2025-2775 | Act now | 43.0% | — | ● | SysAid On-Prem contains an improper restriction of XML external entity reference vulnerabi… |
| CVE-2020-0787 | Act now | 42.5% | 7.8 | ● | An elevation of privilege vulnerability exists when the Windows Background Intelligent Tra… |
| CVE-2026-21962 | Act now | 42.5% | 10.0 | ● | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of O… |
| CVE-2020-12271 | Act now | 42.4% | — | ● | Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability wh… |
| CVE-2026-48282 | Act now | 42.4% | 10.0 | ● | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of … |
| CVE-2007-0671 | Act now | 42.4% | — | ● | Microsoft Office Excel contains a remote code execution vulnerability that can be exploite… |
| CVE-2023-33538 | Act now | 41.9% | — | ● | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection… |
| CVE-2021-44026 | Act now | 41.9% | — | ● | Roundcube Webmail is vulnerable to SQL injection via search or search_params. |
| CVE-2023-21674 | Act now | 41.8% | — | ● | Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerabili… |
| CVE-2017-5030 | Act now | 41.7% | — | ● | Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote … |
| CVE-2022-21999 | Act now | 41.7% | — | ● | Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for … |
| CVE-2024-41710 | Act now | 41.6% | — | ● | Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference… |
| CVE-2019-16928 | Act now | 41.6% | — | ● | Exim contains an out-of-bounds write vulnerability which can allow for remote code executi… |
| CVE-2019-0841 | Act now | 41.4% | — | ● | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard l… |
| CVE-2024-38178 | Act now | 41.4% | — | ● | Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows … |
| CVE-2011-1823 | Act now | 41.4% | — | ● | The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket,… |
| CVE-2021-22894 | Act now | 41.3% | — | ● | Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities… |
| CVE-2023-4762 | Act now | 41.1% | — | ● | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker t… |
| CVE-2023-29336 | Act now | 40.9% | — | ● | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalatio… |
| CVE-2023-2033 | Act now | 40.8% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote att… |
| CVE-2026-12569 | Act now | 40.6% | 9.8 | ● | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PD… |
| CVE-2015-0666 | Act now | 40.4% | — | ● | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Netwo… |
| CVE-2023-39780 | Act now | 40.2% | — | ● | ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remo… |
| CVE-2026-18556 | Act now | 40.2% | 7.4 | ● | Authentication bypass using an alternate path or channel vulnerability in N-able N-central… |
| CVE-2021-34448 | Act now | 40.1% | 6.8 | ● | Scripting Engine Memory Corruption Vulnerability |
| CVE-2021-20016 | Act now | 40.0% | 9.8 | ● | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unaut… |
| CVE-2026-28318 | Act now | 40.0% | 7.5 | ● | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U … |