Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-24472 | Act now | 7.2% | 8.1 | ● | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affect… |
| CVE-2004-0210 | Act now | 7.2% | — | ● | A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability coul… |
| CVE-2018-0158 | Act now | 7.2% | — | ● | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functiona… |
| CVE-2022-24521 | Act now | 7.1% | — | ● | Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerabili… |
| CVE-2024-38080 | Act now | 7.1% | — | ● | Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a loca… |
| CVE-2026-34621 | Act now | 7.1% | 8.6 | ● | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improper… |
| CVE-2021-1879 | Act now | 7.1% | — | ● | Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for… |
| CVE-2019-0344 | Act now | 7.1% | — | ● | SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data… |
| CVE-2017-12231 | Act now | 7.1% | — | ● | A vulnerability in the implementation of Network Address Translation (NAT) functionality i… |
| CVE-2017-12233 | Act now | 7.1% | — | ● | There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) fea… |
| CVE-2017-12234 | Act now | 7.1% | — | ● | There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) fea… |
| CVE-2017-12235 | Act now | 7.1% | — | ● | A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol… |
| CVE-2017-12237 | Act now | 7.1% | — | ● | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cis… |
| CVE-2018-0154 | Act now | 7.1% | — | ● | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-… |
| CVE-2020-6820 | Act now | 7.1% | — | ● | Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a Rea… |
| CVE-2023-26369 | Act now | 7.1% | — | ● | Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for cod… |
| CVE-2021-30713 | Act now | 7.0% | — | ● | Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions i… |
| CVE-2021-1871 | Act now | 7.0% | — | ● | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows… |
| CVE-2024-57728 | Act now | 7.0% | — | ● | SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbit… |
| CVE-2021-30952 | Act now | 7.0% | — | ● | Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vu… |
| CVE-2026-20128 | Act now | 6.9% | — | ● | Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnera… |
| CVE-2019-1064 | Act now | 6.9% | — | ● | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard l… |
| CVE-2008-3431 | Act now | 6.9% | — | ● | An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox w… |
| CVE-2022-27518 | Act now | 6.9% | — | ● | Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or … |
| CVE-2018-0159 | Act now | 6.9% | — | ● | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functiona… |
| CVE-2026-33825 | Act now | 6.7% | 7.8 | ● | Insufficient granularity of access control in Microsoft Defender allows an authorized atta… |
| CVE-2013-1675 | Act now | 6.7% | — | ● | Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mP… |
| CVE-2012-0767 | Act now | 6.7% | — | ● | Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web… |
| CVE-2021-33739 | Act now | 6.6% | — | ● | Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability … |
| CVE-2025-24990 | Act now | 6.4% | — | ● | Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerabili… |
| CVE-2020-16010 | Act now | 6.4% | — | ● | Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a r… |
| CVE-2024-38106 | Act now | 6.3% | — | ● | Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege e… |
| CVE-2024-38014 | Act now | 6.3% | 7.8 | ● | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-68820 | Act now | 6.2% | 7.0 | ● | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attac… |
| CVE-2020-8468 | Act now | 6.2% | — | ● | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a conten… |
| CVE-2017-6627 | Act now | 6.2% | — | ● | A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthen… |
| CVE-2019-1069 | Act now | 6.1% | 7.8 | ● | An elevation of privilege vulnerability exists in the way the Task Scheduler Service valid… |
| CVE-2021-22600 | Act now | 6.1% | — | ● | Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could l… |
| CVE-2021-27059 | Act now | 6.1% | 7.6 | ● | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2021-27101 | Act now | 6.0% | — | ● | Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header i… |
| CVE-2025-62215 | Act now | 6.0% | — | ● | Microsoft Windows Kernel contains a race condition vulnerability that allows a local attac… |
| CVE-2019-15271 | Act now | 6.0% | — | ● | A deserialization of untrusted data vulnerability in the web-based management interface of… |
| CVE-2019-6693 | Act now | 5.8% | 6.5 | ● | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration ba… |
| CVE-2022-26500 | Act now | 5.8% | — | ● | The Veeam Distribution Service in the Backup & Replication application allows unauthentica… |
| CVE-2022-3075 | Act now | 5.8% | — | ● | Google Chromium Mojo contains an insufficient data validation vulnerability that allows a … |
| CVE-2026-3502 | Act now | 5.7% | — | ● | TrueConf Client contains a download of code without integrity check vulnerability. An atta… |
| CVE-2023-2136 | Act now | 5.7% | — | ● | Google Chromium Skia contains an integer overflow vulnerability that allows a remote attac… |
| CVE-2016-0167 | Act now | 5.7% | — | ● | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalatio… |
| CVE-2010-3035 | Act now | 5.7% | — | ● | Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause… |
| CVE-2022-20700 | Act now | 5.7% | — | ● | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers coul… |