Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-57819 | Act now | 85.5% | — | ● | Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sani… |
| CVE-2026-50522 | Act now | 85.4% | 9.8 | ● | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized at… |
| CVE-2022-27924 | Act now | 85.4% | 7.5 | ● | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject… |
| CVE-2023-24955 | Act now | 85.4% | — | ● | Microsoft SharePoint Server contains a code injection vulnerability that allows an authent… |
| CVE-2013-2423 | Act now | 85.2% | — | ● | Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote atta… |
| CVE-2026-34908 | Act now | 85.2% | 10.0 | ● | A malicious actor with access to the network could exploit an Improper Access Control vuln… |
| CVE-2014-0322 | Act now | 85.1% | — | ● | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to exe… |
| CVE-2020-11023 | Act now | 84.9% | — | ● | JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing malici… |
| CVE-2013-3906 | Act now | 84.9% | — | ● | Microsoft Graphics Component contains a memory corruption vulnerability which can allow fo… |
| CVE-2023-41266 | Act now | 84.8% | 8.2 | ● | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May… |
| CVE-2019-10758 | Act now | 84.7% | — | ● | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses… |
| CVE-2023-38950 | Act now | 84.7% | — | ● | ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an un… |
| CVE-2022-23134 | Act now | 84.7% | — | ● | Malicious actors can pass step checks and potentially change the configuration of Zabbix F… |
| CVE-2024-28986 | Act now | 84.6% | — | ● | SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that c… |
| CVE-2019-11581 | Act now | 84.6% | — | ● | Atlassian Jira Server and Data Center contain a server-side template injection vulnerabili… |
| CVE-2025-64328 | Act now | 84.6% | — | ● | Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could… |
| CVE-2018-17463 | Act now | 84.6% | — | ● | Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attac… |
| CVE-2020-28949 | Act now | 84.6% | — | ● | PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is no… |
| CVE-2026-15409 | Act now | 84.5% | — | ● | SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that coul… |
| CVE-2020-15415 | Act now | 84.5% | — | ● | DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulner… |
| CVE-2020-7796 | Act now | 84.4% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerabil… |
| CVE-2020-5722 | Act now | 84.4% | — | ● | Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via cr… |
| CVE-2020-12641 | Act now | 84.3% | — | ● | Roundcube Webmail contains an remote code execution vulnerability that allows attackers to… |
| CVE-2024-21762 | Act now | 84.3% | 9.8 | ● | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.… |
| CVE-2024-38112 | Act now | 84.2% | — | ● | Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact… |
| CVE-2017-11317 | Act now | 84.2% | — | ● | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform … |
| CVE-2021-21224 | Act now | 84.2% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote att… |
| CVE-2017-0213 | Act now | 84.1% | — | ● | Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker… |
| CVE-2024-43451 | Act now | 84.1% | — | ● | Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disc… |
| CVE-2023-28432 | Act now | 84.0% | — | ● | MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment… |
| CVE-2015-3035 | Act now | 83.9% | — | ● | Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attacke… |
| CVE-2009-3953 | Act now | 83.9% | — | ● | Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support th… |
| CVE-2020-3161 | Act now | 83.9% | — | ● | Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Expl… |
| CVE-2023-27992 | Act now | 83.8% | — | ● | Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command… |
| CVE-2026-50751 | Act now | 83.8% | 9.3 | ● | A logic flow weakness in Remote Access and Mobile Access certificate validation in depreca… |
| CVE-2019-9874 | Act now | 83.7% | — | ● | Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the S… |
| CVE-2021-23758 | Act now | 83.6% | 8.1 | ● | All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due … |
| CVE-2025-34291 | Act now | 83.6% | — | ● | Langflow contains an origin validation error vulnerability in which an overly permissive C… |
| CVE-2025-40551 | Act now | 83.6% | — | ● | SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that c… |
| CVE-2026-42271 | Act now | 83.6% | — | ● | BerriAI LiteLLM contains a command injection vulnerability that could allow any authentica… |
| CVE-2022-24990 | Act now | 83.6% | — | ● | TerraMaster OS contains a remote command execution vulnerability that allows an unauthenti… |
| CVE-2019-0193 | Act now | 83.5% | — | ● | The optional Apache Solr module DataImportHandler contains a code injection vulnerability. |
| CVE-2016-5195 | Act now | 83.5% | — | ● | Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. |
| CVE-2012-1889 | Act now | 83.5% | — | ● | Microsoft XML Core Services contains a memory corruption vulnerability which could allow f… |
| CVE-2022-26923 | Act now | 83.5% | — | ● | An authenticated user could manipulate attributes on computer accounts they own or manage,… |
| CVE-2021-20021 | Act now | 83.4% | 9.8 | ● | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to cre… |
| CVE-2010-1871 | Act now | 83.4% | — | ● | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red… |
| CVE-2016-10174 | Act now | 83.3% | — | ● | The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve … |
| CVE-2025-14847 | Act now | 83.2% | — | ● | MongoDB Server contains an improper handling of length parameter inconsistency vulnerabili… |
| CVE-2010-3765 | Act now | 83.2% | — | ● | Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when Java… |