All vulnerabilities
529 / 529
Sort
7.8
CVE-2023-38831CVE KEV
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to vi…
2023-01-01KEV
EPSS97.8%
pct 99
8.6
CVE-2016-4553DEB
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host h…
2016-01-01Pre-auth
EPSS79.7%
pct 99
8.6
CVE-2016-4554DEB
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin re…
2016-01-01Pre-auth
EPSS39.2%
pct 98
9.8
CVE-2022-26871CVE KEV
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticat…
2022-01-01KEV
EPSS19.5%
pct 97
6.8
CVE-2023-35719CVE
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Auth…
2023-01-01
EPSS19.3%
pct 96
7.4
CVE-2020-13777DEB
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss …
2020-01-01Pre-auth
EPSS17.5%
pct 96
9.3
CVE-2014-4936CVE
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malware…
2014-01-01
EPSS16.8%
pct 96
7.2
CVE-2020-17049MSR
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determi…
2020-01-01Microsoft
EPSS13.8%
pct 96
5.3
CVE-2024-5458ANC
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code log…
2024-01-01Pre-auth
EPSS12.1%
pct 95
8.8
CVE-2023-22523CVE
This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Exe…
2023-01-01
EPSS11.1%
pct 95
6.5
CVE-2026-21527MSR
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allo…
2026-01-01MicrosoftPre-auth
EPSS9.5%
pct 94
3.5
CVE-2015-0251DEB
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remot…
2015-01-01
EPSS7.6%
pct 93
4.3
CVE-2014-0034CVE
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not prop…
2014-01-01
EPSS7.4%
pct 93
5.4
CVE-2015-5296DEB
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connection…
2015-01-01Pre-auth
EPSS7.3%
pct 93
8.8
CVE-2023-5482AST
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote a…
2023-01-01Pre-auth
EPSS7.1%
pct 93
5.9
CVE-2017-7674DEB
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 an…
2017-01-01Pre-auth
EPSS6.8%
pct 93
5.3
CVE-2016-3739ANC
The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 functi…
2016-01-01Pre-auth
EPSS6.4%
pct 92
4.3
CVE-2014-0364CVE
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verif…
2014-01-01
EPSS6.2%
pct 92
5.3
CVE-2020-11985DEB
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using p…
2020-01-01Pre-auth
EPSS6.1%
pct 92
8.1
CVE-2017-11103DEB
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks b…
2017-01-01Pre-auth
EPSS5.1%
pct 91
8.3
CVE-2023-40547DEB
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-…
2023-01-01Microsoft
EPSS4.9%
pct 90
4.0
CVE-2014-8143DEB
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directo…
2014-01-01
EPSS4.3%
pct 89
5.1
CVE-2013-0334DEB
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to i…
2013-01-01
EPSS3.8%
pct 88
6.9
CVE-2025-51471DEB
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote …
2025-01-01Pre-auth
EPSS3.7%
pct 88
8.1
CVE-2019-11235DEB
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is …
2019-01-01
EPSS3.6%
pct 87
4.7
CVE-2014-9365DEB
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CP…
2014-01-01Pre-auth
EPSS3.3%
pct 86
6.8
CVE-2017-10388ANC
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libra…
2017-01-01Pre-auth
EPSS3.2%
pct 86
4.3
CVE-2014-6512DEB
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60…
2014-01-01
EPSS3.0%
pct 85
4.3
CVE-2015-5235DEB
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsig…
2015-01-01
EPSS3.0%
pct 85
9.8
CVE-2018-19971CVE
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
2018-01-01Pre-auth
EPSS3.0%
pct 85
4.3
CVE-2015-2704DEB
realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf …
2015-01-01
EPSS2.9%
pct 85
7.8
CVE-2019-0805MSR
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUA…
2019-01-01Microsoft
EPSS2.8%
pct 84
6.8
CVE-2014-8165DEB
scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsaf…
2014-01-01
EPSS2.8%
pct 84
5.3
CVE-2023-51764DEB
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reje…
2023-01-01Pre-auth
EPSS2.6%
pct 83
3.1
CVE-2020-24587AST
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equiv…
2020-01-01Microsoft
EPSS2.6%
pct 83
7.2
CVE-2022-20829CVE
A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and th…
2022-01-01
EPSS2.6%
pct 83
4.3
CVE-2018-13796DEB
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to…
2018-01-01Pre-auth
EPSS2.5%
pct 82
9.8
CVE-2021-43616DEB
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if depen…
2021-01-01Pre-auth
EPSS2.5%
pct 82
9.1
CVE-2019-5161CVE
An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionali…
2019-01-01
EPSS2.5%
pct 82
7.3
CVE-2021-38295DEB
In Apache CouchDB, a malicious user with permission to create documents in a database is able t…
2021-01-01
EPSS2.5%
pct 82
Select a vulnerability on the left to open the preview.