Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2019-7194 | Act now | 83.1% | — | ● | QNAP devices running Photo Station contain an external control of file name or path vulner… |
| CVE-2020-3992 | Act now | 83.0% | 9.8 | ● | OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202… |
| CVE-2016-7200 | Act now | 82.9% | — | ● | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execut… |
| CVE-2024-42009 | Act now | 82.9% | — | ● | RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could … |
| CVE-2021-27561 | Act now | 82.9% | — | ● | Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that… |
| CVE-2015-1187 | Act now | 82.9% | — | ● | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform re… |
| CVE-2024-0769 | Act now | 82.7% | — | ● | D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of t… |
| CVE-2023-43208 | Act now | 82.7% | — | ● | NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerabilit… |
| CVE-2025-33073 | Act now | 82.7% | — | ● | Microsoft Windows SMB Client contains an improper access control vulnerability that could … |
| CVE-2025-8110 | Act now | 82.5% | — | ● | Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in … |
| CVE-2010-2883 | Act now | 82.4% | — | ● | Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows r… |
| CVE-2010-1297 | Act now | 82.2% | — | ● | Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers… |
| CVE-2010-0806 | Act now | 82.2% | — | ● | Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remo… |
| CVE-2018-6789 | Act now | 82.1% | — | ● | Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP lis… |
| CVE-2024-43468 | Act now | 82.0% | — | ● | Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticate… |
| CVE-2025-40536 | Act now | 82.0% | — | ● | SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow… |
| CVE-2025-34026 | Act now | 81.9% | — | ● | Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerabi… |
| CVE-2009-4324 | Act now | 81.9% | — | ● | Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execut… |
| CVE-2013-1331 | Act now | 81.7% | — | ● | Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to … |
| CVE-2012-4969 | Act now | 81.7% | — | ● | Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote att… |
| CVE-2018-13382 | Act now | 81.7% | — | ● | An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN w… |
| CVE-2014-4114 | Act now | 81.6% | — | ● | A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote… |
| CVE-2019-0752 | Act now | 81.6% | 7.5 | ● | A remote code execution vulnerability exists in the way that the scripting engine handles … |
| CVE-2023-4911 | Act now | 81.4% | — | ● | GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when process… |
| CVE-2017-11826 | Act now | 81.2% | — | ● | A remote code execution vulnerability exists in Microsoft Office software when the softwar… |
| CVE-2021-31955 | Act now | 81.1% | — | ● | Microsoft Windows Kernel contains an unspecified vulnerability that allows for information… |
| CVE-2019-9621 | Act now | 81.0% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vul… |
| CVE-2013-0074 | Act now | 81.0% | 7.8 | ● | Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly val… |
| CVE-2017-0262 | Act now | 81.0% | — | ● | A remote code execution vulnerability exists in Microsoft Office. |
| CVE-2016-7255 | Act now | 81.0% | 7.8 | ● | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1… |
| CVE-2024-8957 | Act now | 81.0% | — | ● | PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows … |
| CVE-2021-26411 | Act now | 80.8% | 8.8 | ● | Internet Explorer Memory Corruption Vulnerability |
| CVE-2026-1603 | Act now | 80.6% | — | ● | Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or… |
| CVE-2017-0037 | Act now | 80.4% | — | ● | Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, wh… |
| CVE-2020-10221 | Act now | 80.2% | — | ● | rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerabilit… |
| CVE-2020-14871 | Act now | 80.2% | — | ● | Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability c… |
| CVE-2016-7201 | Act now | 80.1% | — | ● | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execut… |
| CVE-2023-22952 | Act now | 80.1% | — | ● | Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTempl… |
| CVE-2020-10987 | Act now | 79.8% | — | ● | Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote at… |
| CVE-2013-4810 | Act now | 79.5% | — | ● | HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle … |
| CVE-2010-0738 | Act now | 79.4% | 5.3 | ● | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platfor… |
| CVE-2021-21551 | Act now | 79.2% | — | ● | Dell dbutil driver contains an insufficient access control vulnerability which may lead to… |
| CVE-2018-18809 | Act now | 79.1% | — | ● | TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow we… |
| CVE-2013-3346 | Act now | 78.9% | — | ● | Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attacke… |
| CVE-2012-4792 | Act now | 78.8% | — | ● | Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote a… |
| CVE-2020-6418 | Act now | 78.8% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker… |
| CVE-2021-22555 | Act now | 78.7% | — | ● | Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacke… |
| CVE-2023-49103 | Act now | 78.4% | — | ● | ownCloud graphapi contains an information disclosure vulnerability that can reveal sensiti… |
| CVE-2021-1732 | Act now | 78.4% | 7.8 | ● | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-60137 | Act now | 78.3% | 5.9 | ● | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly… |