Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-45247 | Act now | 27.5% | 9.8 | ● | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object… |
| CVE-2018-8581 | Act now | 27.4% | — | ● | A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who … |
| CVE-2023-28205 | Act now | 27.1% | — | ● | Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that le… |
| CVE-2018-4063 | Act now | 27.1% | — | ● | Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type … |
| CVE-2024-4978 | Act now | 26.9% | — | ● | Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, n… |
| CVE-2020-5135 | Act now | 26.9% | — | ● | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Ser… |
| CVE-2025-68461 | Act now | 26.8% | — | ● | RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an … |
| CVE-2025-30397 | Act now | 26.8% | — | ● | Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an … |
| CVE-2024-37085 | Act now | 26.8% | — | ● | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with suffic… |
| CVE-2021-21166 | Act now | 26.7% | — | ● | Google Chromium contains a race condition vulnerability that allows a remote attacker to p… |
| CVE-2026-56164 | Act now | 26.6% | — | ● | Microsoft SharePoint contains a missing authentication for critical function vulnerability… |
| CVE-2025-14733 | Act now | 26.5% | 9.8 | ● | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow … |
| CVE-2014-2817 | Act now | 26.3% | — | ● | Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attack… |
| CVE-2020-8196 | Act now | 26.3% | — | ● | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an i… |
| CVE-2016-3351 | Act now | 26.3% | 6.5 | ● | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obta… |
| CVE-2026-21510 | Act now | 26.2% | — | ● | Microsoft Windows Shell contains a protection mechanism failure vulnerability that could a… |
| CVE-2024-49138 | Act now | 26.2% | — | ● | Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overfl… |
| CVE-2021-22506 | Act now | 25.7% | — | ● | Micro Focus Access Manager contains an information leakage vulnerability resulting from a … |
| CVE-2015-2590 | Act now | 25.5% | — | ● | An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an … |
| CVE-2023-20269 | Act now | 25.5% | 5.0 | ● | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA… |
| CVE-2026-20245 | Act now | 25.3% | 7.8 | ● | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Ci… |
| CVE-2018-6882 | Act now | 25.3% | 6.1 | ● | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml functi… |
| CVE-2016-7855 | Act now | 25.2% | — | ● | Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote … |
| CVE-2022-0185 | Act now | 25.2% | — | ● | Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param… |
| CVE-2019-18187 | Act now | 25.1% | — | ● | Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files fr… |
| CVE-2018-5002 | Act now | 25.1% | — | ● | Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to rem… |
| CVE-2024-35250 | Act now | 25.0% | — | ● | Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerabili… |
| CVE-2009-1862 | Act now | 24.9% | — | ● | Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or… |
| CVE-2014-0502 | Act now | 24.8% | — | ● | Adobe Flash Player contains a double free vulnerability that allows a remote attacker to e… |
| CVE-2022-3038 | Act now | 24.7% | — | ● | Google Chromium Network Service contains a use-after-free vulnerability that allows a remo… |
| CVE-2022-41128 | Act now | 24.6% | 8.8 | ● | Windows Scripting Languages Remote Code Execution Vulnerability |
| CVE-2026-20122 | Act now | 24.6% | — | ● | Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability d… |
| CVE-2023-48365 | Act now | 24.5% | — | ● | Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate pr… |
| CVE-2016-0040 | Act now | 24.5% | — | ● | The kernel in Microsoft Windows allows local users to gain privileges via a crafted applic… |
| CVE-2018-19949 | Act now | 24.4% | 9.8 | ● | If exploited, this command injection vulnerability could allow remote attackers to run arb… |
| CVE-2025-4632 | Act now | 24.3% | — | ● | Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker… |
| CVE-2016-9563 | Act now | 24.2% | — | ● | SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in B… |
| CVE-2022-1096 | Act now | 24.2% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote att… |
| CVE-2020-1380 | Act now | 24.2% | — | ● | Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for… |
| CVE-2021-27878 | Act now | 24.0% | — | ● | Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow… |
| CVE-2018-19953 | Act now | 23.9% | 6.1 | ● | If exploited, this cross-site scripting vulnerability could allow remote attackers to inje… |
| CVE-2023-32439 | Act now | 23.8% | — | ● | Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that le… |
| CVE-2021-3560 | Act now | 23.7% | — | ● | Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of … |
| CVE-2024-27443 | Act now | 23.6% | — | ● | Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarIn… |
| CVE-2016-4656 | Act now | 23.4% | — | ● | A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in … |
| CVE-2025-23006 | Act now | 23.4% | 9.8 | ● | Pre-authentication deserialization of untrusted data vulnerability has been identified in … |
| CVE-2021-36948 | Act now | 23.3% | 7.8 | ● | Windows Update Medic Service Elevation of Privilege Vulnerability |
| CVE-2024-9680 | Act now | 23.2% | 9.8 | ● | An attacker was able to achieve code execution in the content process by exploiting a use-… |
| CVE-2015-5317 | Act now | 23.0% | — | ● | Jenkins User Interface (UI) contains an information disclosure vulnerability that allows u… |
| CVE-2023-28206 | Act now | 23.0% | — | ● | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerabi… |