All vulnerabilities
43 / 43
Sort
7.8
CVE-2023-38831CVE KEV
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to vi…
2023-01-01KEV
EPSS97.8%
pct 99
7.2
CVE-2009-1185DEB
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which…
2009-01-01
EPSS81.5%
pct 99
8.8
CVE-2015-4495DEB KEV
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS…
2015-01-01KEV
EPSS70.2%
pct 99
9.4
CVE-2025-34291ANC KEV
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables accoun…
2025-01-01KEV
EPSS25.2%
pct 97
9.8
CVE-2022-26871CVE KEV
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticat…
2022-01-01KEV
EPSS19.5%
pct 97
7.4
CVE-2020-13777DEB
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss …
2020-01-01Pre-auth
EPSS17.5%
pct 96
9.3
CVE-2014-4936CVE
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malware…
2014-01-01
EPSS16.8%
pct 96
7.5
CVE-2021-33959CVE
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
2021-01-01Pre-auth
EPSS15.0%
pct 96
5.3
CVE-2017-18016CVE
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and …
2017-01-01Pre-auth
EPSS5.6%
pct 91
9.8
CVE-2019-3980CVE
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication …
2019-01-01Pre-auth
EPSS5.2%
pct 91
8.1
CVE-2020-8819CVE
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of…
2020-01-01
EPSS4.5%
pct 90
6.9
CVE-2025-51471DEB
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote …
2025-01-01Pre-auth
EPSS3.7%
pct 88
7.3
CVE-2022-31813ANC
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin serv…
2022-01-01Pre-auth
EPSS3.1%
pct 86
7.8
CVE-2019-0805MSR
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUA…
2019-01-01Microsoft
EPSS2.8%
pct 84
5.3
CVE-2023-51764DEB
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reje…
2023-01-01Pre-auth
EPSS2.6%
pct 83
9.8
CVE-2021-43616DEB
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if depen…
2021-01-01Pre-auth
EPSS2.5%
pct 82
7.3
CVE-2021-38295DEB
In Apache CouchDB, a malicious user with permission to create documents in a database is able t…
2021-01-01
EPSS2.5%
pct 82
6.3
CVE-2015-6254CVE
The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does n…
2015-01-01
EPSS1.8%
pct 75
7.8
CVE-2018-20225ANC
An issue was discovered in pip (all versions) because it installs the version with the highest …
2018-01-01
EPSS1.7%
pct 74
6.8
CVE-2024-23922CVE
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. Th…
2024-01-01
EPSS1.7%
pct 73
9.6
CVE-2022-41924CVE
A vulnerability identified in the Tailscale Windows client allows a malicious website to reconf…
2022-01-01Pre-auth
EPSS1.6%
pct 71
5.9
CVE-2017-7561DEB
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache…
2017-01-01Pre-auth
EPSS1.5%
pct 71
8.6
CVE-2024-45410ANC
Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefi…
2024-01-01Pre-auth
EPSS1.5%
pct 70
9.8
CVE-2022-25262CVE
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
2022-01-01Pre-auth
EPSS1.4%
pct 69
8.1
CVE-2020-11493CVE
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain…
2020-01-01Pre-auth
EPSS0.9%
pct 55
9.8
CVE-2020-26527CVE
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource…
2020-01-01Pre-auth
EPSS0.9%
pct 54
7.8
CVE-2021-30005DEB
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient…
2021-01-01
EPSS0.8%
pct 53
8.2
CVE-2025-43865ANC
React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's …
2025-01-01Pre-auth
EPSS0.7%
pct 49
5.3
CVE-2022-4539ANC
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versi…
2022-01-01Pre-auth
EPSS0.6%
pct 45
6.5
CVE-2024-53259ANC
quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICM…
2024-01-01
EPSS0.6%
pct 43
8.6
CVE-2025-40778ANC
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing …
2025-01-01Pre-auth
EPSS0.5%
pct 39
5.5
CVE-2025-21497ANC
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versi…
2025-01-01
EPSS0.4%
pct 35
5.5
CVE-2022-40140CVE
An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service coul…
2022-01-01
EPSS0.4%
pct 33
9.1
CVE-2026-23552ANC
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. …
2026-01-01Pre-auth
EPSS0.4%
pct 31
8.8
CVE-2026-22794ANC
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, th…
2026-01-01Pre-auth
EPSS0.4%
pct 30
7.5
CVE-2025-27415ANC
Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a craf…
2025-01-01Pre-auth
EPSS0.4%
pct 28
5.4
CVE-2026-25604ANC
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the cli…
2026-01-01
EPSS0.4%
pct 27
5.5
CVE-2022-46718CVE
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.7.2 and i…
2022-01-01
EPSS0.4%
pct 27
7.3
CVE-2017-9606CVE
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges …
2017-01-01
EPSS0.3%
pct 21
9.1
CVE-2025-27558AST
IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks…
2025-01-01Pre-auth
EPSS0.3%
pct 18
Select a vulnerability on the left to open the preview.