Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2020-35730 | Act now | 32.7% | — | ● | Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attac… |
| CVE-2021-30633 | Act now | 32.7% | — | ● | Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remot… |
| CVE-2026-20963 | Act now | 32.6% | — | ● | Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allow… |
| CVE-2026-73570 | Act now | 32.4% | 8.9 | ● | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 … |
| CVE-2013-0641 | Act now | 32.3% | — | ● | A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform… |
| CVE-2024-57968 | Act now | 32.3% | — | ● | Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote… |
| CVE-2023-3079 | Act now | 32.1% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote att… |
| CVE-2021-27852 | Act now | 31.9% | — | ● | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allo… |
| CVE-2019-15752 | Act now | 31.9% | — | ● | Docker Desktop Community Edition contains a vulnerability that may allow local users to es… |
| CVE-2022-4135 | Act now | 31.9% | — | ● | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote att… |
| CVE-2026-0300 | Act now | 31.7% | — | ● | Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Aut… |
| CVE-2011-2005 | Act now | 31.5% | — | ● | afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate u… |
| CVE-2026-20133 | Act now | 31.4% | — | ● | Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthor… |
| CVE-2025-0994 | Act now | 31.3% | — | ● | Trimble Cityworks contains a deserialization vulnerability. This could allow an authentica… |
| CVE-2017-5070 | Act now | 31.2% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote att… |
| CVE-2016-4523 | Act now | 31.2% | — | ● | The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a d… |
| CVE-2022-24682 | Act now | 30.9% | 6.1 | ● | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before… |
| CVE-2026-56290 | Act now | 30.9% | 9.8 | ● | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension … |
| CVE-2020-0968 | Act now | 30.7% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scri… |
| CVE-2025-26633 | Act now | 30.4% | 7.0 | ● | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to… |
| CVE-2024-21351 | Act now | 30.3% | 7.6 | ● | Windows SmartScreen Security Feature Bypass Vulnerability |
| CVE-2021-20028 | Act now | 30.1% | — | ● | SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL … |
| CVE-2019-3568 | Act now | 30.1% | — | ● | A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via s… |
| CVE-2019-13608 | Act now | 30.0% | — | ● | Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability th… |
| CVE-2019-1405 | Act now | 30.0% | 7.8 | ● | An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (U… |
| CVE-2025-20393 | Act now | 29.9% | — | ● | Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances con… |
| CVE-2025-32756 | Act now | 29.8% | — | ● | Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vuln… |
| CVE-2017-0222 | Act now | 29.6% | — | ● | A remote code execution vulnerability exists when Internet Explorer improperly accesses ob… |
| CVE-2018-8653 | Act now | 29.6% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scri… |
| CVE-2025-68686 | Act now | 29.6% | 5.9 | ● | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vuln… |
| CVE-2018-20753 | Act now | 29.3% | 9.8 | ● | Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows … |
| CVE-2010-0232 | Act now | 29.3% | — | ● | The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit… |
| CVE-2023-2533 | Act now | 29.2% | — | ● | PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under sp… |
| CVE-2023-41993 | Act now | 29.2% | — | ● | Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that lead… |
| CVE-2017-0149 | Act now | 29.2% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote … |
| CVE-2014-3931 | Act now | 29.0% | — | ● | Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allo… |
| CVE-2018-2380 | Act now | 28.9% | — | ● | SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that al… |
| CVE-2021-30807 | Act now | 28.8% | — | ● | Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vuln… |
| CVE-2023-33010 | Act now | 28.8% | — | ● | Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a… |
| CVE-2024-38193 | Act now | 28.5% | — | ● | Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerabil… |
| CVE-2024-3393 | Act now | 28.4% | — | ● | Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS pa… |
| CVE-2024-11120 | Act now | 28.4% | — | ● | Multiple GeoVision devices contain an OS command injection vulnerability that allows a rem… |
| CVE-2020-3153 | Act now | 28.3% | 6.5 | ● | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for … |
| CVE-2022-37969 | Act now | 28.3% | 7.8 | ● | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-20262 | Act now | 28.2% | 6.5 | ● | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, c… |
| CVE-2019-19356 | Act now | 28.2% | — | ● | Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perf… |
| CVE-2023-33009 | Act now | 28.1% | — | ● | Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a… |
| CVE-2024-1086 | Act now | 28.1% | 7.8 | ● | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be… |
| CVE-2023-36802 | Act now | 27.9% | — | ● | Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for pr… |
| CVE-2025-27363 | Act now | 27.8% | — | ● | FreeType contains an out-of-bounds write vulnerability when attempting to parse font subgl… |