Browse vulnerabilities
377,708 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-31207 | Act now | 99.8% | — | ● | Microsoft Exchange Server contains an unspecified vulnerability that allows for security f… |
| CVE-2019-11043 | Act now | 99.8% | — | ● | In some versions of PHP in certain configurations of FPM setup, it is possible to cause FP… |
| CVE-2020-13927 | Act now | 99.8% | — | ● | The previous default setting for Airflow's Experimental API was to allow all API requests … |
| CVE-2025-25257 | Act now | 99.8% | — | ● | Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated… |
| CVE-2021-31166 | Act now | 99.8% | — | ● | Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote … |
| CVE-2019-15107 | Act now | 99.8% | 9.8 | ● | An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contai… |
| CVE-2022-47966 | Act now | 99.8% | 9.8 | ● | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, al… |
| CVE-2023-3519 | Act now | 99.7% | 9.8 | ● | Unauthenticated remote code execution |
| CVE-2023-38205 | Act now | 99.7% | — | ● | Adobe ColdFusion contains an improper access control vulnerability that allows for a secur… |
| CVE-2019-18935 | Act now | 99.7% | — | ● | Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerab… |
| CVE-2020-15505 | Act now | 99.7% | — | ● | Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) pro… |
| CVE-2025-61882 | Act now | 99.7% | 9.8 | ● | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (comp… |
| CVE-2021-22205 | Act now | 99.7% | 10.0 | ● | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. Gi… |
| CVE-2019-16759 | Act now | 99.7% | — | ● | The PHP module within vBulletin contains an unspecified vulnerability that allows for remo… |
| CVE-2023-46604 | Act now | 99.7% | — | ● | Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow … |
| CVE-2010-2861 | Act now | 99.7% | 9.8 | ● | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFus… |
| CVE-2024-0012 | Act now | 99.7% | 9.8 | ● | An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated … |
| CVE-2016-10033 | Act now | 99.7% | — | ● | PHPMailer contains a command injection vulnerability because it fails to sanitize user-sup… |
| CVE-2017-0147 | Act now | 99.7% | — | ● | The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive informat… |
| CVE-2017-1000353 | Act now | 99.7% | — | ● | Jenkins contains a remote code execution vulnerability. This vulnerability that could allo… |
| CVE-2025-48703 | Act now | 99.7% | — | ● | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnera… |
| CVE-2022-22965 | Act now | 99.6% | — | ● | Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote cod… |
| CVE-2024-5217 | Act now | 99.6% | — | ● | ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomple… |
| CVE-2024-9465 | Act now | 99.6% | — | ● | Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauth… |
| CVE-2024-28995 | Act now | 99.6% | — | ● | SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access t… |
| CVE-2017-12615 | Act now | 99.6% | 8.1 | ● | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via set… |
| CVE-2020-16846 | Act now | 99.6% | — | ● | SaltStack Salt allows an unauthenticated user with network access to the Salt API to use s… |
| CVE-2023-20198 | Act now | 99.6% | — | ● | Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interfac… |
| CVE-2026-8037 | Act now | 99.6% | 9.6 | ● | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products a… |
| CVE-2021-33045 | Act now | 99.6% | — | ● | Dahua IP cameras and related products contain an authentication bypass vulnerability when … |
| CVE-2024-4040 | Act now | 99.5% | — | ● | CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacke… |
| CVE-2018-20062 | Act now | 99.5% | — | ● | ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execu… |
| CVE-2014-6278 | Act now | 99.5% | — | ● | GNU Bash contains an OS command injection vulnerability which allows remote attackers to e… |
| CVE-2025-31324 | Act now | 99.5% | 10.0 | ● | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorizati… |
| CVE-2018-0171 | Act now | 99.5% | — | ● | Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticate… |
| CVE-2022-42475 | Act now | 99.5% | — | ● | Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnera… |
| CVE-2024-23692 | Act now | 99.5% | 9.8 | ● | Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template in… |
| CVE-2017-7494 | Act now | 99.4% | — | ● | Samba contains a remote code execution vulnerability, allowing a malicious client to uploa… |
| CVE-2018-2628 | Act now | 99.4% | — | ● | Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenti… |
| CVE-2024-32113 | Act now | 99.4% | — | ● | Apache OFBiz contains a path traversal vulnerability that could allow for remote code exec… |
| CVE-2023-34048 | Act now | 99.4% | — | ● | VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation … |
| CVE-2024-38856 | Act now | 99.4% | — | ● | Apache OFBiz contains an incorrect authorization vulnerability that could allow remote cod… |
| CVE-2011-0611 | Act now | 99.4% | — | ● | Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitr… |
| CVE-2017-9805 | Act now | 99.4% | — | ● | Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deseriali… |
| CVE-2021-32030 | Act now | 99.4% | — | ● | ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability… |
| CVE-2020-1472 | Act now | 99.4% | — | ● | Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerabili… |
| CVE-2017-0148 | Act now | 99.4% | — | ● | The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafte… |
| CVE-2022-0543 | Act now | 99.4% | — | ● | Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote cod… |
| CVE-2015-5119 | Act now | 99.3% | — | ● | A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe F… |
| CVE-2014-6287 | Act now | 99.3% | — | ● | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFile… |