V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

1605 / 1605
CAPEC: CAPEC-388×Clear all
7.8
CVE-2023-38831CVE KEV
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to vi…
2023-01-01KEV
EPSS97.8%
pct 99
7.2
CVE-2009-1185DEB
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which…
2009-01-01
EPSS81.5%
pct 99
8.6
CVE-2016-4553DEB
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host h…
2016-01-01Pre-auth
EPSS79.7%
pct 99
7.8
CVE-2020-16952MSR
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails…
2020-01-01Microsoft
EPSS71.0%
pct 99
8.8
CVE-2015-4495DEB KEV
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS…
2015-01-01KEV
EPSS70.2%
pct 99
9.8
CVE-2023-29711CVE
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows at…
2023-01-01Pre-auth
EPSS68.0%
pct 99
8.8
CVE-2024-23898DEB
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does…
2024-01-01Pre-auth
EPSS66.9%
pct 99
8.6
CVE-2016-4554DEB
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin re…
2016-01-01Pre-auth
EPSS39.2%
pct 98
5.5
CVE-2019-9827CVE
Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP …
2019-01-01
EPSS26.8%
pct 97
9.4
CVE-2025-34291ANC KEV
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables accoun…
2025-01-01KEV
EPSS25.2%
pct 97
8.2
CVE-2022-21824AST
Due to the formatting logic of the "console.table()" function it was not safe to allow user con…
2022-01-01Pre-auth
EPSS21.5%
pct 97
9.8
CVE-2022-26871CVE KEV
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticat…
2022-01-01KEV
EPSS19.5%
pct 97
6.8
CVE-2023-35719CVE
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Auth…
2023-01-01
EPSS19.3%
pct 96
6.5
CVE-2021-21135AST
Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed …
2021-01-01Pre-auth
EPSS19.2%
pct 96
7.4
CVE-2020-13777DEB
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss …
2020-01-01Pre-auth
EPSS17.5%
pct 96
9.3
CVE-2014-4936CVE
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malware…
2014-01-01
EPSS16.8%
pct 96
7.5
CVE-2021-33959CVE
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
2021-01-01Pre-auth
EPSS15.0%
pct 96
7.2
CVE-2020-17049MSR
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determi…
2020-01-01Microsoft
EPSS13.8%
pct 96
5.3
CVE-2024-5458ANC
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code log…
2024-01-01Pre-auth
EPSS12.1%
pct 95
8.8
CVE-2023-22523CVE
This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Exe…
2023-01-01
EPSS11.1%
pct 95
6.5
CVE-2026-21527MSR
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allo…
2026-01-01MicrosoftPre-auth
EPSS9.5%
pct 94
7.5
CVE-2001-1452CVE
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received f…
2001-01-01Pre-auth
EPSS9.4%
pct 94
7.4
CVE-2021-26291DEB
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (…
2021-01-01Pre-auth
EPSS8.7%
pct 94
7.5
CVE-2024-36421CVE
Flowise is a drag & drop user interface to build a customized large language model flow. In ver…
2024-01-01Pre-auth
EPSS8.5%
pct 94
3.5
CVE-2015-0251DEB
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remot…
2015-01-01
EPSS7.6%
pct 93
4.3
CVE-2014-0034CVE
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not prop…
2014-01-01
EPSS7.4%
pct 93
5.4
CVE-2015-5296DEB
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connection…
2015-01-01Pre-auth
EPSS7.3%
pct 93
8.8
CVE-2023-5482AST
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote a…
2023-01-01Pre-auth
EPSS7.1%
pct 93
4.2
CVE-2019-19919DEB
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote C…
2019-01-01
EPSS7.1%
pct 93
5.9
CVE-2017-7674DEB
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 an…
2017-01-01Pre-auth
EPSS6.8%
pct 93
5.3
CVE-2016-3739ANC
The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 functi…
2016-01-01Pre-auth
EPSS6.4%
pct 92
4.3
CVE-2014-0364CVE
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verif…
2014-01-01
EPSS6.2%
pct 92
5.3
CVE-2020-11985DEB
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using p…
2020-01-01Pre-auth
EPSS6.1%
pct 92
9.8
CVE-2000-1218CVE
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, …
2000-01-01Pre-auth
EPSS6.1%
pct 92
8.8
CVE-2020-1408MSR
A remote code execution vulnerability exists when the Windows font library improperly handles s…
2020-01-01MicrosoftPre-auth
EPSS5.7%
pct 91
5.3
CVE-2017-18016CVE
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and …
2017-01-01Pre-auth
EPSS5.6%
pct 91
9.8
CVE-2019-3980CVE
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication …
2019-01-01Pre-auth
EPSS5.2%
pct 91
8.1
CVE-2017-11103DEB
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks b…
2017-01-01Pre-auth
EPSS5.1%
pct 91
8.1
CVE-2020-2604ANC
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serializat…
2020-01-01Pre-auth
EPSS4.9%
pct 90
8.3
CVE-2023-40547DEB
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-…
2023-01-01Microsoft
EPSS4.9%
pct 90
Select a vulnerability on the left to open the preview.