Browse vulnerabilities
377,848 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-21492 | Act now | 2.6% | — | ● | Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive in… |
| CVE-2025-62221 | Act now | 2.5% | — | ● | Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability t… |
| CVE-2022-41049 | Act now | 2.5% | 5.4 | ● | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-21519 | Act now | 2.5% | — | ● | Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow… |
| CVE-2025-32975 | Act now | 2.5% | — | ● | Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerab… |
| CVE-2025-30154 | Act now | 2.4% | — | ● | reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability tha… |
| CVE-2025-25249 | Act now | 2.4% | 8.1 | ● | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiO… |
| CVE-2022-0028 | Act now | 2.4% | — | ● | A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-ba… |
| CVE-2022-26486 | Act now | 2.3% | 9.6 | ● | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and explo… |
| CVE-2023-20109 | Act now | 2.3% | — | ● | Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted T… |
| CVE-2026-45321 | Act now | 2.3% | — | ● | TanStack contains an unspecified vulnerability that allowed malicious versions of the prod… |
| CVE-2025-21391 | Act now | 2.3% | — | ● | Microsoft Windows Storage contains a link following vulnerability that could allow for pri… |
| CVE-2025-53521 | Act now | 2.3% | — | ● | F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a thre… |
| CVE-2025-32706 | Act now | 2.3% | — | ● | Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overfl… |
| CVE-2019-0880 | Act now | 2.3% | — | ● | A local elevation of privilege vulnerability exists in how splwow64.exe handles certain ca… |
| CVE-2020-9818 | Act now | 2.3% | — | ● | Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which ma… |
| CVE-2019-1130 | Act now | 2.3% | 7.8 | ● | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXS… |
| CVE-2022-41073 | Act now | 2.3% | 7.8 | ● | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2021-1782 | Act now | 2.2% | — | ● | Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that ma… |
| CVE-2026-20349 | Act now | 2.2% | 8.6 | ● | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Se… |
| CVE-2026-11645 | Act now | 2.2% | 8.8 | ● | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remo… |
| CVE-2020-9819 | Act now | 2.2% | — | ● | Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may al… |
| CVE-2025-24993 | Act now | 2.2% | — | ● | Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow … |
| CVE-2017-12232 | Act now | 2.2% | — | ● | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers G… |
| CVE-2026-75650 | Act now | 2.1% | 10.0 | ● | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Tem… |
| CVE-2025-32709 | Act now | 2.1% | — | ● | Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerab… |
| CVE-2025-3928 | Act now | 2.1% | — | ● | Commvault Web Server contains an unspecified vulnerability that allows a remote, authentic… |
| CVE-2017-6663 | Act now | 2.1% | — | ● | A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE… |
| CVE-2025-40602 | Act now | 2.1% | — | ● | SonicWall SMA1000 contains a missing authorization vulnerability that could allow for priv… |
| CVE-2021-40450 | Act now | 2.1% | — | ● | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalatio… |
| CVE-2021-41357 | Act now | 2.1% | — | ● | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalatio… |
| CVE-2023-6448 | Act now | 2.1% | — | ● | Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if le… |
| CVE-2017-12238 | Act now | 2.0% | — | ● | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Cata… |
| CVE-2026-76461 | Act now | 2.0% | 9.8 | ● | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gate… |
| CVE-2026-3910 | Act now | 2.0% | — | ● | Google Chromium V8 contains an improper restriction of operations within the bounds of a m… |
| CVE-2025-0111 | Act now | 2.0% | — | ● | Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability.… |
| CVE-2020-2506 | Act now | 2.0% | — | ● | QNAP Helpdesk contains an improper access control vulnerability which could allow an attac… |
| CVE-2025-24991 | Act now | 2.0% | — | ● | Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnera… |
| CVE-2025-24984 | Act now | 2.0% | — | ● | Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Inf… |
| CVE-2026-49869 | Act now | 1.9% | 10.0 | ● | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,… |
| CVE-2025-21043 | Act now | 1.9% | — | ● | Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram… |
| CVE-2025-30400 | Act now | 1.9% | — | ● | Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an … |
| CVE-2019-0797 | Act now | 1.9% | — | ● | Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component f… |
| CVE-2025-59689 | Act now | 1.9% | — | ● | Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which al… |
| CVE-2025-27920 | Act now | 1.9% | — | ● | Srimax Output Messenger contains a directory traversal vulnerability that allows an attack… |
| CVE-2026-48027 | Act now | 1.9% | — | ● | Nx Console contains an embedded malicious code vulnerability that allowed a malicious vers… |
| CVE-2026-72530 | Act now | 1.8% | 9.0 | ● | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf serve… |
| CVE-2024-7694 | Act now | 1.8% | — | ● | TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous … |
| CVE-2022-41091 | Act now | 1.8% | 5.4 | ● | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2018-19322 | Act now | 1.8% | 7.8 | ● | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS … |