All vulnerabilities
1541 / 1541
Sort
7.5
CVE-2024-29059MSR KEV
.NET Framework Information Disclosure Vulnerability
2024-01-01MicrosoftKEV
EPSS98.8%
pct 99
6.4
CVE-2010-3332CVE
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for AS…
2010-01-01
EPSS67.5%
pct 99
7.5
CVE-2020-35234CVE
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as ex…
2020-01-01Pre-auth
EPSS63.4%
pct 99
7.5
CVE-2025-62168ANC
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP …
2025-01-01Pre-auth
EPSS63.3%
pct 99
7.5
CVE-2023-43261CVE
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows at…
2023-01-01Pre-auth
EPSS60.1%
pct 99
6.5
CVE-2013-7331CVE KEV
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attacke…
2013-01-01KEV
EPSS58.0%
pct 98
4.3
CVE-2025-47813CVE KEV
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the …
2025-01-01KEV
EPSS56.4%
pct 98
7.5
CVE-2024-20440CVE
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacke…
2024-01-01Pre-auth
EPSS51.5%
pct 98
5.3
CVE-2021-30357CVE
SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of th…
2021-01-01Pre-auth
EPSS22.8%
pct 97
5.3
CVE-2021-31159CVE
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due…
2021-01-01Pre-auth
EPSS17.8%
pct 96
5.3
CVE-2018-8719CVE
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-c…
2018-01-01Pre-auth
EPSS15.8%
pct 96
5.3
CVE-2020-11883CVE
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in Vu…
2020-01-01Pre-auth
EPSS15.2%
pct 96
3.5
CVE-2012-5615DEB
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.6…
2012-01-01
EPSS14.8%
pct 96
9.8
CVE-2018-11716CVE
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenti…
2018-01-01Pre-auth
EPSS14.3%
pct 96
5.3
CVE-2024-21733DEB
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.Thi…
2024-01-01Pre-auth
EPSS14.3%
pct 96
7.5
CVE-2018-12604CVE
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request …
2018-01-01Pre-auth
EPSS13.3%
pct 95
8.2
CVE-2024-9466CVE
A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition all…
2024-01-01
EPSS11.2%
pct 95
5.3
CVE-2025-9985ANC
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information …
2025-01-01Pre-auth
EPSS11.2%
pct 95
7.5
CVE-2018-17961AST
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism …
2018-01-01Pre-auth
EPSS10.0%
pct 94
5.3
CVE-2024-45440DEB
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is N…
2024-01-01Pre-auth
EPSS9.3%
pct 94
9.8
CVE-2018-11717CVE
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging acces…
2018-01-01Pre-auth
EPSS8.6%
pct 94
7.5
CVE-2022-29266CVE
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's …
2022-01-01Pre-auth
EPSS7.7%
pct 93
7.5
CVE-2019-0741CVE
An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive inf…
2019-01-01Pre-auth
EPSS7.4%
pct 93
7.5
CVE-2022-0660CVE
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber…
2022-01-01Pre-auth
EPSS6.9%
pct 93
6.5
CVE-2023-20593AST
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacke…
2023-01-01
EPSS5.8%
pct 92
5.3
CVE-2018-6188AST
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9,…
2018-01-01Pre-auth
EPSS4.9%
pct 90
7.5
CVE-2020-15478CVE
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
2020-01-01Pre-auth
EPSS4.7%
pct 90
3.7
CVE-2018-12536DEB
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, wh…
2018-01-01Pre-auth
EPSS4.3%
pct 89
7.5
CVE-2021-22885AST
A possible information disclosure / unintended method execution vulnerability in Action Pack >=…
2021-01-01Pre-auth
EPSS4.2%
pct 89
7.5
CVE-2024-39719DEB
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/c…
2024-01-01Pre-auth
EPSS4.1%
pct 89
7.5
CVE-2015-3167DEB
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x b…
2015-01-01Pre-auth
EPSS4.0%
pct 89
5.3
CVE-2020-1928CVE
An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive paramete…
2020-01-01Pre-auth
EPSS4.0%
pct 89
6.5
CVE-2023-27587CVE
ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an …
2023-01-01
EPSS3.9%
pct 88
9.8
CVE-2018-11325CVE
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofil…
2018-01-01Pre-auth
EPSS3.8%
pct 88
6.5
CVE-2019-13509DEB
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 1…
2019-01-01
EPSS3.7%
pct 88
7.5
CVE-2026-29146ANC
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
…
2026-01-01Pre-auth
EPSS3.6%
pct 88
3.3
CVE-2001-1556CVE
The log files in Apache web server contain information directly supplied by clients and does no…
2001-01-01
EPSS3.6%
pct 87
4.3
CVE-2016-0448ANC
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u10…
2016-01-01
EPSS3.5%
pct 87
8.5
CVE-2017-7550AST
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain…
2017-01-01
EPSS3.5%
pct 87
5.3
CVE-2019-3888DEB
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plai…
2019-01-01
EPSS3.4%
pct 87
Select a vulnerability on the left to open the preview.