Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2019-5418 | Act now | 98.5% | — | ● | Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially craf… |
| CVE-2008-2992 | Act now | 98.5% | — | ● | Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that cou… |
| CVE-2025-0108 | Act now | 98.5% | — | ● | Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its managemen… |
| CVE-2023-48788 | Act now | 98.4% | — | ● | Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthentic… |
| CVE-2022-21587 | Act now | 98.3% | — | ● | Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticat… |
| CVE-2018-1000861 | Act now | 98.3% | — | ● | A code execution vulnerability exists in the Stapler web framework used by Jenkins |
| CVE-2017-15944 | Act now | 98.3% | — | ● | Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow f… |
| CVE-2016-1555 | Act now | 98.3% | — | ● | Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass fo… |
| CVE-2023-20887 | Act now | 98.3% | — | ● | VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command… |
| CVE-2020-6207 | Act now | 98.3% | — | ● | SAP Solution Manager User Experience Monitoring contains a missing authentication for crit… |
| CVE-2024-55591 | Act now | 98.3% | 9.8 | ● | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affect… |
| CVE-2026-34197 | Act now | 98.3% | 8.8 | ● | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulne… |
| CVE-2022-22947 | Act now | 98.3% | — | ● | Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gatew… |
| CVE-2022-26138 | Act now | 98.2% | — | ● | Atlassian Questions For Confluence App has hard-coded credentials, exposing the username a… |
| CVE-2021-33766 | Act now | 98.1% | 7.3 | ● | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2021-39144 | Act now | 98.1% | — | ● | XStream contains a remote code execution vulnerability that allows an attacker to manipula… |
| CVE-2012-0507 | Act now | 98.1% | 9.8 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java S… |
| CVE-2024-41713 | Act now | 98.1% | 9.1 | ● | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through… |
| CVE-2024-12987 | Act now | 98.1% | — | ● | DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulner… |
| CVE-2023-25717 | Act now | 98.1% | — | ● | Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the we… |
| CVE-2026-24061 | Act now | 98.1% | — | ● | GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for… |
| CVE-2024-3272 | Act now | 98.0% | — | ● | D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that all… |
| CVE-2023-38831 | Act now | 98.0% | 7.8 | ● | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts … |
| CVE-2022-29303 | Act now | 98.0% | — | ● | SolarView Compact contains a command injection vulnerability due to improper validation of… |
| CVE-2021-35395 | Act now | 98.0% | — | ● | Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to … |
| CVE-2022-22536 | Act now | 97.9% | — | ● | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platfor… |
| CVE-2018-19410 | Act now | 97.9% | — | ● | Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a … |
| CVE-2020-14883 | Act now | 97.9% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability in the Console component with… |
| CVE-2021-42237 | Act now | 97.9% | — | ● | Sitcore XP contains an insecure deserialization vulnerability which can allow for remote c… |
| CVE-2020-25078 | Act now | 97.9% | — | ● | D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could al… |
| CVE-2023-25280 | Act now | 97.9% | — | ● | D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote,… |
| CVE-2021-45382 | Act now | 97.8% | — | ● | A remote code execution vulnerability exists in all series H/W revisions routers via the D… |
| CVE-2020-11738 | Act now | 97.8% | — | ● | WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an admi… |
| CVE-2020-17519 | Act now | 97.8% | — | ● | Apache Flink contains an improper access control vulnerability that allows an attacker to … |
| CVE-2015-7450 | Act now | 97.8% | — | ● | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT i… |
| CVE-2022-43769 | Act now | 97.7% | — | ● | Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that … |
| CVE-2021-36380 | Act now | 97.6% | — | ● | Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker t… |
| CVE-2013-0422 | Act now | 97.6% | — | ● | A vulnerability in the way Java restricts the permissions of Java applets could allow an a… |
| CVE-2025-34028 | Act now | 97.6% | — | ● | Commvault Command Center contains a path traversal vulnerability that allows a remote, una… |
| CVE-2016-3714 | Act now | 97.5% | — | ● | ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL… |
| CVE-2024-4358 | Act now | 97.5% | — | ● | Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability … |
| CVE-2021-40444 | Act now | 97.5% | 8.8 | ● | Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that… |
| CVE-2024-56145 | Act now | 97.4% | — | ● | Craft CMS contains a code injection vulnerability. Users with affected versions are vulner… |
| CVE-2019-9082 | Act now | 97.4% | — | ● | ThinkPHP contains an unspecified vulnerability that allows for remote code execution via p… |
| CVE-2023-23397 | Act now | 97.4% | — | ● | Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a N… |
| CVE-2007-3010 | Act now | 97.4% | — | ● | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Serv… |
| CVE-2023-27524 | Act now | 97.4% | — | ● | Apache Superset contains an insecure default initialization of a resource vulnerability th… |
| CVE-2021-22054 | Act now | 97.4% | — | ● | Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-sid… |
| CVE-2023-24489 | Act now | 97.3% | — | ● | Citrix Content Collaboration contains an improper access control vulnerability that could … |
| CVE-2023-26360 | Act now | 97.3% | — | ● | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows fo… |