All vulnerabilities
698 / 698
Sort
7.5
CVE-2021-41277CVE KEV
Metabase is an open source data analytics platform. In affected versions a security issue has b…
2021-01-01KEV
EPSS94.4%
pct 99
8.6
CVE-2024-24919CVE KEV
Potentially allowing an attacker to read certain information on Check Point Security Gateways o…
2024-01-01KEV
EPSS94.3%
pct 99
7.5
CVE-2023-49103CVE KEV
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1…
2023-01-01KEV
EPSS94.3%
pct 99
8.1
CVE-2019-5418AST KEV
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <…
2019-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2021-27850CVE
A critical unauthenticated remote code execution vulnerability was found all recent versions of…
2021-01-01Pre-auth
EPSS94.2%
pct 99
7.5
CVE-2023-28432DEB KEV
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.…
2023-01-01KEV
EPSS94.0%
pct 99
6.5
CVE-2021-36749DEB
In the Druid ingestion system, the InputSource is used for reading data from a certain data sou…
2021-01-01
EPSS93.8%
pct 99
5.3
CVE-2021-34429DEB
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted us…
2021-01-01Pre-auth
EPSS93.8%
pct 99
7.5
CVE-2024-29059MSR KEV
.NET Framework Information Disclosure Vulnerability
2024-01-01MicrosoftKEV
EPSS93.7%
pct 99
5.3
CVE-2020-14181CVE
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enu…
2020-01-01Pre-auth
EPSS93.5%
pct 99
5.3
CVE-2021-28164DEB
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows reque…
2021-01-01Pre-auth
EPSS93.5%
pct 99
4.3
CVE-2015-8399CVE
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration file…
2015-01-01
EPSS93.3%
pct 99
7.5
CVE-2024-0305CVE
A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classi…
2024-01-01Pre-auth
EPSS93.1%
pct 99
6.5
CVE-2018-18778DEB
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
2018-01-01
EPSS93.1%
pct 99
7.5
CVE-2016-6415CVE KEV
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE th…
2016-01-01KEV
EPSS92.7%
pct 99
5.3
CVE-2017-5487DEB
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementatio…
2017-01-01Pre-auth
EPSS92.5%
pct 99
9.8
CVE-2018-12634CVE
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direc…
2018-01-01Pre-auth
EPSS92.4%
pct 99
5.3
CVE-2018-11409CVE
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/serv…
2018-01-01Pre-auth
EPSS92.2%
pct 99
7.5
CVE-2018-8033CVE
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.Ht…
2018-01-01Pre-auth
EPSS92.2%
pct 99
5.3
CVE-2024-30269ANC
DataEase, an open source data visualization and analysis tool, has a database configuration inf…
2024-01-01Pre-auth
EPSS91.9%
pct 99
9.8
CVE-2017-11165CVE
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configur…
2017-01-01Pre-auth
EPSS91.5%
pct 99
7.5
CVE-2015-2080DEB
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to …
2015-01-01Pre-auth
EPSS91.4%
pct 99
5.3
CVE-2021-39327CVE
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due…
2021-01-01Pre-auth
EPSS90.9%
pct 99
9.8
CVE-2018-7251CVE
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an er…
2018-01-01Pre-auth
EPSS90.6%
pct 99
5.3
CVE-2018-15473AST
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout fo…
2018-01-01Pre-auth
EPSS90.4%
pct 99
6.9
CVE-2024-7339CVE
A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-…
2024-01-01Pre-auth
EPSS90.3%
pct 99
5.3
CVE-2016-6210DEB
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOW…
2016-01-01Pre-auth
EPSS90.0%
pct 99
7.5
CVE-2025-30208ANC
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.…
2025-01-01Pre-auth
EPSS89.8%
pct 99
8.1
CVE-2024-3656DEB
A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privileg…
2024-01-01
EPSS89.7%
pct 99
8.8
CVE-2021-32819CVE
Squirrelly is a template engine implemented in JavaScript that works out of the box with Expres…
2021-01-01Pre-auth
EPSS89.6%
pct 99
5.9
CVE-1999-0517CVE
An SNMP community name is the default (e.g. public), null, or missing.
1999-01-01
EPSS89.6%
pct 99
7.5
CVE-2022-45354CVE
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Mo…
2022-01-01Pre-auth
EPSS89.4%
pct 99
7.5
CVE-2017-16894DEB
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as…
2017-01-01Pre-auth
EPSS88.8%
pct 99
6.5
CVE-2022-44268AST
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g.,…
2022-01-01Pre-auth
EPSS88.6%
pct 99
7.5
CVE-2014-7863CVE
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager b…
2014-01-01Pre-auth
EPSS88.2%
pct 99
5.0
CVE-2009-0580DEB
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM a…
2009-01-01
EPSS88.2%
pct 99
4.3
CVE-2018-16323DEB
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when proce…
2018-01-01Pre-auth
EPSS87.5%
pct 99
7.5
CVE-2011-4367DEB
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFace…
2011-01-01Pre-auth
EPSS85.9%
pct 99
9.8
CVE-2025-11749ANC
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi…
2025-01-01Pre-auth
EPSS85.7%
pct 99
7.5
CVE-2016-1561CVE
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized…
2016-01-01Pre-auth
EPSS84.4%
pct 99
Select a vulnerability on the left to open the preview.