Browse vulnerabilities
377,848 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2019-1129 | Act now | 1.8% | — | ● | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard l… |
| CVE-2020-11261 | Act now | 1.8% | — | ● | Memory corruption due to improper check to return error when user application requests mem… |
| CVE-2025-22226 | Act now | 1.7% | — | ● | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due t… |
| CVE-2024-21287 | Act now | 1.7% | — | ● | Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulner… |
| CVE-2025-8875 | Act now | 1.7% | — | ● | N-able N-Central contains an insecure deserialization vulnerability that could lead to com… |
| CVE-2025-21590 | Act now | 1.7% | — | ● | Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. Thi… |
| CVE-2025-48595 | Act now | 1.7% | 8.4 | ● | In multiple locations, there is a possible way to achieve code execution due to an integer… |
| CVE-2025-15556 | Act now | 1.7% | — | ● | Notepad++ when using the WinGUp updater, contains a download of code without integrity che… |
| CVE-2025-48700 | Act now | 1.7% | — | ● | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability tha… |
| CVE-2022-41033 | Act now | 1.7% | — | ● | Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that all… |
| CVE-2023-28229 | Act now | 1.7% | — | ● | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an un… |
| CVE-2024-39891 | Act now | 1.7% | — | ● | Twilio Authy contains an information disclosure vulnerability in its API that allows an un… |
| CVE-2024-38107 | Act now | 1.6% | — | ● | Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that … |
| CVE-2026-3909 | Act now | 1.6% | — | ● | Google Skia contains an out-of-bounds write vulnerability that could allow a remote attack… |
| CVE-2025-24989 | Act now | 1.6% | — | ● | Microsoft Power Pages contains an improper access control vulnerability that allows an una… |
| CVE-2026-8452 | Act now | 1.6% | 9.8 | ● | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable… |
| CVE-2025-21418 | Act now | 1.6% | — | ● | Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overf… |
| CVE-2026-16812 | Act now | 1.6% | 10.0 | ● | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a rem… |
| CVE-2025-21334 | Act now | 1.6% | — | ● | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerabilit… |
| CVE-2025-22224 | Act now | 1.6% | — | ● | VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vu… |
| CVE-2019-8720 | Act now | 1.6% | — | ● | WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perfor… |
| CVE-2026-72529 | Act now | 1.6% | 9.8 | ● | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf serve… |
| CVE-2026-21514 | Act now | 1.5% | — | ● | Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulne… |
| CVE-2021-1905 | Act now | 1.5% | — | ● | Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling… |
| CVE-2025-31277 | Act now | 1.5% | — | ● | Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vu… |
| CVE-2013-2597 | Act now | 1.5% | — | ● | The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buff… |
| CVE-2021-36742 | Act now | 1.5% | — | ● | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an i… |
| CVE-2024-23225 | Act now | 1.5% | — | ● | Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption v… |
| CVE-2023-20963 | Act now | 1.5% | — | ● | Android Framework contains an unspecified vulnerability that allows for privilege escalati… |
| CVE-2026-85046 | Act now | 1.5% | 8.8 | ● | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to … |
| CVE-2026-8398 | Act now | 1.5% | — | ● | Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiali… |
| CVE-2026-54420 | Act now | 1.4% | 8.5 | ● | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.… |
| CVE-2019-1214 | Act now | 1.4% | — | ● | Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memor… |
| CVE-2024-23296 | Act now | 1.4% | — | ● | Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerabilit… |
| CVE-2023-41974 | Act now | 1.4% | — | ● | Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute… |
| CVE-2024-8068 | Act now | 1.4% | — | ● | Citrix Session Recording contains an improper privilege management vulnerability that coul… |
| CVE-2025-32701 | Act now | 1.4% | — | ● | Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerabi… |
| CVE-2025-21335 | Act now | 1.4% | — | ● | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerabilit… |
| CVE-2023-41990 | Act now | 1.4% | — | ● | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allo… |
| CVE-2020-0069 | Act now | 1.4% | — | ● | Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have… |
| CVE-2024-53150 | Act now | 1.4% | — | ● | Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that all… |
| CVE-2025-24983 | Act now | 1.3% | — | ● | Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allo… |
| CVE-2026-20700 | Act now | 1.3% | — | ● | Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operation… |
| CVE-2025-35939 | Act now | 1.3% | — | ● | Craft CMS contains an external control of assumed-immutable web parameter vulnerability. T… |
| CVE-2024-49035 | Act now | 1.3% | — | ● | Microsoft Partner Center contains an improper access control vulnerability that allows an … |
| CVE-2023-4346 | Act now | 1.3% | — | ● | KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrict… |
| CVE-2026-21385 | Act now | 1.3% | — | ● | Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignment… |
| CVE-2025-38352 | Act now | 1.3% | 7.8 | ● | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix… |
| CVE-2023-26083 | Act now | 1.2% | — | ● | Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a … |
| CVE-2025-39682 | Act now | 1.2% | 9.8 | ● | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of … |