Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-7101 | Act now | 19.1% | — | ● | Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unva… |
| CVE-2023-37450 | Act now | 19.0% | — | ● | Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that lead… |
| CVE-2026-48172 | Act now | 18.9% | 9.8 | ● | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to roo… |
| CVE-2015-5123 | Act now | 18.8% | — | ● | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implement… |
| CVE-2016-7892 | Act now | 18.8% | — | ● | Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. |
| CVE-2014-2120 | Act now | 18.8% | — | ● | Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerabilit… |
| CVE-2022-22047 | Act now | 18.8% | — | ● | Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege es… |
| CVE-2025-31200 | Act now | 18.6% | — | ● | Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerabili… |
| CVE-2020-11899 | Act now | 18.6% | — | ● | The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. |
| CVE-2024-7965 | Act now | 18.5% | — | ● | Google Chromium V8 contains an inappropriate implementation vulnerability that allows a re… |
| CVE-2022-22718 | Act now | 18.5% | — | ● | Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for priv… |
| CVE-2019-5591 | Act now | 18.4% | 6.5 | ● | A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on … |
| CVE-2018-8440 | Act now | 18.4% | — | ● | An elevation of privilege vulnerability exists when Windows improperly handles calls to Ad… |
| CVE-2018-0147 | Act now | 18.2% | — | ● | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) c… |
| CVE-2024-40766 | Act now | 18.2% | — | ● | SonicWall SonicOS contains an improper access control vulnerability that could lead to una… |
| CVE-2019-8506 | Act now | 18.1% | — | ● | A type confusion issue affecting multiple Apple products allows processing of maliciously … |
| CVE-2017-0022 | Act now | 18.1% | — | ● | Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attacke… |
| CVE-2010-4345 | Act now | 18.0% | — | ● | Exim allows local users to gain privileges by leveraging the ability of the exim user acco… |
| CVE-2023-42916 | Act now | 17.8% | — | ● | Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability th… |
| CVE-2010-5326 | Act now | 17.8% | — | ● | SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentic… |
| CVE-2018-19943 | Act now | 17.7% | 8.0 | ● | If exploited, this cross-site scripting vulnerability could allow remote attackers to inje… |
| CVE-2024-11182 | Act now | 17.7% | — | ● | MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a rem… |
| CVE-2025-24085 | Act now | 17.6% | — | ● | Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that co… |
| CVE-2022-27926 | Act now | 17.6% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by … |
| CVE-2021-44207 | Act now | 17.6% | — | ● | Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow … |
| CVE-2019-8605 | Act now | 17.5% | — | ● | A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malici… |
| CVE-2026-22719 | Act now | 17.4% | — | ● | Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a c… |
| CVE-2024-38813 | Act now | 17.4% | — | ● | VMware vCenter contains an improper check for dropped privileges vulnerability. This vulne… |
| CVE-2020-4006 | Act now | 17.3% | — | ● | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Conn… |
| CVE-2023-26359 | Act now | 17.0% | — | ● | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could res… |
| CVE-2025-62593 | Act now | 16.9% | 8.8 | ● | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a dev… |
| CVE-2023-36036 | Act now | 16.7% | — | ● | Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerabi… |
| CVE-2021-30533 | Act now | 16.6% | — | ● | Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability tha… |
| CVE-2023-32409 | Act now | 16.5% | — | ● | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerab… |
| CVE-2020-27950 | Act now | 16.5% | — | ● | Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that m… |
| CVE-2021-20022 | Act now | 16.5% | 7.2 | ● | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-auth… |
| CVE-2023-6345 | Act now | 16.5% | — | ● | Google Chromium Skia contains an integer overflow vulnerability that allows a remote attac… |
| CVE-2026-64849 | Act now | 16.4% | 9.3 | ● | MLflow is an open source AI engineering platform for agents, large language models, and ma… |
| CVE-2022-22620 | Act now | 16.3% | — | ● | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to c… |
| CVE-2020-3837 | Act now | 16.1% | — | ● | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that… |
| CVE-2022-4262 | Act now | 16.0% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote att… |
| CVE-2020-0986 | Act now | 15.9% | — | ● | Microsoft Windows kernel contains an unspecified vulnerability when handling objects in me… |
| CVE-2026-58644 | Act now | 15.9% | — | ● | Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allow… |
| CVE-2024-20481 | Act now | 15.8% | 5.8 | ● | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Applia… |
| CVE-2026-21513 | Act now | 15.6% | — | ● | Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that coul… |
| CVE-2019-7286 | Act now | 15.6% | — | ● | Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could a… |
| CVE-2023-50224 | Act now | 15.6% | 6.5 | ● | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability… |
| CVE-2023-35311 | Act now | 15.5% | — | ● | Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker… |
| CVE-2024-4947 | Act now | 15.2% | — | ● | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker t… |
| CVE-2015-0310 | Act now | 15.1% | — | ● | Adobe Flash Player does not properly restrict discovery of memory addresses, which allows … |