Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-21975 | Act now | 78.3% | 7.5 | ● | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8… |
| CVE-2021-28799 | Act now | 78.3% | — | ● | QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow re… |
| CVE-2020-8816 | Act now | 78.2% | — | ● | Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard use… |
| CVE-2022-26318 | Act now | 78.2% | — | ● | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary co… |
| CVE-2023-24880 | Act now | 78.2% | — | ● | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could … |
| CVE-2011-3402 | Act now | 78.1% | — | ● | Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsin… |
| CVE-2017-0261 | Act now | 78.1% | — | ● | Microsoft Office contains a use-after-free vulnerability which can allow for remote code e… |
| CVE-2026-48907 | Act now | 78.1% | 9.8 | ● | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor p… |
| CVE-2023-27351 | Act now | 78.1% | — | ● | PaperCut NG/MF contains an improper authentication vulnerability that could allow remote a… |
| CVE-2013-1347 | Act now | 77.7% | — | ● | This vulnerability may corrupt memory in a way that could allow an attacker to execute arb… |
| CVE-2017-11357 | Act now | 77.7% | 9.8 | ● | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user in… |
| CVE-2023-27532 | Act now | 77.6% | — | ● | Veeam Backup & Replication Cloud Connect component contains a missing authentication for c… |
| CVE-2014-6352 | Act now | 77.5% | — | ● | Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE objec… |
| CVE-2014-1761 | Act now | 77.5% | — | ● | Microsoft Word contains a memory corruption vulnerability which when exploited could allow… |
| CVE-2022-41080 | Act now | 77.3% | 8.8 | ● | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2025-6204 | Act now | 77.3% | — | ● | Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow a… |
| CVE-2013-3897 | Act now | 77.3% | — | ● | A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explore… |
| CVE-2019-1429 | Act now | 77.3% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for… |
| CVE-2023-34192 | Act now | 77.3% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerabili… |
| CVE-2021-42287 | Act now | 77.2% | 7.5 | ● | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2019-7238 | Act now | 77.1% | — | ● | Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerabil… |
| CVE-2019-15949 | Act now | 77.0% | — | ● | Nagios XI contains a remote code execution vulnerability in which a user can modify the ch… |
| CVE-2018-15133 | Act now | 76.8% | — | ● | Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for… |
| CVE-2016-3718 | Act now | 76.7% | — | ● | ImageMagick contains an unspecified vulnerability that allows attackers to perform server-… |
| CVE-2008-0015 | Act now | 76.7% | — | ● | Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An… |
| CVE-2020-13965 | Act now | 76.6% | — | ● | Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote… |
| CVE-2021-38406 | Act now | 76.4% | — | ● | Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing spe… |
| CVE-2022-44698 | Act now | 76.3% | — | ● | Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could… |
| CVE-2023-44221 | Act now | 76.3% | — | ● | SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN m… |
| CVE-2026-25089 | Act now | 76.1% | 9.8 | ● | A improper neutralization of special elements used in an os command ('os command injection… |
| CVE-2026-45659 | Act now | 76.1% | 8.8 | ● | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized atta… |
| CVE-2021-30860 | Act now | 76.0% | — | ● | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerabili… |
| CVE-2023-5631 | Act now | 75.9% | — | ● | Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allo… |
| CVE-2015-0016 | Act now | 75.8% | — | ● | Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Win… |
| CVE-2026-20079 | Act now | 75.8% | 10.0 | ● | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Soft… |
| CVE-2012-0391 | Act now | 75.6% | — | ● | The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper in… |
| CVE-2016-3715 | Act now | 75.3% | — | ● | ImageMagick contains an unspecified vulnerability that could allow users to delete files b… |
| CVE-2021-25298 | Act now | 75.1% | — | ● | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI… |
| CVE-2017-9248 | Act now | 75.1% | — | ● | Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Teler… |
| CVE-2005-2773 | Act now | 74.6% | — | ● | HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary comman… |
| CVE-2018-8298 | Act now | 74.5% | — | ● | The ChakraCore scripting engine contains a type confusion vulnerability which can allow fo… |
| CVE-2025-1316 | Act now | 74.5% | — | ● | Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper in… |
| CVE-2021-42258 | Act now | 74.4% | — | ● | BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the usernam… |
| CVE-2014-0780 | Act now | 74.4% | — | ● | InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows r… |
| CVE-2019-1458 | Act now | 74.3% | 7.8 | ● | An elevation of privilege vulnerability exists in Windows when the Win32k component fails … |
| CVE-2018-14667 | Act now | 74.2% | — | ● | Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability … |
| CVE-2017-8543 | Act now | 74.2% | — | ● | Microsoft Windows allows an attacker to take control of the affected system when Windows S… |
| CVE-2024-21182 | Act now | 74.2% | — | ● | Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated … |
| CVE-2021-40449 | Act now | 74.1% | — | ● | Unspecified vulnerability allows for an authenticated user to escalate privileges. |
| CVE-2013-2551 | Act now | 74.1% | — | ● | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to exe… |