Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-48908 | Act now | 15.1% | — | ● | JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vul… |
| CVE-2022-38028 | Act now | 14.9% | — | ● | Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An … |
| CVE-2022-20708 | Act now | 14.9% | — | ● | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers coul… |
| CVE-2026-56291 | Act now | 14.9% | 9.8 | ● | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < … |
| CVE-2015-2360 | Act now | 14.8% | — | ● | Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain priv… |
| CVE-2021-30883 | Act now | 14.7% | — | ● | Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could a… |
| CVE-2018-14634 | Act now | 14.7% | — | ● | Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() functio… |
| CVE-2020-10181 | Act now | 14.7% | — | ● | Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) v… |
| CVE-2024-8069 | Act now | 14.6% | — | ● | Citrix Session Recording contains a deserialization of untrusted data vulnerability that a… |
| CVE-2026-85706 | Act now | 14.6% | 10.0 | ● | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.… |
| CVE-2021-1789 | Act now | 14.5% | — | ● | A type confusion issue affecting multiple Apple products allows processing of maliciously … |
| CVE-2010-3904 | Act now | 14.5% | — | ● | Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram … |
| CVE-2019-7193 | Act now | 14.4% | — | ● | QNAP QTS contains an improper input validation vulnerability allowing remote attackers to … |
| CVE-2023-28204 | Act now | 14.3% | — | ● | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read v… |
| CVE-2022-26485 | Act now | 14.3% | 8.8 | ● | Removing an XSLT parameter during processing could have lead to an exploitable use-after-f… |
| CVE-2018-0151 | Act now | 14.2% | — | ● | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco … |
| CVE-2024-49039 | Act now | 14.2% | 8.8 | ● | Windows Task Scheduler Elevation of Privilege Vulnerability |
| CVE-2021-22900 | Act now | 14.1% | — | ● | Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows… |
| CVE-2019-9875 | Act now | 14.0% | — | ● | Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the S… |
| CVE-2023-38180 | Act now | 14.0% | 7.5 | ● | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2025-29824 | Act now | 13.9% | — | ● | Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerabi… |
| CVE-2025-42999 | Act now | 13.9% | 9.1 | ● | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can u… |
| CVE-2025-31201 | Act now | 13.9% | — | ● | Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vul… |
| CVE-2024-12686 | Act now | 13.8% | — | ● | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command i… |
| CVE-2017-12240 | Act now | 13.8% | — | ● | The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS … |
| CVE-2016-0165 | Act now | 13.7% | — | ● | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalatio… |
| CVE-2022-1364 | Act now | 13.7% | — | ● | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote att… |
| CVE-2024-38213 | Act now | 13.6% | — | ● | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows… |
| CVE-2015-4902 | Act now | 13.6% | — | ● | Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity vi… |
| CVE-2022-38181 | Act now | 13.6% | — | ● | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-pr… |
| CVE-2023-20867 | Act now | 13.5% | — | ● | VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully… |
| CVE-2021-27876 | Act now | 13.5% | — | ● | Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an at… |
| CVE-2019-3010 | Act now | 13.4% | — | ● | Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows f… |
| CVE-2021-30858 | Act now | 13.4% | — | ● | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to c… |
| CVE-2026-22769 | Act now | 13.3% | — | ● | Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials … |
| CVE-2022-22948 | Act now | 13.3% | — | ● | VMware vCenter Server contains an incorrect default file permissions vulnerability that al… |
| CVE-2026-46817 | Act now | 13.0% | 9.8 | ● | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File T… |
| CVE-2025-6554 | Act now | 12.7% | — | ● | Google Chromium V8 contains a type confusion vulnerability that could allow a remote attac… |
| CVE-2022-23176 | Act now | 12.7% | — | ● | WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credential… |
| CVE-2026-34926 | Act now | 12.7% | 6.7 | ● | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-… |
| CVE-2024-21410 | Act now | 12.6% | — | ● | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege … |
| CVE-2022-22675 | Act now | 12.5% | — | ● | macOS Monterey contains an out-of-bounds write vulnerability that could allow an applicati… |
| CVE-2022-20775 | Act now | 12.5% | — | ● | Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated… |
| CVE-2023-36424 | Act now | 12.2% | — | ● | Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerabili… |
| CVE-2023-32373 | Act now | 12.2% | — | ● | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulner… |
| CVE-2022-20821 | Act now | 12.1% | — | ● | Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attack… |
| CVE-2021-28663 | Act now | 12.1% | — | ● | Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerabil… |
| CVE-2023-21715 | Act now | 12.0% | 7.3 | ● | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2023-36033 | Act now | 12.0% | — | ● | Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulner… |
| CVE-2017-11292 | Act now | 11.9% | — | ● | Adobe Flash Player contains a type confusion vulnerability which can allow for remote code… |