Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-4885 | Act now | 99.3% | — | ● | Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticat… |
| CVE-2023-28771 | Act now | 99.3% | — | ● | Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handli… |
| CVE-2020-14750 | Act now | 99.3% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated a… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming conn… |
| CVE-2018-7602 | Act now | 99.2% | 9.8 | ● | A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and … |
| CVE-2022-30190 | Act now | 99.2% | 7.8 | ● | A remote code execution vulnerability exists when MSDT is called using the URL protocol fr… |
| CVE-2017-0144 | Act now | 99.2% | 8.8 | ● | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windo… |
| CVE-2020-0646 | Act now | 99.2% | — | ● | Microsoft .NET Framework contains an improper input validation vulnerability that allows f… |
| CVE-2024-27348 | Act now | 99.2% | — | ● | Apache HugeGraph-Server contains an improper access control vulnerability that could allow… |
| CVE-2022-24086 | Act now | 99.2% | — | ● | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability … |
| CVE-2020-11978 | Act now | 99.2% | — | ● | A remote code/command injection vulnerability was discovered in one of the example DAGs sh… |
| CVE-2022-36804 | Act now | 99.2% | — | ● | Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command inj… |
| CVE-2023-22515 | Act now | 99.2% | — | ● | Atlassian Confluence Data Center and Server contains a broken access control vulnerability… |
| CVE-2021-44529 | Act now | 99.1% | 9.8 | ● | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an … |
| CVE-2025-68613 | Act now | 99.1% | — | ● | n8n contains an improper control of dynamically managed code resources vulnerability in it… |
| CVE-2022-30333 | Act now | 99.1% | 7.5 | ● | RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files du… |
| CVE-2020-10199 | Act now | 99.1% | — | ● | Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote cod… |
| CVE-2025-49706 | Act now | 99.1% | 6.5 | ● | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to … |
| CVE-2019-16278 | Act now | 99.0% | — | ● | Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function… |
| CVE-2020-0618 | Act now | 99.0% | 8.8 | ● | A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services wh… |
| CVE-2020-7247 | Act now | 99.0% | — | ● | smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allow… |
| CVE-2021-40539 | Act now | 99.0% | — | ● | Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affec… |
| CVE-2019-3929 | Act now | 99.0% | — | ● | Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi H… |
| CVE-2017-3881 | Act now | 99.0% | — | ● | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IO… |
| CVE-2026-39987 | Act now | 98.9% | — | ● | Marimo contains an pre-authorization remote code execution vulnerability, allowing an unau… |
| CVE-2023-36884 | Act now | 98.9% | 7.5 | ● | Windows Search Remote Code Execution Vulnerability |
| CVE-2017-9791 | Act now | 98.9% | — | ● | The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious fie… |
| CVE-2022-3236 | Act now | 98.9% | — | ● | A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows f… |
| CVE-2025-49113 | Act now | 98.9% | — | ● | RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows r… |
| CVE-2023-47246 | Act now | 98.9% | 9.8 | ● | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code executio… |
| CVE-2013-2465 | Act now | 98.8% | — | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |
| CVE-2012-3152 | Act now | 98.8% | — | ● | Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allo… |
| CVE-2025-32433 | Act now | 98.8% | — | ● | Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulne… |
| CVE-2008-4250 | Act now | 98.8% | — | ● | Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service t… |
| CVE-2022-27925 | Act now | 98.7% | 7.2 | ● | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a… |
| CVE-2026-1340 | Act now | 98.7% | — | ● | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could a… |
| CVE-2024-29059 | Act now | 98.6% | — | ● | Microsoft .NET Framework contains an information disclosure vulnerability that exposes the… |
| CVE-2026-34486 | Act now | 98.6% | 7.5 | ● | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE… |
| CVE-2024-50623 | Act now | 98.6% | 9.8 | ● | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, th… |
| CVE-2024-8963 | Act now | 98.6% | — | ● | Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could a… |
| CVE-2026-1281 | Act now | 98.6% | — | ● | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could a… |
| CVE-2019-17558 | Act now | 98.6% | — | ● | The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which… |
| CVE-2024-9463 | Act now | 98.5% | — | ● | Palo Alto Networks Expedition contains an OS command injection vulnerability that allows a… |
| CVE-2024-50603 | Act now | 98.5% | — | ● | Aviatrix Controllers contain an OS command injection vulnerability that could allow an una… |
| CVE-2019-11539 | Act now | 98.5% | — | ● | Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the ad… |
| CVE-2012-4681 | Act now | 98.5% | 9.8 | ● | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE… |
| CVE-2026-41940 | Act now | 98.5% | — | ● | WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authenticati… |
| CVE-2016-3088 | Act now | 98.5% | — | ● | The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and ex… |
| CVE-2022-24816 | Act now | 98.5% | — | ● | OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt… |
| CVE-2024-20767 | Act now | 98.5% | — | ● | Adobe ColdFusion contains an improper access control vulnerability that could allow an att… |