Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-3129 | Act now | 99.9% | — | ● | Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote a… |
| CVE-2020-10189 | Act now | 99.9% | — | ● | Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for una… |
| CVE-2014-7169 | Act now | 99.9% | — | ● | GNU Bash through 4.3 processes trailing strings after function definitions in the values o… |
| CVE-2015-3113 | Act now | 99.9% | — | ● | Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to … |
| CVE-2022-22963 | Act now | 99.9% | — | ● | When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible f… |
| CVE-2024-27198 | Act now | 99.9% | — | ● | JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker… |
| CVE-2021-26085 | Act now | 99.9% | — | ● | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted… |
| CVE-2023-34362 | Act now | 99.9% | — | ● | Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauth… |
| CVE-2017-0199 | Act now | 99.9% | — | ● | Microsoft Office and WordPad contain an unspecified vulnerability due to the way the appli… |
| CVE-2021-38647 | Act now | 99.9% | 9.8 | ● | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
| CVE-2021-39226 | Act now | 99.9% | — | ● | Grafana contains an authentication bypass vulnerability that allows authenticated and unau… |
| CVE-2021-1497 | Act now | 99.9% | — | ● | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vul… |
| CVE-2022-35405 | Act now | 99.9% | — | ● | Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspeci… |
| CVE-2025-24813 | Act now | 99.9% | — | ● | Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to e… |
| CVE-2025-4427 | Act now | 99.9% | — | ● | Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in t… |
| CVE-2026-10520 | Act now | 99.9% | 10.0 | ● | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10… |
| CVE-2018-0296 | Act now | 99.9% | 7.5 | ● | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could … |
| CVE-2019-0604 | Act now | 99.9% | — | ● | Microsoft SharePoint fails to check the source markup of an application package. An attack… |
| CVE-2019-3396 | Act now | 99.9% | — | ● | Atlassian Confluence Server and Data Center contain a server-side template injection vulne… |
| CVE-2021-20038 | Act now | 99.9% | — | ● | SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow … |
| CVE-2024-45519 | Act now | 99.9% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the post… |
| CVE-2026-31431 | Act now | 99.9% | 7.8 | ● | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - … |
| CVE-2015-1427 | Act now | 99.9% | — | ● | The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox… |
| CVE-2019-7481 | Act now | 99.9% | 7.5 | ● | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to u… |
| CVE-2020-7961 | Act now | 99.9% | — | ● | Liferay Portal contains a deserialization of untrusted data vulnerability that allows remo… |
| CVE-2023-21839 | Act now | 99.9% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticate… |
| CVE-2021-22986 | Act now | 99.9% | — | ● | F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability … |
| CVE-2014-0497 | Act now | 99.9% | — | ● | Adobe Flash Player contains an integer underflow vulnerability that allows a remote attack… |
| CVE-2022-35914 | Act now | 99.9% | — | ● | Teclib GLPI contains a remote code execution vulnerability in the third-party library, htm… |
| CVE-2019-1653 | Act now | 99.9% | — | ● | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access … |
| CVE-2021-27065 | Act now | 99.9% | 7.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-33044 | Act now | 99.9% | — | ● | Dahua IP cameras and related products contain an authentication bypass vulnerability when … |
| CVE-2021-44515 | Act now | 99.9% | — | ● | Zoho Desktop Central contains an authentication bypass vulnerability that could allow an a… |
| CVE-2021-36260 | Act now | 99.9% | — | ● | A command injection vulnerability in the web server of some Hikvision product. Due to the … |
| CVE-2021-21972 | Act now | 99.9% | 9.8 | ● | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Ser… |
| CVE-2025-24893 | Act now | 99.9% | — | ● | XWiki Platform contains an eval injection vulnerability that could allow any guest to perf… |
| CVE-2021-35394 | Act now | 99.9% | — | ● | RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an … |
| CVE-2025-32432 | Act now | 99.8% | — | ● | Craft CMS contains a code injection vulnerability that allows a remote attacker to execute… |
| CVE-2023-23752 | Act now | 99.8% | — | ● | Joomla! contains an improper access control vulnerability that allows unauthorized access … |
| CVE-2022-46169 | Act now | 99.8% | — | ● | Cacti contains a command injection vulnerability that allows an unauthenticated user to ex… |
| CVE-2021-37415 | Act now | 99.8% | — | ● | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass tha… |
| CVE-2017-7269 | Act now | 99.8% | — | ● | Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Info… |
| CVE-2024-36401 | Act now | 99.8% | — | ● | OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically … |
| CVE-2020-0796 | Act now | 99.8% | 10.0 | ● | A remote code execution vulnerability exists in the way that the Microsoft Server Message … |
| CVE-2016-6277 | Act now | 99.8% | — | ● | NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input dire… |
| CVE-2025-55182 | Act now | 99.8% | 10.0 | ● | A pre-authentication remote code execution vulnerability exists in React Server Components… |
| CVE-2025-10035 | Act now | 99.8% | 10.0 | ● | A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows a… |
| CVE-2023-29298 | Act now | 99.8% | — | ● | Adobe ColdFusion contains an improper access control vulnerability that allows for a secur… |
| CVE-2022-1040 | Act now | 99.8% | — | ● | An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allo… |
| CVE-2021-34527 | Act now | 99.8% | 8.8 | ● | A remote code execution vulnerability exists when the Windows Print Spooler service improp… |