Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2020-1956 | Act now | 97.3% | — | ● | Apache Kylin contains an OS command injection vulnerability which could permit an attacker… |
| CVE-2020-25213 | Act now | 97.3% | — | ● | WordPress File Manager plugin contains a remote code execution vulnerability that allows u… |
| CVE-2026-63030 | Act now | 97.3% | 9.8 | ● | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoi… |
| CVE-2019-5544 | Act now | 97.3% | — | ● | VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer o… |
| CVE-2020-14864 | Act now | 97.2% | — | ● | Path traversal vulnerability, where an attacker can target the preview FilePath parameter … |
| CVE-2025-20281 | Act now | 97.2% | — | ● | Cisco Identity Services Engine contains an injection vulnerability in a specific API of Ci… |
| CVE-2021-41277 | Act now | 97.2% | — | ● | Metabase contains a local file inclusion vulnerability in the custom map support in the AP… |
| CVE-2020-2555 | Act now | 97.1% | — | ● | Multiple Oracle products contain a remote code execution vulnerability that allows an unau… |
| CVE-2019-20500 | Act now | 97.1% | — | ● | D-Link DWL-2600AP access point contains an authenticated command injection vulnerability v… |
| CVE-2015-2051 | Act now | 97.1% | — | ● | D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands… |
| CVE-2019-7256 | Act now | 97.1% | — | ● | Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an… |
| CVE-2023-38203 | Act now | 97.1% | — | ● | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows fo… |
| CVE-2025-54068 | Act now | 97.1% | — | ● | Laravel Livewire contain a code injection vulnerability that could allow unauthenticated a… |
| CVE-2018-1273 | Act now | 97.0% | 9.8 | ● | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupporte… |
| CVE-2017-8291 | Act now | 97.0% | — | ● | Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type… |
| CVE-2026-20253 | Act now | 96.9% | 9.8 | ● | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthent… |
| CVE-2023-52163 | Act now | 96.9% | — | ● | Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for … |
| CVE-2019-1003030 | Act now | 96.9% | — | ● | Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the… |
| CVE-2019-3398 | Act now | 96.8% | — | ● | Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the … |
| CVE-2010-3962 | Act now | 96.8% | — | ● | Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that… |
| CVE-2020-25223 | Act now | 96.8% | — | ● | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM. |
| CVE-2021-22502 | Act now | 96.7% | — | ● | Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allow… |
| CVE-2011-3544 | Act now | 96.7% | — | ● | An access control vulnerability exists in the Applet Rhino Script Engine component of Orac… |
| CVE-2015-1641 | Act now | 96.7% | — | ● | Microsoft Office contains a memory corruption vulnerability due to failure to properly han… |
| CVE-2018-6530 | Act now | 96.7% | — | ● | Multiple D-Link routers contain an unspecified vulnerability that allows for execution of … |
| CVE-2009-0927 | Act now | 96.6% | — | ● | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to e… |
| CVE-2020-11651 | Act now | 96.6% | — | ● | SaltStack Salt contains an authentication bypass vulnerability in the salt-master process … |
| CVE-2023-33246 | Act now | 96.6% | — | ● | Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are e… |
| CVE-2009-1151 | Act now | 96.6% | — | ● | Setup script used to generate configuration can be fooled using a crafted POST request to … |
| CVE-2023-46747 | Act now | 96.5% | — | ● | F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path … |
| CVE-2020-8260 | Act now | 96.5% | — | ● | Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated at… |
| CVE-2026-23760 | Act now | 96.4% | 9.8 | ● | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vul… |
| CVE-2010-0840 | Act now | 96.3% | — | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allow… |
| CVE-2021-20124 | Act now | 96.3% | — | ● | Draytek VigorConnect contains a path traversal vulnerability in the file download function… |
| CVE-2021-35587 | Act now | 96.3% | — | ● | Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network ac… |
| CVE-2017-3506 | Act now | 96.3% | — | ● | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS comma… |
| CVE-2018-20250 | Act now | 96.3% | 7.8 | ● | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when… |
| CVE-2017-17562 | Act now | 96.3% | — | ● | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI pr… |
| CVE-2026-33017 | Act now | 96.2% | — | ● | Langflow contains a code injection vulnerability that could allow building public flows wi… |
| CVE-2018-14847 | Act now | 96.1% | — | ● | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary f… |
| CVE-2019-20085 | Act now | 96.1% | — | ● | TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via G… |
| CVE-2015-4852 | Act now | 96.0% | — | ● | Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within A… |
| CVE-2022-24112 | Act now | 96.0% | — | ● | Apache APISIX contains an authentication bypass vulnerability that allows for remote code … |
| CVE-2020-17530 | Act now | 95.9% | — | ● | Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated… |
| CVE-2019-1652 | Act now | 95.9% | — | ● | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV… |
| CVE-2025-61884 | Act now | 95.9% | 7.5 | ● | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Ru… |
| CVE-2020-5847 | Act now | 95.8% | — | ● | Unraid contains a vulnerability due to the insecure use of the extract PHP function that c… |
| CVE-2021-26857 | Act now | 95.8% | 7.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2022-23131 | Act now | 95.7% | — | ● | Unsafe client-side session storage leading to authentication bypass/instance takeover via … |
| CVE-2020-5410 | Act now | 95.6% | — | ● | Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows … |