Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-13159 | Act now | 100.0% | — | ● | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allow… |
| CVE-2018-11776 | Act now | 100.0% | — | ● | Apache Struts contains a vulnerability that allows for remote code execution under two cir… |
| CVE-2018-7600 | Act now | 100.0% | — | ● | Drupal Core contains a remote code execution vulnerability that could allow an attacker to… |
| CVE-2023-29300 | Act now | 100.0% | — | ● | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows fo… |
| CVE-2024-27199 | Act now | 100.0% | — | ● | JetBrains TeamCity contains a relative path traversal vulnerability that could allow limit… |
| CVE-2017-10271 | Act now | 100.0% | 7.5 | ● | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomp… |
| CVE-2021-34523 | Act now | 100.0% | 9.0 | ● | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2024-7593 | Act now | 100.0% | — | ● | Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows… |
| CVE-2025-3248 | Act now | 100.0% | — | ● | Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endp… |
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.4… |
| CVE-2020-9054 | Act now | 100.0% | — | ● | Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command… |
| CVE-2024-4577 | Act now | 100.0% | — | ● | PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vul… |
| CVE-2019-9670 | Act now | 100.0% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external … |
| CVE-2023-46805 | Act now | 100.0% | 8.2 | ● | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Iv… |
| CVE-2022-40684 | Act now | 100.0% | 9.8 | ● | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS … |
| CVE-2023-22527 | Act now | 100.0% | — | ● | Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injec… |
| CVE-2023-29357 | Act now | 100.0% | — | ● | Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthent… |
| CVE-2021-20090 | Act now | 100.0% | — | ● | Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthe… |
| CVE-2024-45195 | Act now | 100.0% | — | ● | Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obt… |
| CVE-2021-22204 | Act now | 100.0% | — | ● | Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and… |
| CVE-2025-22457 | Act now | 100.0% | 9.0 | ● | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Pol… |
| CVE-2024-1709 | Act now | 100.0% | — | ● | ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an a… |
| CVE-2025-59287 | Act now | 100.0% | — | ● | Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted dat… |
| CVE-2023-42793 | Act now | 100.0% | — | ● | JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote … |
| CVE-2023-4863 | Act now | 100.0% | — | ● | Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a rem… |
| CVE-2025-0282 | Act now | 100.0% | 9.0 | ● | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Pol… |
| CVE-2024-24919 | Act now | 100.0% | 8.6 | ● | Potentially allowing an attacker to read certain information on Check Point Security Gatew… |
| CVE-2021-45046 | Act now | 100.0% | — | ● | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomp… |
| CVE-2012-0158 | Act now | 100.0% | — | ● | Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code e… |
| CVE-2024-4879 | Act now | 100.0% | — | ● | ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly templa… |
| CVE-2025-31161 | Act now | 100.0% | — | ● | CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header … |
| CVE-2014-8361 | Act now | 100.0% | — | ● | Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP servic… |
| CVE-2025-5777 | Act now | 100.0% | 7.5 | ● | Insufficient input validation leading to memory overread when the NetScaler is configured … |
| CVE-2022-41082 | Act now | 100.0% | — | ● | Microsoft Exchange Server contains an unspecified vulnerability that allows for authentica… |
| CVE-2021-3156 | Act now | 100.0% | — | ● | Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which a… |
| CVE-2020-25506 | Act now | 100.0% | — | ● | D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi comp… |
| CVE-2022-47986 | Act now | 100.0% | — | ● | IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a… |
| CVE-2019-2725 | Act now | 100.0% | 9.8 | ● | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomp… |
| CVE-2021-42013 | Act now | 100.0% | — | ● | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perf… |
| CVE-2020-0688 | Act now | 100.0% | — | ● | Microsoft Exchange Server Validation Key fails to properly create unique keys at install t… |
| CVE-2019-10149 | Act now | 100.0% | — | ● | Improper validation of recipient address in deliver_message() function in /src/deliver.c m… |
| CVE-2022-1388 | Act now | 100.0% | — | ● | F5 BIG-IP contains a missing authentication in critical function vulnerability which can a… |
| CVE-2024-38475 | Act now | 100.0% | — | ● | Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite th… |
| CVE-2022-41040 | Act now | 100.0% | — | ● | Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," … |
| CVE-2024-29824 | Act now | 100.0% | — | ● | Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that a… |
| CVE-2018-15961 | Act now | 100.0% | — | ● | Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for c… |
| CVE-2023-38035 | Act now | 100.0% | — | ● | Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vuln… |
| CVE-2018-10562 | Act now | 99.9% | — | ● | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-… |
| CVE-2017-11882 | Act now | 99.9% | — | ● | Microsoft Office contains a memory corruption vulnerability that allows remote code execut… |
| CVE-2022-30525 | Act now | 99.9% | — | ● | A command injection vulnerability in the CGI program of some Zyxel firewall versions could… |