All vulnerabilities
1450 / 1450
Sort
9.8
CVE-2022-24112CVE KEV
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction o…
2022-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2024-4358CVE KEV
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthe…
2024-01-01KEV
EPSS94.3%
pct 99
9.8
CVE-2022-23131DEB KEV
In the case of instances where the SAML SSO authentication is enabled (non-default), session da…
2022-01-01KEV
EPSS94.0%
pct 99
9.8
CVE-2021-29441CVE
Nacos is a platform designed for dynamic service discovery and configuration and service manage…
2021-01-01Pre-auth
EPSS93.9%
pct 99
9.8
CVE-2018-18925CVE
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as…
2018-01-01Pre-auth
EPSS93.6%
pct 99
8.1
CVE-2024-41107ANC
The CloudStack SAML authentication (disabled by default) does not enforce signature check. In C…
2024-01-01Pre-auth
EPSS92.0%
pct 99
9.8
CVE-2024-43441ANC
Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server.
This…
2024-01-01Pre-auth
EPSS90.2%
pct 99
7.2
CVE-2009-1185DEB
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which…
2009-01-01
EPSS89.5%
pct 99
6.1
CVE-2022-31798CVE
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= …
2022-01-01Pre-auth
EPSS86.6%
pct 99
8.8
CVE-2021-31195MSR
Microsoft Exchange Server Remote Code Execution Vulnerability
2021-01-01MicrosoftPre-auth
EPSS77.6%
pct 98
7.8
CVE-2020-16952MSR
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails…
2020-01-01Microsoft
EPSS75.1%
pct 98
8.8
CVE-2015-4495DEB KEV
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS…
2015-01-01KEV
EPSS71.6%
pct 98
9.1
CVE-2022-39227CVE
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 ar…
2022-01-01Pre-auth
EPSS71.3%
pct 98
9.8
CVE-2020-7388CVE
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By e…
2020-01-01Pre-auth
EPSS68.8%
pct 98
9.6
CVE-2022-41924CVE
A vulnerability identified in the Tailscale Windows client allows a malicious website to reconf…
2022-01-01Pre-auth
EPSS53.6%
pct 97
9.8
CVE-2019-3980CVE
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication …
2019-01-01Pre-auth
EPSS50.3%
pct 97
7.4
CVE-2021-26291DEB
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (…
2021-01-01Pre-auth
EPSS46.1%
pct 97
2.6
CVE-2013-2249DEB
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds…
2013-01-01
EPSS43.7%
pct 97
8.8
CVE-2024-23898DEB
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does…
2024-01-01Pre-auth
EPSS36.9%
pct 97
5.3
CVE-2015-8139DEB
ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then imperso…
2015-01-01Pre-auth
EPSS30.1%
pct 96
9.8
CVE-2022-27518CVE KEV
Unauthenticated remote arbitrary code execution
2022-01-01KEV
EPSS27.7%
pct 96
6.5
CVE-2021-21136AST
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 al…
2021-01-01Pre-auth
EPSS25.1%
pct 96
6.5
CVE-2021-21135AST
Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed …
2021-01-01Pre-auth
EPSS24.9%
pct 96
8.1
CVE-2017-14263CVE
Honeywell NVR devices allow remote attackers to create a user account in the admin group by lev…
2017-01-01Pre-auth
EPSS24.4%
pct 96
9.8
CVE-2022-3180CVE
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and…
2022-01-01Pre-auth
EPSS23.5%
pct 95
9.8
CVE-2021-34646CVE
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulne…
2021-01-01Pre-auth
EPSS22.5%
pct 95
9.8
CVE-2017-12965CVE
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sess…
2017-01-01Pre-auth
EPSS22.2%
pct 95
9.3
CVE-2024-50339ANC
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to…
2024-01-01Pre-auth
EPSS21.5%
pct 95
5.4
CVE-2020-10135AST
Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specifica…
2020-01-01
EPSS20.2%
pct 95
9.6
CVE-2024-12108CVE
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp G…
2024-01-01
EPSS19.4%
pct 95
7.5
CVE-2022-47522CVE
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to interce…
2022-01-01
EPSS17.6%
pct 95
7.5
CVE-2019-1234CVE
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure…
2019-01-01Pre-auth
EPSS16.6%
pct 94
4.3
CVE-2014-0033DEB
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does no…
2014-01-01
EPSS16.2%
pct 94
7.5
CVE-2020-10136CVE
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsul…
2020-01-01Pre-auth
EPSS16.0%
pct 94
8.8
CVE-2020-1408MSR
A remote code execution vulnerability exists when the Windows font library improperly handles s…
2020-01-01MicrosoftPre-auth
EPSS15.9%
pct 94
6.5
CVE-2021-21134AST
Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remo…
2021-01-01Pre-auth
EPSS15.3%
pct 94
9.8
CVE-2018-5353CVE
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows …
2018-01-01Pre-auth
EPSS15.3%
pct 94
6.5
CVE-2022-35770MSR
Windows NTLM Spoofing Vulnerability
2022-01-01MicrosoftPre-auth
EPSS15.2%
pct 94
7.8
CVE-2020-1449MSR
A remote code execution vulnerability exists in Microsoft Project software when the software fa…
2020-01-01Microsoft
EPSS14.8%
pct 94
7.5
CVE-2022-34689MSR
Windows CryptoAPI Spoofing Vulnerability
2022-01-01MicrosoftPre-auth
EPSS14.4%
pct 94
Select a vulnerability on the left to open the preview.