Browse vulnerabilities
377,957 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2014-7285 | High | 50.3% | — | — | |
| CVE-2021-30119 | High | 50.3% | 5.4 | Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDes… | |
| CVE-2017-16720 | High | 50.3% | — | — | |
| CVE-2017-6465 | High | 50.3% | — | — | |
| CVE-2015-5127 | High | 50.3% | — | — | |
| CVE-2015-5130 | High | 50.3% | — | — | |
| CVE-2015-5134 | High | 50.3% | — | — | |
| CVE-2022-36633 | High | 50.3% | — | — | |
| CVE-2025-49002 | High | 50.3% | — | — | |
| CVE-2012-3363 | High | 50.2% | — | — | |
| CVE-2025-47188 | High | 50.2% | — | — | |
| CVE-2021-3407 | High | 50.2% | — | — | |
| CVE-2010-3229 | High | 50.2% | — | — | |
| CVE-2018-2894 | High | 50.2% | — | — | |
| CVE-2021-40493 | High | 50.2% | — | — | |
| CVE-2023-34124 | High | 50.2% | — | — | |
| CVE-2024-1380 | High | 50.2% | — | — | |
| CVE-2010-0477 | High | 50.2% | — | — | |
| CVE-2017-14078 | High | 50.2% | — | — | |
| CVE-2023-44351 | High | 50.2% | — | — | |
| CVE-2021-40856 | High | 50.1% | — | — | |
| CVE-2021-4044 | High | 50.1% | — | — | |
| CVE-2018-14364 | High | 50.1% | — | — | |
| CVE-2017-14535 | High | 50.1% | — | — | |
| CVE-2017-14098 | High | 50.1% | — | — | |
| CVE-2017-11890 | High | 50.1% | — | — | |
| CVE-2023-1133 | High | 50.1% | — | — | |
| CVE-2020-17518 | High | 50.0% | — | — | |
| CVE-2024-33610 | High | 50.0% | — | — | |
| CVE-2021-35621 | High | 50.0% | — | — | |
| CVE-2012-4915 | High | 50.0% | — | — | |
| CVE-2017-8538 | High | 50.0% | — | — | |
| CVE-2025-34027 | High | 45.2% | 9.0 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass… | |
| CVE-2026-46442 | High | 36.3% | 9.9 | Flowise is a drag & drop user interface to build a customized large language model flow. P… | |
| CVE-2026-34156 | High | 35.0% | 9.9 | NocoBase is an AI-powered no-code/low-code platform for building business applications and… | |
| CVE-2025-56005 | High | 19.1% | 9.8 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote… | |
| CVE-2026-34938 | High | 13.2% | 10.0 | PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praiso… | |
| CVE-2026-35216 | High | 10.7% | 9.0 | Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated … | |
| CVE-2026-33439 | High | 10.0% | 9.8 | Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIde… | |
| CVE-2019-18184 | High | 8.1% | 9.8 | Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharact… | |
| CVE-2026-8985 | High | 6.6% | 9.8 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection … | |
| CVE-2026-62241 | High | 6.5% | 9.1 | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('… | |
| CVE-2026-7854 | High | 5.9% | 9.8 | A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this … | |
| CVE-2026-19586 | High | 5.7% | 9.8 | A pre-authentication OS command injection vulnerability has been identified in Omada gatew… | |
| CVE-2018-18861 | High | 4.5% | 9.8 | Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE co… | |
| CVE-2026-0545 | High | 4.4% | 9.8 | In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected… | |
| CVE-2026-45700 | High | 4.4% | 9.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP'… | |
| CVE-2026-61498 | High | 4.1% | 9.8 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in th… | |
| CVE-2026-39932 | High | 3.7% | 9.1 | OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document categ… | |
| CVE-2015-10138 | High | 3.6% | 9.8 | The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads… |