Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-4008 | Act now | 93.7% | — | ● | Smartbedded Meteobridge contains a command injection vulnerability that could allow remote… |
| CVE-2021-26858 | Act now | 93.7% | 7.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2013-0632 | Act now | 93.6% | — | ● | An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an… |
| CVE-2017-0143 | Act now | 93.3% | — | ● | Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability t… |
| CVE-2021-44077 | Act now | 93.3% | — | ● | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and Su… |
| CVE-2018-0802 | Act now | 93.3% | — | ● | Microsoft Office contains a memory corruption vulnerability due to the way objects are han… |
| CVE-2020-5849 | Act now | 93.2% | — | ● | Unraid contains an authentication bypass vulnerability that allows attackers to gain acces… |
| CVE-2024-28987 | Act now | 93.2% | — | ● | SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a … |
| CVE-2020-2551 | Act now | 93.2% | — | ● | Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components … |
| CVE-2022-33891 | Act now | 93.1% | — | ● | Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when… |
| CVE-2016-4437 | Act now | 93.0% | — | ● | Apache Shiro contains a vulnerability which may allow remote attackers to execute code or … |
| CVE-2021-40870 | Act now | 93.0% | — | ● | Unrestricted upload of a file with a dangerous type is possible, which allows an unauthent… |
| CVE-2024-6670 | Act now | 93.0% | — | ● | Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticate… |
| CVE-2018-10561 | Act now | 92.9% | — | ● | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-… |
| CVE-2025-47812 | Act now | 92.9% | — | ● | Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerab… |
| CVE-2026-39808 | Act now | 92.8% | — | ● | Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an u… |
| CVE-2022-24706 | Act now | 92.5% | — | ● | Apache CouchDB contains an insecure default initialization of resource vulnerability which… |
| CVE-2025-2747 | Act now | 92.5% | — | ● | Kentico Xperience CMS contains an authentication bypass using an alternate path or channel… |
| CVE-2016-3427 | Act now | 92.3% | — | ● | Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attack… |
| CVE-2022-43939 | Act now | 92.3% | — | ● | Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorizat… |
| CVE-2017-5689 | Act now | 92.2% | — | ● | Intel products contain a vulnerability which can allow attackers to perform privilege esca… |
| CVE-2019-2616 | Act now | 92.2% | — | ● | Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that al… |
| CVE-2025-11371 | Act now | 92.1% | — | ● | Gladinet CentreStack and Triofox contains a files or directories accessible to external pa… |
| CVE-2024-20439 | Act now | 92.1% | — | ● | Cisco Smart Licensing Utility contains a static credential vulnerability that allows an un… |
| CVE-2018-11138 | Act now | 92.1% | 9.8 | ● | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appl… |
| CVE-2012-0754 | Act now | 92.0% | — | ● | Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers… |
| CVE-2019-6340 | Act now | 92.0% | — | ● | In Drupal Core, some field types do not properly sanitize data from non-form sources. This… |
| CVE-2022-26258 | Act now | 92.0% | — | ● | D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp… |
| CVE-2020-10148 | Act now | 92.0% | — | ● | SolarWinds Orion API contains an authentication bypass vulnerability that could allow a re… |
| CVE-2024-7399 | Act now | 91.9% | — | ● | Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an att… |
| CVE-2010-0249 | Act now | 91.9% | — | ● | Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remo… |
| CVE-2025-5086 | Act now | 91.9% | — | ● | Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability… |
| CVE-2022-37042 | Act now | 91.9% | 9.8 | ● | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives… |
| CVE-2020-8657 | Act now | 91.9% | — | ● | EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same … |
| CVE-2025-64446 | Act now | 91.8% | — | ● | Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unaut… |
| CVE-2024-5910 | Act now | 91.8% | — | ● | Palo Alto Networks Expedition contains a missing authentication vulnerability that allows … |
| CVE-2021-42321 | Act now | 91.7% | 8.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2024-11680 | Act now | 91.7% | — | ● | ProjectSend contains an improper authentication vulnerability that allows a remote, unauth… |
| CVE-2022-26352 | Act now | 91.6% | — | ● | dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type v… |
| CVE-2026-20182 | Act now | 91.5% | — | ● | Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability … |
| CVE-2020-1350 | Act now | 91.4% | — | ● | Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to pe… |
| CVE-2010-2568 | Act now | 91.3% | — | ● | Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be ex… |
| CVE-2025-9242 | Act now | 91.3% | 9.8 | ● | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow … |
| CVE-2012-5076 | Act now | 91.3% | — | ● | The default Java security properties configuration did not restrict access to the com.sun.… |
| CVE-2024-13160 | Act now | 91.2% | — | ● | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allow… |
| CVE-2021-35211 | Act now | 91.2% | — | ● | SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for … |
| CVE-2020-8243 | Act now | 90.8% | — | ● | Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interfa… |
| CVE-2026-35616 | Act now | 90.7% | 9.8 | ● | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may… |
| CVE-2017-12149 | Act now | 90.7% | 9.8 | ● | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, i… |
| CVE-2021-21315 | Act now | 90.7% | — | ● | In this vulnerability, an attacker can send a malicious payload that will exploit the name… |